Security strength is not a binary measure, there are many levels of security between "no encryption at all" to "run your own server".
Not really in the space we're discussing, i.e. usian and iranian everyday phone applications. Small private actors aren't going to pop the TLS on messages anyway, and the states involved have or can compromise the system as such.
Or endnode in Tor. Not sure it's secure enough against US which operates it.