Thanks for that. So PG de facto has absolutely no security while in transit then. That is what we are trying to establish.
Your definition of "in transit" is unusual...someone obtaining a copy of a backup (or any data files) is generally considered "data at rest". Data in transit is stuff flowing on the wires when you, e.g., connect psql to the database and makes queries. The server is capable of leveraging SSL to setup secure tunnels for data in transit. The server does not itself encrypt data at rest whether it is the data files, WAL, or in-memory data buffers. Supplemental options in this area are present but I am unfamiliar with them.