I'm not exposing it to the WAN, just the LAN. :\
I don't think people really appreciate how massive of a security difference that is. It doesn't matter how big your budget is if you sit on the WAN all day. Someone will _always_ tag you eventually.
LAN with hardened VPN/SSH setups are virtually impossible to get into in a software-is-at-fault kind of way. And even if they did, they'd then have to launch the attack from someone's workstation at which point you've already been compromised anyway.
Oh, and then to get to the chat service they'd still need to break the security of an open source chat service which is non-trivial.