A good first step would be to provide a way to secure REST services. @starksm64 has started working on Elytron support.