Yes, a scan of a staging environment is acceptable for the security review, provided the staging environment is functionally equivalent to the production environment. However, keep in mind that SSL scans will still be performed on the production version, and invalid certificates are allowed on the staging version.
Using a middleware proxy server for callouts does not change the security scan requirements for the final endpoint. The final endpoint is still within the scope of the security review and must undergo security testing. This includes providing necessary credentials and scan reports, such as ZAP or DAST, for the endpoint.