Microsoft Sovereign Cloud Azure — including Sovereign Landing Zone and Azure Local
Azure services maintain control-plane connections to Microsoft endpoints. Azure Dedicated HSM and the Hold-Your-Own-Key option exist (criterion 2 partial), but the HSMs are racked in Microsoft facilities and operated by Microsoft personnel. The runtime is closed source. Audit substrate is Azure Monitor / Sentinel. Hardware is Microsoft's, even in the "Sovereign Landing Zone" and Azure Local SKUs.