This alone lends credence to their claims. To this date there has been no major breaches despite being a large target (albeit smaller than LP). Moreover, the fact that your vault is both password protected and locked behind a secret key is about as good as you can get in terms of commercially offered security.
That's not to say they couldn't be lying. But after careful evaluation I've gone to them and people much more experienced in security have also moved to them as well.
FWIW a "source code audit" or "making it open source" does not imply intrinsic security. You are putting far too much weight in either a firm to do the right thing with money, or the existence of sufficiently motivated OSS researchers mining what might be millions of lines of code. We still find bugs in the Linux kernel regularly despite it quite literally having tens of millions of eyes on it. What makes you think this would do anything more than assuage your fears through security kabuki? In fact, OSS while sounding nice introduces an entirely new attack vector that a company may simply not have the staff to mitigate. To use the Linux kernel once more vulnerabilities have been deliberately injected into the kernel more than once. There have been game breaking SSL bugs. Huge overflow problems, etc. I love OSS. It is not a panacea. Signal chose this model - it does not imply it is the best, the most practical, or the most secure.