1) Full Disk Encryption
2) Two physical machines owned by you, perhaps stored in some basement
3) Be able to boot them back on without physical access (perhaps this is simply a Bad Idea?)
4) One machine with two NICs running Tor, exposing only Tor to one of the NICs
5) The other machine running a VM host with 1 VM for each of your services. The host is connected to the NIC of the first machine, thus only has access to the internet through Tor