Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch.
You noticed that the email implies the security has been perfected. Did you also note that it would be unethical for a professional to blindly convey that false belief.