Business and Visionary plans only currently.
You can find out more at proton.me/support/smtp-submission
Expose a VPN endpoint on non standard port and keep everything else internal if you can. If you want things to be even nicer create a seperate vlan for your internal services or just firewall rules from your VPN to the needed ports on your services.
If you are even more paranoid send an email notification everytime the VPN server has a new connection or keep a default account/password on your services and monitor when some dumbass logs in with it.