I think Kagi / Orion should go down the independent auditor route like TrailOfBits, Cure53 and others.
That way the software would be audited and it doesn't have to be open source.