By default we use an RC4 based SSL-Like encryption with rolling keys.
You can also enable the use of TLS (SSL) within the port 3389 RDP payload which will perform true SSL encryption.
If you are using TS Gateway we use SSL between the client and the gateway and that drop back to one of the mechanisms above when we strip the RDP oout of the HTTPS.