Earlier quoted context omitted.
My "device" is a laptop. You say "like Apple", but I believe Apple's CSAM is unique - nothing else tries to scan your messages between keyboard and encryption.
I think the term « device » is a bit misleading. I should have used client side instead. It doesn’t need to scan your messages between keyboard and encryption, the application handles your messages in plaintext and it can scan them without needing any decryption. The encryption is done just before sending the messages.
[Edit] I evidently don't understand your remark. If some "encryption app" processes the plaintext before it is encrypted, isn't it processing plaintext between the keyboard and the encryption?