Unix based operating systems have pretty great file system security and almost everything is based on the file system, and you can use unix sockets for networking. So you can for example create a new user, give the user access to only the folders it needs. Then run the program as that user.
You can also from within the app itself read configuration files, etc, then chroot, and setuid to continue as a non privileged user.
Then you can use Apparmor or se_linux to fine tune access.