No one is posting their private keys on github, and when they do their crypto goes poof nearly instantly. None of the exchanges publish their threat model documents. I sure as shit don't tell people where I store my private keys.
The bitcoin whitepaper and code are more analogous to the ISO standard, which is public.