Ultimately, yes, it comes down to trust. Trustlessness is a crucial component of decentralization.
yep either consolidation or more tech needed to prove security or somehow guarantee it. one option would be to enforce certain security standards on the provider side