I'm guessing the SSH session between me and my friend is not encrypted end-to-end because of proxies and what not in between?
Presumably all this does is spawn a local SSH server with the appropriate authorized_keys file, and forward the TCP connection through the company's servers for NAT traversal. The actual connection is encrypted end-to-end.