Both Intel and ARM ship with "management engines" that a vendor can use to take control of a computer.
http://www.networkworld.com/article/3085494/security/intel-management-engines-security-through-obscurity-should-scare-the-out-of-you.html
Oracle/SUN released the SPARC T2, which lacks such an engine. It's the only CPU that can be trusted.
http://www.oracle.com/technetwork/systems/opensparc/opensparc-t2-page-1446157.html
I would like to see this CPU in a Raspberry-Pi form factor. Speed is not material.
Solaris is also quite strong - zones are far more capable than systemd-nspawn, and zfs continues to rule the realm of file systems.
These are great products, and Oracle is failing to properly capitalize them. They are open, and someone else should.