If you think of it for a second, web crypto (protection against intermediaries and dishonest server) actually requires trusting the server, so no encryption-derived claims are sound if the server is dishonest. Any third party exploiting (or forcing legally) the server can make it dishonest and collect required keys in few simple steps. And, FWIW, if encryption is controlled by browser, adversary compromising the client itself can simply disable it.
So, while the effort is very important (and I bet they'd be around the first people who will suggest techniques for safe in-browser crypto execution), it isn't that they can be compared security-wise other than: - ethics - security policy - competence of security teams.
Isn't a level playing field for ProtonMail.
And, my final problem is, 99% of people are still outside Protonmail anyway, hence the intolerant winner argument, which ruined PGP and will ruin many optional security systems on top of convenience protocols in the foreseeable future.