I'm always bothered by statements like this because it appears to be skimming over if the provider can perform cryptography with the key. My understanding is that those keys are only decrypted in the users apps/web browser, not server-side. Is that right?
You need to trust that the provider doesn't perform additional operations along side legitimate user triggered actions, which I believe PM handles.