1) yes, Druid works with Graviton; see here for example
https://aws.amazon.com/solutions/case-studies/zomato-case-study/
2) for Apache Druid, security fixes are either applied to the latest major version as a patch release, or to the next major version, if the Druid PMC determines that the severity of the issue does not necessitate a patch release. Major versions are generally released once every 3 months
3) performance would be similar, as most of the delta between Apache and Imply versions of Druid are in areas other than perf-related
BTW, note that from a branding PoV there is no such thing as "Imply Druid" 🙂 — it is more accurate to say that Imply includes a custom distribution of Apache Druid