They do officially support the Permissive security policy, and it is intended to allow you to boot custom kernels. Running a fully-untrusted operating system kernel is an intended feature, even if they aren't going to give you support if something breaks in the upper layers.
They don't officially (!) support it.