> I believe secrets are still encrypted at this stage similar to cold boot.

Does this mean that the Signal desktop application doesn't lock/unlock its (presumably encrypted) database with a secret when locking/unlocking the laptop?

It wouldn’t matter because the whole OS would be evicted from memory and the entire storage encrypted.

Signal itself wouldn’t even be detectable as an app