The CEO stated that the timelock will only expire if the vulnerabilities are found and fixed
I admit I don't understand the technical details of how it works, and it was quite complicated, but my assumption was that the timelock is something that can't be changed once it's set. I assumed it was based on cryptography, but judging by your comment it's completely centralized.
That confirms what I knew already: don't trust things you don't understand

It reminds me of the "ETH DOA smart contract" where the only person who understood how it works was called "the attacker".
Keep it simple, keep your own keys
