Move it behind nginx. There are many guides about running services behind nginx. We don't have docs for that though because typesense is already using a production ready http server so you can directly expose it on port 443 (https) but I do get your customer's concern.