Security of the Elastic Cloud Hosted platform?

Please, correct me if I am wrong.

A Elastic Cloud deployment resides on the chosen cloud provider (may be GCP, Amazon, Azure).
It belongs to a "project" that owns (I am using a GCP term here, with which I am familiar more than Azure or Amazon). The security at rest paradigm allows to say that the data on the elasticsearch servers won't be accessible to other actors on the same "project".

The servers in the deployment seem to be inaccessible to the customer via SSH. But is it the case also for personnel?

Do they have the possibility to access these servers if the customer has changed the deployment passwords?

Where can I find this information in the Terms & Conditions of the Cloud Hosted offering?

Thanks in advance,

