If you use Suexec, you could change the permissions to 700, so only the user owning that site can read the files.
Also using stuff like jailshell, you should have the ability to lock a user out of other directories(though i have never tested this)
For the most part, a stock server without much...