[tor-talk] Securing a hidden service

I'm trying to make my hidden service more secure. It runs on a server
running Ubuntu 12.04.1 LTS server version. I have set up full disk
encryption and a basic firewall but I want to do more. If an attacker
managed to compromise nginx or apache (whichever I decide to use), is there
a way I can prevent the web server from sending any data outside of the Tor
network? An apparmor profile or something?


