This is for example why Lavabit chose to go out of business instead of giving up their keys.
Which apple does.
It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc).
The headaches that come from e2e everything are too great for most people.
That's obviously only the case if they aren't also the sole providers of the "ends".
1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.
Another way is to open source it and repeat 2/3/4
The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.