Why do you ever need a JSON (3-tiered application I guess)?
You said your requirements is simple 5 users application.
In your place (being novice), I would go for a good old simple direct SQL connection.
In case of security concerns (you think one provided by the SQL engine is not enough), use firewalls, ssh tunnels or other admin measures.