While that’s of course a valid consideration, I’d be more worried about the plugins than the core application. Does your architect disallow them, or does he review them all?
Some cases in point: Atom has analytics built in; look at what happened with Kite hijacking minimap and autocomplete_python for Atom; or SidebarEnhancements for Sublime which also tracks users. Of course them being open source makes it easier to “catch” them, but usually only after lots of users getting violated.
Are you going to review all source code for Atom or are you going to trust Sublime’s devs having their livelihoods depend on the product being trusted by peers? Do you review all source code in Ubuntu, or do you trust it? Wether or not something’s open source is secondary at best, IMO.
Edit, also…
I’m sure I could get my bosses to pay more licenses if it would
… bosses tend to not pay for things they can get for free 

) development for such a large project may dry up.
. Actually, I just upload to github fast experiments or code I’m not really interested on… Closed source is not necessarily the devil, you know?