Nothing on this page is marketing: every claim maps to a control that lives in the open repository, and the key claims are checked against the code by the site test suite.
The full technical document (threat model, boundaries and decisions) lives in the repository:docs/SECURITY.md on GitHub