Security implications of Vera's architecture

Can someone tell me if I’ve understood the following:

Vera provides a UPnP front end for all its z-wave devices, and other controlled items. (That’s one of its cool features). So anything z-wave attached to Vera is advertised via the UPnP protocol to the LAN.

So anyone who can connect to my LAN can quite easily detect and control all my z-wave devices because Vera advertises them all. Including the z-wave front door lock. And they only need a browser to do it, since everything has a url.

Is that correct?

Is there a way to configure a device to be monitored but not accept changes from Vera? For example, to run events when a correct PIN code is entered at the lock but not to be able to open the lock?

EDIT: although thinking about it, that kind of configuration change is going to be difficult to make meaningful unless there’s a way to secure entry in to Vera too.