This stuff has to work. The adversary for secure messaging is world governments. If all you're worried about is criminals, Gchat will do a fine job of protecting you. For a vivid example of what I'm talking about, see the Telegram/Iran fiasco.
It's hard enough building secure messaging in a native application; there are lots of details that are not easy to get right (as Cure53 demonstrated to your team).
Bluntly: I feel that it's irresponsible to add to that portfolio of difficulties the added attack surface of content-controlled Javascript.
The reason people build services like this is that users will prefer them to (more secure) native app alternatives. It's easy to see why. The common response to this observation is: "but users won't install an app". They won't install an app because people keep luring the away with insecure web-page based secure messengers.