Not sure that’s how it works. The certification and the encryption are two different things. Though encryption certification does require the private keys to be uploaded to the CA, a bunch of internal encryption for these type of apps would not necessarily be certified by that or a CA in order for the encryption to be effective.
Correct