HA does have a REST API, but with the way PageNodes works you'd have to hardcode the HA password right into the PN workflow. Have you considered adding the equivalent of environment variables, which can be set in a PN account and used as placeholders in workflows?
That's a good question. Our storage is in local indexeddb. And the site is https, so no one should see your flow if you don't share it.
That said there's nothing stopping you from reaching out to another secure service or plugin before making requests.