A solution for your threat model is for the whistleblower to set up a proxy on some cloud server. For example, here are instructions for how to set up 'Your own proxy and VPN on Amazon EC2' -
https://en.wikibooks.org/wiki/How_to_Protect_your_Internet_A... . Problem solved, no, for the problem envisioned in your model?
You write 'the founder logs on to join the conversation ... with only the throwaway and CEO participating'. Why does the founder even want to 'join the conversation'? The supposed reason is to prevent overreaction, but there are naysayers and doubters and even those who lie about a company for the 'lulz', so it would be odd to see a founder jump on this one criticism and not all of the others.
The tradeoff is a chance of finding the IP address of a user's NAT'ed machine [1] among all of the readers (which is larger than the commenters) vs. the bigger downside of drawing attention to the thread. More people read a thread if there are comments, and I'll bet that some people will track posting by founders of darling companies.
If there is a thread, then why doesn't the founder let all the company's fans downvote and chastise the whisteblower for being an anonymous liar? And in any case, the more readers, the less useful the IP/geo tracking data.
The "only interact with stories it has created" has a big limitation. If there is a big thread, then the founder would post a response to the company's blog, and someone will post a new story "X responds". Our whistleblower would be unable to comment on this new thread.
[1] It would be better for our founder to use the Geolocation API than IP address. But our intrepid whistleblower even with Tor must be careful to strip geo and other identifying information from images, and other thing beyond what HN can hope to do, to be really safe.