Securing / encrypting HA to Shelly plus 1 data

I am going to be using a Shelly Plus 1 to open a door so starting to look into securing the comms as much as possible.

I have access to HA as https and password protected the shelly instance. The trigger is RPC over WS so my question is, is the HA → Shelly session encrypted by default or is it open ?

If it is not encrypted I guess I can use MQTT with TLS setup as one way of encrypting the data between the devices ?

“Generation 2 devices use the RPC protocol to communicate with the integration.”

Thanks