MCP servers · GPL-3.0
An empty rule set authorizes nothing.
SAPÉ builds Model Context Protocol servers that let an LLM client reach your files and your databases — and refuse every operation you did not explicitly allow. You write the rules. You read back what the model did.
Permission model
What the rules actually guarantee.
Default-deny permissions
Configuring a connection makes it reachable. It authorizes nothing. The rules decide what may be done with it.Nothing granted behind your back
Rules come from one place: the desktop app. No default rule is ever seeded — not for your home directory, not for any database.Credentials never leave the machine
Database passwords go to the OS keyring, with an encrypted local fallback. No tool accepts, returns or logs one.Built for MCP clients
Runs over stdio for Claude Desktop or any Model Context Protocol client, with a desktop GUI for writing rules.Products
What SAPÉ ships.
Two MCP servers, released. More are in development and follow the same staged, user-gated build process.
SAPÉ f-MCP
Controlled file system access for LLMs, with a permission database you actually manage. Create, read, edit, delete, move, copy, list, chmod, download, upload — each checked against an explicit per-path rule.
A link planted inside an allowed directory can't be used to reach a path no rule covers.
Verified: Windows, Linux · macOS untested
Join and contributeSAPÉ d-MCP
Permission-gated database access for LLMs, with a rule database you actually manage. 38 tools across MS-SQL, PostgreSQL, MySQL/MariaDB and SQLite — drop and edit are never granted, on any rule.
Every table, view, function and procedure it creates is create-once.
Verified: Linux · Windows & macOS unverified
Join and contributeUnder construction
More SAPÉ products are in development. They will be here for download and collaboration soon.
Profile
SAPÉ smart bud
SAPÉ designs permission-gated tools that let LLM clients work with real systems — file systems, databases — without stepping outside an explicit rule. Every tool ships with a desktop interface for writing those rules, approving what needs approval, and reading back what a model actually did.
SAPÉ smart bud also works in logistics for technical and industrial operations: first analysing how material, people and time actually move through an operation, then building the software that plans, tracks and reports on it. The same principles apply — explicit rules, and a record of what actually happened.
SAPÉ smart bud is built and maintained by Luciano Arrezze. Both current products are released under the GPL-3.0-only license and documented in the open — including what is not yet verified.
Contact
Tell us what you're trying to build.
Fill in the form below and we'll get back to you at the address you provide.