The reality is more complicated than that. There are a lot of layers that make up any sort of cybersecurity defense. Yes, the OS does need to be implemented well and of course the US gov has standards for all of that stuff. The standards go pretty in depth and the standards used for US cybersecurity are commonly cited in the infosec crowd for hardening deployments.Isn't that a bit of a myth? Unless the OS is secure, neither is an application running under that OS?
I freely admit not to knowing the OS those particular Signal users were using, but I've read that the US government has a list of requirements for secure communication and has done for some years.
This can go into a far deeper rabbit hole of compiler security and open source software but that's a whole tangent that could easily have its own thread