diff --git a/sites/default/config/.htaccess b/sites/default/config/.htaccess
new file mode 100644
index 000000000..91883a339
--- /dev/null
+++ b/sites/default/config/.htaccess
@@ -0,0 +1,23 @@
+# Deny all requests from Apache 2.4+.
+
+ Require all denied
+
+
+# Deny all requests from Apache 2.0-2.2.
+
+ Deny from all
+# Turn off all options we don't need.
+Options None
+Options +FollowSymLinks
+
+# Set the catch-all handler to prevent scripts from being executed.
+SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006
+
+ # Override the handler again if we're run later in the evaluation list.
+ SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003
+
+
+# If we know how to do it safely, disable the PHP engine entirely.
+
+ php_flag engine off
+
\ No newline at end of file
diff --git a/sites/default/config/README.txt b/sites/default/config/README.txt
new file mode 100644
index 000000000..e2f975482
--- /dev/null
+++ b/sites/default/config/README.txt
@@ -0,0 +1 @@
+This directory structure contains the staging config for your site.