I think you have to trust your security software, and if it's not open source, you can't trust it.
However, what do you say to those who will argue that it's actually the other way around? They'll say that private companies have full developments teams paid and dedicated towards maintaining the security of their products... meaning that more work and research gets done, making them more secure, and trustworthy in the end. Or those who say that open sourcing the code makes it easier to find vulnerabilities?