not sure about it either. But like all android based devices, security updates would still need to be done by combination of device manufacturer and carrier.
its a big issue that anyone running a non nexus based android device should be aware of. Somteimes security patches can take a long time to get out.
I know when I was on my Note 2, 4.4 came Months after 4.4 was releeased by google itself, and then the 4.4.4 patch for security fix took another 2 months after google released their security fix.
Androids biggest problem isn't the diversity of the versions IMHO, it's the ridiculousness of the hardware makers customization and lengthy time to get those customizations out.
If you've ever ran a nexus device after using a non nexus version of android, it's like night and day. Most people who complain about bad experiences with android itself are usually having that experience because of the 3rd party version of the OS, not because of Android itself