Free software is the way to go :)
If your software is not free, you have no guarantee of what's happening there.
Bugs like Heartbleed demonstrate that massive vulnerabilities can be introduced and persist in well-regarded open-source codebases for long periods of time without detection in spite of theoretical "millions of eyes". Heartbleed was, to the best of our understanding, the result of an honest mistake. What's to say that any significant OSS codebase with thousands of committers doesn't have a substantial number of subtle and less-than-honest "mistakes" of a similar character?
That open source code can be audited by third parties is only relevant if it actually happens, and otherwise you have only a false sense of security.