Protection against a rogue hypervisor is the main benefit of SEV. The whole point is to raise VM security to equivalent of a bare metal machine with encrypted memory and no exposed DMA channels. Protection from other guests is a nice side effect but should be a given
Sadly this means AWS are still the only ones offering this kind of confidential computing without known flaws, and probably only because they don’t have researchers attempting attacks like this on their graviton CPUs