So its been a crazy long time since i updated this post and even had time to work on this project. (i have since been running a far safer thermostat solution since then) but I am getting it going again.
To your point about IoT and the security needs for it, I actually work in the cyber security field and have been at it for over 10 years. I am aware of the design challenges required to make this work and keep it from being an access point for attackers. My goal is to have it only send out encrypted data and not allow anything inbound. Well at least not directly. I have an SSL vpn configured for my home with Dynamic DNS setup so I can remotely connect to my home as it is. I use this for my Home assistant system which has no route path to the internet configured.
Anyway, I have solved some of the issues I needed to deal with recently and should hopefully have a working prototype by the end of dec. Ill try to update this thread, or start a new one depending on if people are interested.