Apple at least claims to not have keys for their E2EE, such as when you turn on Advanced Protection (or whatever it’s called) it has this whole spiel about how screwed you are if you lose your recovery ability
You could additionally use encryption at rest where the key is only ever on the client.