Any files in the web tree that can be serverd by IIS are going to be visible/discoverable, so it's never advisable to put confidential information there even if you think it's hidden somehow (security through obscurity=inevitable failure). If you need to restrict files only to members of a particular security role, you should use the Shared Files module to restrict them to the roles you want.
Jamie