They see all the traffic in cleartext. Plus you have to trust them not to maliciously alter your traffic. As a US company, their options may be limited if they are coerced by their government to do so.
Just use TLS / mTLS over the tunnel, no?
Just use TLS / mTLS over the tunnel, no?