It rephrases and generalizes his points rather than tackling them head-on.
Kobeissi's main point is that ProtonMail could serve up any javascript they want to the client, including javascript that compromises the encryption or which hands over the encryption keys to ProtonMail.
Nowhere in ProtonMail's response is this point ever directly addressed or even acknowledged.