Regarding open source, we want to do it for parts and potentially all of the code. We plan to open-source our extension points as we go. You can read more about this here https://github.com/warpdotdev/Warp/discussions/400.
We have also talked internally about having penetration testing.
As for our business model, the terminal is totally free for individuals and we want to make a terminal so useful for individuals that their companies will want to pay for the team features.
The general philosophy is that we would never charge for anything a terminal currently does. So no paywalls around SSH or anything like that. The types of features we could eventually charge for are things that have a cost to us, for example enabling real-time terminal collaboration.