DC's in a running in HP Vmware Cloud service

The company my friend works for use HP Cloud services.  This is a VMware service offering.

My friend has been asked to lok into the viability of putting all the GC/DC servers on the HP Cloud.

The worry is security around the virtualised domain controllers.  They don't want HP to have access to them.I know this defeats the point of using a 3rd party service.

My initial answer was either don't put then in the cloud or run your own.

Can security be limited instances a'la multi tennetted ?

Is it possible to encrypt the vmdk's ?

