Of course there was never any question that any new penetration testing I would do with them would be under NDA. What worried me is that the disclosure may not be made public if I was under a NDA that prevented me from publishing it. I didn't want to have any professional or ethical conflicts.
You were right: once you had engaged a unit of Salesforce for an app test, it would have been extremely difficult for you to publish this. Not black-letter impossible, but difficult.
The retroactive part of the deal was a clear ominous alarm and you acted accordingly. I find great joy in knowing that you showed a pristine level of ethic behaviour in your security research. Well done.