Except that we cannot verify that you actually deploy the "open" code. It's obviously commendable that you do development in the open, and have people review the work you do. But there is no way for us to know that you don't run /addNSAbackdoor.sh in your deploy script for key parts of your infrastructure.
There is already published docs that show Yahoo is/was part of Prism since 2008: http://www.wired.com/2014/09/feds-yahoo-fine-prism/