Hassbian or Hass.io security

Hello,

I have a raspberry pi 3, and an AEOTEC ZWave stick.
I tried to use another home automation system, but had issues with detecting my devices.
Now I want to try Home assistant. One of my concerns is security. I read the advice. Keep your devices local. Currently I only want to access my devices when I’m home. Is hass.io set up in such a way that it blocks certain wan connections? Or do I need to configure my router for this?
If this is the case, is hassbian not easier, because you can add IPtables or UFW.
I really like the hass.io philosophy that I don’t want to spend hours configuring my pi, but rather set up my automation rules. For me this includes security.
I’m not a linux expert, so I’m looking for an easy answer.

Hope someone can help me.