If you access ProtonMail via their web app, all that's needed to steal your password and decrypt email at will is a few quick changes to the index.html they serve you. This could be targeted to specific users, and once the password is exfiltrated, the page can be reloaded, leaving no trace of the attack. Anyone with access to ProtonMail's back end code or infrastructure could do this. So at least in the case of their web app, they could absolutely provide LE with whatever they wanted in a way that would be quite difficult for the average user to detect.
I don't know whether their mobile apps also trust the server in the same way--by loading content or js from the server. If not, then those could potentially offer a more secure alternative since the same attack would now require an update for all users, which would leave evidence behind. Of course, you still have to trust that any users you're sending email to also never submit their passwords to the web app.