Hm, you can just run it on an encrypted volume. And put an ngnix in front of it to handle https. There you go end to end encrypted.