Just learned, there's a tool by Google called Copybara, & it solves the problem of everything inside monorepos being visible to even people concerned with just a single submodule or project.
Always, thought about how companies managed monorepo security. & Copybara is the answer.