diff --git a/content/.htaccess.base b/content/.htaccess.base
new file mode 100644
index 0000000..5bbdf2e
--- /dev/null
+++ b/content/.htaccess.base
@@ -0,0 +1,14 @@
+DirectorySlash Off
+
+
+ RewriteEngine On
+ RewriteBase /
+
+ # Route /app requests to index.php
+ RewriteCond %{REQUEST_URI} ^/app/
+ RewriteRule ^(.*)$ /index.php [L,QSA]
+
+ # Don't rewrite if file exists
+ RewriteCond %{REQUEST_FILENAME} !-f
+ RewriteRule ^(.*)$ /index.php [L,QSA]
+
diff --git a/custom/data/petitions/.htaccess b/custom/data/petitions/.htaccess
new file mode 100644
index 0000000..2928f4a
--- /dev/null
+++ b/custom/data/petitions/.htaccess
@@ -0,0 +1,7 @@
+# Deny access to petition data files
+
+ Require all denied
+
+
+# Also deny directory listing
+Options -Indexes