hey, this is correct. If you're using the SaaS backen and you're in the same organization, it will be decryptable by anyone in that organization, assuming they have read/write permission to that stack.
As an alternative though, you can also set up the encryption using a cloud secrets provider when you create the stack, so you can use AWS KMS/Gcloud Secret store etc. There's more information about this here:
https://www.pulumi.com/docs/intro/concepts/config/#available-encryption-providers