There's no reason you can't open source anti spam. The only reasons not to do so are that it's either absurdly to bypass if it's known, which makes it useless, or if they don't want it visible.
Why wouldn't they want extra eyes on it? That's how a lot of vulnerabilities get found, people actually checking the code and testing it.
That suggests some other reason, and they haven't said (that I'm aware of). Since that means that part can't be trusted, you can't trust the rest of it either. That isn't to say you can't choose to use it, but you're using it blind, which makes it no more secure or private than telegram or any other options.