From what source and how were they validated, both from a secure checksum perspective and code audit? Was a full application pen-test done on each package after installation and configuration? Additionally, what controls are running server-side to audit memory execution and modifications on disk? Is Tripwire being used as an example? How about Wireshark? Is it being used to monitor all traffic from the host NICs with alerts sent out if it spots any non-encrypted traffic or traffic to IP addresses not explicitly white-listed? How about ongoing monitoring for zero-days for each of the packages used?
Nothing I read in the article leads me to believe there is any NSA proofing here whatsoever. Making something secure isn't about finding a "secure" data center and hosting a solution yourself. In fact, self hosted solutions can be some of the toughest to secure because you must have a broad and deep knowledge of security as it relates to the entire environment and then keep up with package changes in a way which results in auditing each and every future change. Honestly, no one has time for that and even if secure at x point in time, it won't be at y point, say when a Hartbleed level vuln is announced for a package used while the author is on vacation and can't reach his servers to appropriately mitigate.