Trust Is the Ultimate Moat: How Open Source Wins in the Age of AI
For decades, software companies guarded their source code as their crown jewels. That logic is collapsing. AI now reproduces, refactors, and reimplements code at a pace that makes the codebase itself nearly worthless as a defensive asset. So what's left to compete on?
In cybersecurity, the answer was always trust, not code. Customers don't buy lines of code; they buy a decade of track record, independent certifications, a clean breach history, and a community of thousands who scrutinize the product in the open. This talk argues that trust is the only durable moat left, and that open source is the most honest way to build it.
Drawing on Passbolt's experience as a European password manager licensed entirely under AGPL, including the paid version. I'll explain why we gave away the code deliberately from day one, why that decision strengthened rather than weakened the business, and what this means for European digital sovereignty in an AI-accelerated world.
The conventional wisdom of the software industry held that your source code was your competitive advantage, the thing you protect, obfuscate, and litigate over. AI has quietly demolished that assumption. A model can now read, reproduce, and adapt a codebase in minutes. The marginal cost of copying functioning software is approaching zero. If your moat was the code, your moat is gone.
This talk makes a direct argument: in cybersecurity, and increasingly in software at large, the real moat is trust, and trust cannot be copied, scraped, or generated.
I'll break down what actually makes customers choose a security vendor, and none of it lives in the repository:
Time in market. Ten years of operating without disappearing, pivoting, or selling out. You cannot fork a track record.
Certifications and audits. Independent validation that takes years and real money to earn.
A clean breach history. Reputation accumulated one uneventful day at a time, instantly destroyed, never instantly built.
Community. Thousands of users reading the code, reporting issues, and vouching for the product in public. A community is a relationship, not an artifact.
I'll then make the case for why open source is the most credible foundation for trust, using Passbolt as the worked example. Our entire product, including the commercial, paid version, is licensed under AGPL. We chose this deliberately, from the very beginning, precisely because we understood that the code itself means very little. If a competitor can copy it easily, they still cannot maintain it over the long term, operate the infrastructure around it with the same robustness, or earn the trust that took us a decade to build. Giving away the code cost us nothing we actually depended on, and bought us enormous credibility.
This argument has a sharp edge for European digital sovereignty. Sovereignty is not achieved by hiding code behind borders; it's achieved through transparency, auditability, and the ability of any organisation,public or private, to verify exactly what it is running. Closed, proprietary security tools ask you to trust a vendor's word. Open source lets you trust the evidence. In an era where AI makes secrecy ever more fragile and verification ever more important, openness is not a charitable concession. It's the strategic high ground.
Kevin Muller is a serial tech entrepreneur with 20 years of experience across France, Luxembourg, and India, where he spent 15 years building and scaling ventures. He is currently the CEO of Passbolt, an open source platform that empowers modern IT teams to securely manage passwords and secrets. Backed by $12M in funding, Passbolt is trusted by over 50,000 organizations in 100+ countries, including public institutions, defence agencies, governments, IT companies, and many SMBs and startups.
Beyond Passbolt, Kevin is an active startup mentor and occasional investor, with a strong focus on open source, cybersecurity, and healthtech.
