No setuid programs are expected to be executed, so add SecureBits=noroot noroot-locked to unit files.