

It absolutely does but you have to do it yourself, they dont accept any liability for doing that and nor should they, so if you dont know how to do it with at least the minimal level of safety and security and accept that risk yourself then you really shouldn’t try. Ideally you would only do it via a private VPN to trusted users.
Plex has some features built in to make just opening the port reasonably safe, though I’d still recommend against that. They also have a reasonably secure account verification system, and the software itself has proven to be somewhat safe.
Jellyfin has very little security built in and is not intended to be public facing, it also has the double edged sword of being open source, so you could read through all the code and pick it apart for flaws and exploits if you wanted to and we all just trust that when exploits or flaws are found they are reported properly.
JF is great but you are on your own if you want to make it available via WAN.
I’ve always kept my apps and databases on solid state media, putting them on spinning rust, even in a well tuned ZFS pool with lots of disks is way too slow for their (admittedly inefficient) database.