When do critical security updates hit PureOS?

You need to check on the top right in the app details screen to see what source is selected.

apt + dpkg are the Debian package manager. This is different from Flatpak so your assumption was correct