You still should hire pentesters, you still should have trusted employees to find bugs and fix them, and more... If you are relying just on bug bounties, your security will suck.
That being said, NDA's sound sketchy, if you disclose bug, than after it is fixed, you should be able to blog about it (or when they do not fix it for looong time).
Exactly the way we position our own Bug Bounty Program. Where the pentesters can be hired to also confirm things done well, the hunters are only paid for failures they found.
In our case there is an added bonus with the Bug Bounty Program: we've come to REALLY apriciate the technical level of reports. Since they only get paid for triagable findings, the details we get reported are so much better then what we used to get from our pentesters. Of course we now require the same quality of reporting from them.
What also helps is that the pentesters are motivated more to deliver higher quality findings since they are aware the service will enter the Bug Bounty Program after their findings are resolved.
Again, BBP should NOT replace your other security activities, they are an additional source with possible unforeseen benefits.
I don't know why you think that describes security bounty programs? They are about paying external people that find bugs and tell you so you can fix them with your people.