Do you expect us to open the port on public interface?
As far as I know, postgres authentication is rather simple and exposing the port does not easily add huge liability.
This is really a trade-off between ease-of-setup and better security. We're eager to talk to (a lot of) users to see what there current setup is and how PGBackup could add some value for them.
Famous last words of security on the internet.
Edit to add why: You'll have full reachability between pgbackup and your customer's servers without opening ports inbound on either side. Traffic is also encrypted :-)
Disclaimer: I am part of Wormhole Network.