If they can pay that single guy any amount of money to sign an NDA, even if he doesn't find any exploits during that time it's still worth the money for them. Their goal is most likely preventing public disclosure more than obtaining an actual audit since, like you said, they would better off...