HomeAssistant, all IoT devices are on a VLAN that can only talk to HomeAssistant...HomeAssistant server only accessible via LAN or through WireGuard to my VPS (which WireGuard's to my router, which connects to my HA server).
Not perfect, not invulnerable, but it also only controls lights and harmless switches.

VHCOL area (San Francisco)
"middle class" usually means household income of 300k or so.