The people that would blow the whistle on this are people that report bugs, but don't get paid. If he claims to have paid people, but the 'people' and vulnerabilities are just fabrications, then only someone within the organization would be able to blow the whistle, no?