What distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?

I think that many other companies (especially larger ones, I suppose) don't respond as promptly to security issues.

see, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity