There is encryption at rest (storage encryption), transport encryption and end-to-end encryption. E.g. Posteo has transport encryption and optional storage encryption. With activated storage encryption, Posteo cannot read your mail because the encryption key on their server is only usable with your password (which they do not store). Proton Bridge adds end-to-end encryption to Protonmail
Are they actually stating “secure alternative”? I only see this on the Lemmy post but not on the linked site. Of course, there is “Security & Compliance”, but not in distinction to GitHub or Gitlab