"security" is always left for after-the-fact ---- exactly as evidenced by this disclosure and their poor in-house practices.
Like everything in software it's about tradeoffs. Maybe they erred a little too far on one side of the curve, so let's learn from that. But it's unfair to expect startups to be in the same league as banks security-wise. Do you have any idea how much a good pentest costs?