AWS RDS Database not in a VPC, no SSL

If an AWS EC2 Server is connecting to an AWS RDS Database, but the database + server are not part of a VPC, and there is no SSL setup on the database…

Does that mean the data is being sent over HTTP unsecured?

My understanding is that to protect your connection to your database, you need SSL to encrypt your connection to the database, OR need to have both components in a VPC so they are isolated from public traffic. No VPC, no SSL cert on your DB connection appears to be a unsafe configuration.