Just giving the benefit of the doubt here, a lot of the time it's unclear if your disclosure even made it to the right people in a company or not. No response is the norm for security disclosures, as is claims of "we didn't get this", even if you have a receipt for their ticketing system that says they did. I've sometimes spent far longer attempting to contact a company than doing research into something that seems to be a problem.
It's easy to prove. Just go look at the number of iOS and OSX security fixes attributed to him. Or you can go do a simple search on any reputable site posting security info and you'll see him all over it.