I'm one of those people who understand the importance of reputation and integrity. One bad deal might ruin mine forever. You needed resources to expand your privacy business. Did you try and fail to partner with reputable businesses such as Mozilla, get funding from governments/foundations, etc? Did you try to get with amoral companies whose background or business wasn't harmful to privacy? And, after that, settle for the one company that was interested which could damage your brand?
I have a feeling you didn't since I'm sure there's plenty of companies, non-profits, or cooperatives that might have worked with you who don't have that background. Although I can't prove that, I see investments and partnerships all the time with organizations that raise less eyebrows. That you went with that company will undermine trust.
I'm no longer recommending PIA. I do appreciate that, before this change, your company went as far as defending its users' rights when FBI was after them. I'll still give you credit for that.
Edit re hiring security people: You also keep justifying hiring con men for second chances or doing business with intelligence assets like there were no other alternatives. I've met all kinds of security professionals and cryptographic researchers who haven't taken malicious contracts or damaged others [that I'm aware of]. Quite a few have turned down work because they're ideologically opposed to it or just don't harm others. I'm one of those. So, my next bit of skepticism is that you really couldn't find anyone better than folks like Karpeles. You could've asked here or at Black Hat and probably got a ton of candidates who might be more trustworthy with your customers' privacy.