I didn't get a reply for so long (over 1 month!) I implemented fingerprinting and logging on my POC, was able to prove that they looked at it, and THEN patched, and that it WAS them who looked at it. Companies will patch before even replying, despite how jerkish that is.
It takes H1 extremly long to triage reports... so long that companies fix it and then triagers cant reproduce it and want "more info"... highly recommended: take as much proof as possible that those issues really existed ;)