Web apps secure mode encryption

When enabling the “Web apps secure mode” option, I noticed that WorkflowGen only encrypts values to Base64 format. That does not seem really secure to me. Is this by design or a bug? Shouldn’t WorkflowGen encrypt the values using an encryption key instead?