Open source vs source viewable is irrelevant in this context: the point is that publishing code by no means guarantees that vulnerabilities will be found in a timely manner.
In the context of Casa, which only generates and stores the mobile key, a malicious app could be deployed to steal keys practically instantly, far faster than any human or machine would catch the malicious code. Having the code available would not change the security model: either you trust Casa to handle the mobile key or you don't, and we offer multiple options that serve both of those models.