I'm not sure what you mean by 'incredible security'. You have to choose the best trade-offs that suit you and your business. For example, you can choose to install Blesta on a server with no access to the Internet. That will cripple most attempts to circumvent the system since no one can access it, but that wouldn't make it very useful.
You can install Blesta on a server by itself, with the database on another server by itself. Ensure the web server has access to write only for directories that need to be written to by Blesta (typically the temp directory, uploads directory), which are not web-accessible. Other than that, there is no need to rename/delete files, directories, or chmod anything.