How do people rationalize using a service like this for anything other than toy projects? Sending your source code to some service, then adopting and executing the artifacts it produces, means this is the central, most critical aspect of your security story. For real projects it doesn't stand even a moment's scrutiny.
Call me old school, but I'm with you. A vendor would have to be exceptionally well regarded over a long time to get my trust in such a scenario.