There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…
No you can't. AMD builds the TPM in to the CPU, with AMD's encrypted memory feature (SEV), in theory you do not have to trust the data center an all.
The CPU boots, loads a verified firmware using PSB, initializes a safe environment in SEV, your entire boot procedure and data is encrypted and safe using FDE and SEV keys stored in the TPM using PCR's.