Proof without prior knowledge exists. It's called a cryptographic attestation. TPM quote, signed by the hardware, includes the PCR values that identify the specific boot chain.
But no datacenter remote hands is running tpm2_quote for you. The tooling gap is real.