remote control has both a socket only mode, and has the ability to allow tty connections only with a password: https://sw.kovidgoyal.net/kitty/conf/#opt-kitty.allow_remote...
Furthermore, remote control in kitty has capability based security where you can lock down the protocol to allow individual actions with arbitrary granularity:
https://sw.kovidgoyal.net/kitty/conf/#opt-kitty.remote_contr...