You link to a file in the web site that has the file download server behavior that gets the file from the higher level and allows the user to download. That way you can add security assist validation on that page to prevent download by users that aren't logged in.
You don't link to the files directly, since there is no way to... that is why they are secure.