If this is closed source (and the source seems to be only implementing API calls to a closed system) then it's fair to assume that this application is probably insecure or has backdoors.
Also if the private key is stored in the cloud then it's likely to be subject to requisitions.