I don’t use Vesta since a while but Hestia have security in mind such as2 examples I have in mind
- Hestia have 2nd authentification by default
- Restrict access to php-fpm by group
- …
Also; Hestia seams more a teamwork than Vestia, I remember when serghey-rodin stop answering to almost anyone on almost any communication channel for few months, if I remember well, this is what give birth to Hestia