Lavabit provides a direct example.
I'm not saying I don't use Signal, because I do. It would work fine against cops or the federal government as a citizen. But if lives depended on it, it would merely be part of my communications toolbelt.
Defense in depth is important. It's also unnecessary for most people most of the time, which is why I generally don't do it and just use Signal for interpersonal communication. But it's still good for people to know that depending on one system like Signal for security has risks so they can make their own determination on if it's worth it to harden their communication systems.
For one-to-one communication, ideally I'd set up either some sort of special code with the receiving end and just use http. If more information relaying is needed, a one-time pad would be good. I'd try to keep the messages short in case there's a hole in the system somewhere. Again, depending on your needs, relying on one protocol like matrix or pgp could be risky. Good OPSEC can make up for a leaky security system.
For one-to-many communication, proxies and device disassociation are priority above all else. You can assume interception of those messages generally.