Part of the security risk also is the number of different models. I’ve been tempted to try some other models, but how many do I want to give access to SSH or even my repo? Obviously there are ways to work with this, but it’s gonna run through some people‘s heads.
Because they siphon off data to US intelligence, and if you claim they don't, you couldn't possibly know because the CLOUD Act can mandate them to do so without telling you or allowing you to admit it. Of course, if you're in the US this doesn't matter but for the rest of the world it does.