Hi,
To prevent an Orion account from accessing configs through the UI, you must not let the user access NCM at all. This can be done by assigning NCM Role "None" (Settings -> Manage accounts).
NCM always stores the downloaded configs to the SQL DB. Thus, you must secure your DB in order to prevent unauthorised access.
Depending on your settings NCM may also store a copy of each config in Config Archive directory. (See NCM settings for exact path.) You can either disable this option or make sure the folder is not accessible to given users.
Feel free to ask for details on either option.
Regards,
Jiri