Well, the standard provides for the encryption of AVPs so that intermediate nodes like relays/LBs can't access this confidential information. Encryption/decryption will be left to the applications at the two ends. But in practice I don't think this is used. TLS/DTLS security between peers will protect it over the wire...
rk