Since it uses SSH to transport the initial session password, as robustly as SSH is.
A one-time shared passkey is sent over ssh and then this passkey is used to encrypt/decrypt the data in both directions. The server and the client have different initial nonces.
> ET does not implement any of the SSH protocol
That implies they rolled their own wire protocol. Maybe they did a good job (like mosh appears to have done). More likely not. I'd be OK using this on an internal network or over a VPN, but relying on it alone for security would be premature.
--Edit--
A quick glance at the repo suggests they're using NaCl to handle the encryption + the SSH server for auth