In a very boring and traditional way: you buy a domain name, configure dynamic DNS, and then use port forwarding in your home firewall. No 3rd party proxies.
But I’m glad they’re not backdooring anything….
It’s how most companies operate (RBAC behind a private key challenge).
Exposing anything to the internet carries intrinsic risk, but exposing a VPN door is among the least risky of the available options, if internet accessibility is an essential feature. The only realistic compromise vectors are private key disclosure, bad VPN configs, or operating an outdated version of WireGuard with a known vulnerability.