If you really want super paranoid level security, communicating digitally is probably not your best bet anyway.
Here's the SHA1 checksum of the compiled binary from the latest release (2.0):
f9347ae51c3276f4b34fba0be7c0648f20c8c11e /Applications/ChatSecure.app/ChatSecure
Considering the fact that Apple is in the NSA wiretapping program and involved in secret tracking [1], don't you think it's unfair to call someone who's asking a way to verify if Apple isn't messing with the code "super paranoid"?
That's why it's better to use Crypto.Cat - its source is the executable. Verifying the hash is enough to make sure the source code didn't change.
You've gotta draw the line somewhere (unless you're rms). I would venture to say an open source OS and applications on worldwide-deployed hardware in the hundreds of millions count is probably safe enough for my purposes.