The fly in the ointment is that they control the software and updates to that closed software so can short circuit that with appropriate pressure.
That would seem to constitute Honest Services Fraud under federal law, if they promised E2E then sabotaged it intentionally…
Throwing this on the "brainstorm if we had an ideal legislative world" pile: Stealing a user's private key should be a felony, even if it hasn't (yet) been abused for anything.
The tricky part is keeping it from being "permitted" by a crappy contract of adhesion. Banning it entirely would make it very difficult to buy/sell backup services...