Backend is never verifiable. It's a moot point. Signal's backend is open source yet they always release the sources late. Their servers were running entirely different code for a year and they even injected some cryptocurrency related features which weren't reflected in the source code.
Backend is always unverifiable, open source or not.
> Decompiling and inspecting mobile apps is relatively simple
Not so much when WhatsApp obfuscates binaries on purpose.
On top of that, the T&C clearly forbid you from doing it.
> As for Telegram, its messages are stored in plain text on their servers
Absolutely false. Telegram's cloud encryption algorithm has already been audited by independent researchers.
Calling symmetric encryption as "plain text", is disingenuous.
> This means that if Russian secret services were to gain access to Telegram's backend, they could easily read all the messages.
I guess Russia's telegram ban doesn't matter then? Nor Durov's fight with the Russian government. He actually moved to another country to stop the Russian government from having access to the servers.
It's totally fine to understand your security context and the security your messaging medium provides but it's not good to misrepresent facts and use terms that mislead people.