s/container/volume/; security policy is at the OS volume level (which can share a container with others), and there is merit to sharing the OS *container* with macOS at some point in the (possibly distant) future. This wouldn't affect the security picture.