If you go to the company's public github & bitbucket profile you cannot see the project but you can see all the devs and all these devs have access to the code.
The logic is: All the employees are able to work with minimal delay (caused by background checks)
1. That repo links to a publicly-viewable website, I'm seeing files in the list from 9 months ago (way long enough), and GitHub has a very clear, very well-oiled DMCA process. This is up because it's okay.
2. From https://news.ycombinator.com/item?id=13682657 (nearby this thread):
> If you go to the company's public github & bitbucket profile you cannot see the project but you can see all the devs and all these devs have access to the code.
IOW, it's a private repo hosted on GitHub. «The code is safe from the public» but the contractor's actions still squarely violate the security guidelines for the project such as no USB drive access (!) (https://news.ycombinator.com/item?id=13679303).
The OP qualified this fairly explicitly here: https://news.ycombinator.com/item?id=13682501