

So I have a NAS running Ubuntu I only keep my movies, my Jellyfin, and torrent software on in an isolated VLAN I stream from. I would think this would make any security issue with Jellyfin a dead end. I stream all content from Jellyfin domain I made and never use it locally. I stream off it at home from my VPN. This seems a safe way to stream where it can be used away from home unless I am missing something? Pointing out any holes in my logic is appreciated.
The VPN is a paid no-log VPN out of Panama. The traffic goes through the VPN applied to the VLAN and my device I stream to uses a different connection to the same VPN service. The domain is a DDNS.