The provider has access to the host, they can just inspect the job from the outside and you won’t be able to tell
secure boot + virtualized memory encryption is supposed to prevent that, you'll have to trust intel/amd though.
I suppose you can transfer the keys out of the machine over the network (and hope the hypervisor doesn't replace the socket buffers just before transmission) and verify them off site, but guest machines will always be just that: guests on a host that has all the power.