You also have to trust your VM host not to provide an emulated SGX (which is what https://github.com/sslab-gatech/opensgx is, unless I'm very much mistaken).
I think you're mistaken. Intel provides infrastructure to ensure you're talking to an enclave running on an actual Intel machine, and you can then do a remote attestation to verify the contents of that enclave.
I thought this was well known already? if you send your data to someone else's server (even if you are renting it), there is no way you can be reasonably sure it will remain untouched.
https://www.reddit.com/r/yishan/comments/4cub02/transparency...
Does that inform anyone's choice of cloud infrastructure?