Subject: I assume you are copying the .nsf off of the server
In which case you can enable encryption on the .nsf’s via the admin client I believe & then run compact -c. This will encrypt the .nsf’s and they can then only be opened using the server .id file.
go to application properties and encryption settings.
There is a CPU hit for enabling encryption, but it depends on what level of encryption (not certain if you can select anything other than strong these days).
You should be able to google it, there might be a red book, but don’t know for certain.