Hi Vincent,
RequestFactory is not inherently any more or less secure that GWT RPC. With either approach, you should protect RPC calls for sensitive data with SSL and protect against XSRF attacks by sending a token with each request payload. For more info, see
As for the second part of your question, you are correct. On the client side, RequestFactory works with proxy (interface) representations of entities. RequestFactory automatically converts between the proxy representation and the server-side entity when sending / receiving.