Earlier quoted context omitted.
Yup, for proton open source means client code only
I tend to think this is a fair trade-off for services like this because: 1) for end-to-end encrypted services, I think what you most want to verify is: is my data actually being encrypted with my keys before being sent over the network, which open-source clients allow you to do 2) you can't personally verify what code is running on a company's servers anyway and to a lesser extent: 3) there could be legitimate securi…
If this is ever the case, it means the server code has been written in a horribly vulnerable way and you should never use it.