I mean, you don't. You have to trust the maintainers of the software you use, to a certain degree, or spend a majority of your time auditing the software you use.
That being said, Brave is pretty upfront about the security of their software. They've paid $25k in bug/security bounties so far and their browser is open source. So if an update turns evil, it stands to reason that someone is going to notice.