for everything else there are plugins in your client for OMEMO (what signal is based on) and OTR (which is purely session based).
Handling this as a third-party implementation for E2EE is probably the only true way to gain trust anyway. If your provider provides the infrastructure and the client then how can you really trust it?