One error some people make, imo, is to move to self-hosted and not immediately take the time to establish some security…kind of like getting a new apartment with no lock on the door and then leaving to go get more of your stuff. Moving your content can go smoothly if you plan and prepare ahead like you are doing now, and I would suggest the same for security. There are various plugins that can provide that for you with just a few clicks, and BulletProof Security is my own recommendation:
1) Install and activate it;
2) Click “Create default.htaccess File”;
3) Click “Create secure.htaccess File”;
4) Activate Website Root Folder .htaccess Security Mode;
5) Activate Website wp-admin Folder .htaccess Security Mode;
6) Activate Deny All htaccess Folder Protection For The BPS Master htaccess Folder;
7) Activate Deny All htaccess Folder Protection For The BPS Backup Folder;
8) Click on the “Backup & Restore” tab and do a “Backup .htaccess Files”.
At that point you will have some very-solid security in place via .htaccess with even more features available, and none of that will ever interfere with your permalinks or anything else.
https://www.ads-software.com/plugins/search.php?q=BulletProof+Security