ProtonVPN provides the source code for their desktop and mobile clients in their GitHub organization [1]. Yes open source != safe; however this level of transparency is at least a step in the right direction.
They also have regularly been audited by independent organizations that are openly available for the public to see their compliance [2][3][4][5][6].
Do you have any evidence to suggest that they are honeypots?