They're also leaving themselves open to MITM attacks, where an attacker could change all of the tor addresses.
Edit: Nevermind — I assume you're referring to this scenario[1], in which the company installs a root certificate onto your actual computer that allows them to sign certificates for other sites.
From there, everything can be tracked.