This is how I see it.
Windows - Most secure, but requires a lot of work (365 E5 or GPO, plus Defender configs) - Never use those privacy scripts, they break things, and Microsoft just turn the settings back on.
ChromeOS - Excellent security out of the box, can be further hardened with Google Workspace enterprise.
macOS - Good for security, excellent hardware security, somewhat OK for privacy, needs an MDM to get its best security, which brings its own privacy issues, disable iCloud, use a VPN or NextDNS to block telemetry.
Linux - horrific security for the most part, secureblue tries to remediate this, avoid AMD CPUs if you need TPM, excellent privacy if you use the right distro, Ubuntu or Red Hat are the only two others if you want security, Ubuntu Pro helps with this as it can enforce compliance, still needs something like Landscape however.
I would stick with the mac and put some DNS blocking in place at the router level, or leverage a VPN to do this, log out of iCloud etc.
Frameworks are great because of how they are designed, but they are not the most secure laptops, far from it, I have an AMD one and I cant use TPM with secureblue because its not implemented in the kernel properly yet...
You could leverage VMs and run something like secureblue in that, I used to use Parallels a lot and it worked great but its closed source, UTM maybe a good shout but never really tried it.