Reading the documentation for the snapshot agent - as an enterprise feature - and the parameter aws-s3-server-side-encryption i would guess the oss ones are not encrypted.
Personally i would store the snapshot on a network storage, not the server/ cluster itself. You could encrypt the backups using pgp.
I think they should be handled like every backup: with care. 