True, but just static analysis of private source code is likely to discover several vulnerabilities, forget about experts looking for them in the source code. How many companies even do security based static code analysis using state of the art tools?