100% with you on the need to trust and fund fully open source software.
Phishing/social engineering is always a concern; even just tailgating through a door in the physical world...
But a communications solution that is self-hosted, integrates with internal identity and access mgt systems, and operates as a closed network/federation helps minimise risks.
All of which comes down to optimising for the use case. 🙂