That's provably false when you get to the bottom of what makes proprietary software trustworthy: it has to be verified by qualified people who you trust after being designed and built with enough rigor to not have accidental flaws. That's regardless of whether it's proprietary or FLOSS. I went into detail here:
https://pastebin.com/EZQWbwCB
In fact, the first systems that resisted strong pentesting by NSA were proprietary, shared- or closed-source systems. They shredded everything else. Two are below with another designed like that. The first, safe, kind-of-secure machine that I know of was Burroughs B5000 whose CPU did things like stop overflows, protect pointers, and check function arguments. It was immune to common, root causes of many failures or attacks. OS in a type-safe, high-level language (ALGOL variant). It was a proprietary system whose source was shared with customers. Linux systems still don't have as much code-level security in average case as that proprietary software from 1961. The virtualization solutions in FLOSS still aren't produced as securely as VAX VMM or the separation kernels that followed in 2000's with VMM's layered on top.
http://www.cse.psu.edu/~trj1/cse443-s12/docs/ch6.pdf
http://lukemuehlhauser.com/wp-content/uploads/Karger-et-al-A...
(See Layering and Assurance sections especially. Compare to QA practices of favorite FLOSS VM.)
http://www.smecc.org/The%20Architecture%20%20of%20the%20Burr...
https://www.usenix.org/legacy/events/sec04/tech/wips/wips/04...
(Nizza uses FLOSS components. This document is just great at describing the architecture they and the proprietary vendors were using with separation kernels. The proprietary offerings contained a lot of problems FLOSS didn't with their 4-12kloc kernels having less code to screw up. User-mode drivers can boost reliability a bit, too.)