If a company publishes loads of articles about how they have technical controls for privacy and security, through encryption and compartmentalization and code review and build provenance and so forth, and all the people who work/worked at said company are always whining about how onerous those processes are, then what gives you reason to doubt it?
Everyone who wants to work at a startup knows where to find the rest of Silicon Valley (and Austin and etc.). I wish them the best and I look forward to reading their data-breach disclosures if they get popular enough for anyone to care about what they're doing.
Now I'm at google, and onboarded on to the version of the infra that already went through that, and I can take it all at face value. It is a PAIN still, but this is the reality of a system that interfaces with O(10^8) users, O(10^2) governments.