My guess is that everything on a .google.com domain requires loads of security testing. This let's them put up a marketing site with out tons of auditing.
Yeah that's absolutely correct. Google has more initiatives than they can produce internally and so a lot of work is contracted to external vendors/agencies, which can have security concerns. The withgoogle.com domain allows Google to host externally-created sites that do not have any access whatsoever to internal user data.