Earlier quoted context omitted.
I think the point is that silent circle is secured by policy, not by technology. The validity of their security assertions only extend as far as you trust their word.
It's hard for anything but policy to protect against denial of service (legal attacks against the company). Even if you have technical security which prevents compromise of data, they can shut the business down. CALEA means you are actually prevented from building/operating some kinds of privacy tech within the US (PSTN voice without wiretaps for sure, and PSTN-interconnected VOIP is a gray area; a mobile-focused VPN…
In practice, many operators do offer up access to 100% of their traffic, and to their endpoint devices to law enforcement and security agencies, but it's not a CALEA legal requirement.