When lives are on the line, it's dangerous to wait for peer-reviewed papers or solid evidence to come out. Think of how many years the NSA spied on everything before Snowden leaked it. There were rumors for years, but no solid proof. It's better to be more paranoid and have good OPSEC.
I'm not saying I don't use Signal, because I do. It would work fine against cops or the federal government as a citizen. But if lives depended on it, it would merely be part of my communications toolbelt.
Lavabit provides a direct example.