Without restricting access directly on the server, you will never be safe.
Also read FAQ.

Restrict user's access to directories above default

I would like to create a restricted version that has values for sessions pre-loaded. I see that I can do this. As part of this, I would like to prevent the user from traversing to the parent of the default directories and also prevent users using the Custom command, the Open Terminal, the Open in PuTTY, restrict users from using Change Directory to go outside the tree with Default Directory as the root. Finally, I would like to have users unable to view session configuration data so they are unable to download unrestricted WinSCP and circumvent the restrictions.

The restricted version is important because we want to make reports available to partners in China without allowing access to the rest of the server.