I wouldn't be surprised if they encrypt them at rest, but at some point the weights have to be loaded into vram.