If a vendor don’t have any audits from the past 2 years, but their software has changed a lot since then, don’t fucking trust it–especially if their audit report is from a no-name security vendor and it claims the vendor’s product is perfect.
I find it ironic that you said that, then recommended Signal, which doesn’t publish all of their security audit reports, and their last public formal audit by some known name company was from more than a decade ago. Since then, Signal have changed A LOT.