It's honestly quite pathetic, but not at all unexpected these days. I do sometimes wish that when the negligence is so gross (sending API keys in the response of an unsecured request?) that the government would issue a fine. If you don't feel that your developers are security minded, there are many computer security professionals around the globe available to help. Maybe using some of those hundreds of millions of VC dollars for a quick audit would be the norm if there were actual penalties for this kind of reckless behavior.