Hi @nmateo
systemd-boot is not bad. You can use ZFS with all options, GRUB cannot, but GRUB have option to lock with password. So use whatever you want.
As of all age laws you must look forward - better to have one working solution than...
If I wanted to trick VPS provider I would look does he use ARP. In that case I would use L2 VPN (wireguard is only L3): Cloudzy VPS eth0 -> bridge with VPN -> VPN L2 -> Proxmox -> bridge with VPS -> VPS