If a company builds something like WebGoat and maintains WebGoat, I think allowing a logo or sponsorship like WebGoat has has now is ok.

But if a company wants to use OWASP to publish a formal publication, like the Top Ten, the various guides, etc. That's a VERY different use of OWASP since it's using the OWASP brand to back an idea or standard.