Hi Joel,
The requested feature to separate the web front end from the application layer is in our road-map, will keep you posted once it is implemented. As a workaround, you could deploy a reverse proxy in front of ADSelfService Plus server for secure external access with SSL enabled.