Seems like a technical ad for their product. If the thread model includes malicious admins then all bets are off as admins can change both server-side and front-side code.
Some measure of security could be achieved using browser extensions (c.f. Mailvelope or https://stosb.com/blog/signed-web-pages/).