The company remained on HackerOne and continued to promise bug bounties (and occasionally even paid some). Meanwhile, since the company hadn't responded to my report, I was not even able to disclose it within the platform.
I wrote it off as a learning experience and concluded that HackerOne was clearly focused on getting companies on board while not really caring about hackers. Business-wise, it's probably a clever practice (because getting companies on board is hard while finding hackers is easy), but I certainly am not very excited about them...
Edit: Said company is still on HackerOne, still offering their bug bounty, with links in the description now pointing to 404s since they changed their product line in the meantime. QED.