The bureaucracy is way worse. BCID requirements. MDBs that take 4+ hours to roll out. The Byzantine array of different MDB group types, often with two party control. GDPR company compliance. Tagging proto fields with provenance. Documents are private by default now. Most support happens in chat groups, and is if you're not at deepmind your help requests are getting ignored. Spending a month filing GUTS tickets to get your intern access to basic tools. XManager idle pruning. GCP automated boq setup/teardown tools usually fail and you have to fall back to getting support from a contractor 12 time zones away.
If a company publishes loads of articles about how they have technical controls for privacy and security, through encryption and compartmentalization and code review and build provenance and so forth, and all the people who work/worked at said company are always whining about how onerous those processes are, then what gives you reason to doubt it?
Everyone who wants to work at a startup knows where to find the rest of Silicon Valley (and Austin and etc.). I wish them the best and I look forward to reading their data-breach disclosures if they get popular enough for anyone to care about what they're doing.
Now I'm at google, and onboarded on to the version of the infra that already went through that, and I can take it all at face value. It is a PAIN still, but this is the reality of a system that interfaces with O(10^8) users, O(10^2) governments.