Jitsi is built to run with a server managing the call. This is peer to peer, it appears.
Or can you?
The NAT hole punching is done by the STUN servers listed in script.js. They appear to be public third-party STUN servers, so that could be a vector for a malicious actor. There are also third-party TURN servers listed, which will relay media in the case that NAT traversal fails. That should be ok too, but could also be another attack vector.
Ended up deciding to spend the week configuring jitsi, but all it took was 1 hour to install and configure the server and I was done
The development of the frontend is a bit messy, but you'll manage