MCP servers · GPL-3.0

An empty rule set authorizes nothing.

SAPÉ builds Model Context Protocol servers that let an LLM client reach your files and your databases — and refuse every operation you did not explicitly allow. You write the rules. You read back what the model did.

Engineer reviewing code on a monitor at a desk

Permission model

What the rules actually guarantee.

Default-deny permissions

Configuring a connection makes it reachable. It authorizes nothing. The rules decide what may be done with it.

Nothing granted behind your back

Rules come from one place: the desktop app. No default rule is ever seeded — not for your home directory, not for any database.

Credentials never leave the machine

Database passwords go to the OS keyring, with an encrypted local fallback. No tool accepts, returns or logs one.

Built for MCP clients

Runs over stdio for Claude Desktop or any Model Context Protocol client, with a desktop GUI for writing rules.

Products

What SAPÉ ships.

Two MCP servers, released. More are in development and follow the same staged, user-gated build process.

SAPÉ f-MCP

Controlled file system access for LLMs, with a permission database you actually manage. Create, read, edit, delete, move, copy, list, chmod, download, upload — each checked against an explicit per-path rule.

A link planted inside an allowed directory can't be used to reach a path no rule covers.

Verified: Windows, Linux · macOS untested

Join and contribute

SAPÉ d-MCP

Permission-gated database access for LLMs, with a rule database you actually manage. 38 tools across MS-SQL, PostgreSQL, MySQL/MariaDB and SQLite — drop and edit are never granted, on any rule.

Every table, view, function and procedure it creates is create-once.

Verified: Linux · Windows & macOS unverified

Join and contribute
In development

Under construction

More SAPÉ products are in development. They will be here for download and collaboration soon.

Profile

SAPÉ smart bud

SAPÉ designs permission-gated tools that let LLM clients work with real systems — file systems, databases — without stepping outside an explicit rule. Every tool ships with a desktop interface for writing those rules, approving what needs approval, and reading back what a model actually did.

SAPÉ smart bud also works in logistics for technical and industrial operations: first analysing how material, people and time actually move through an operation, then building the software that plans, tracks and reports on it. The same principles apply — explicit rules, and a record of what actually happened.

SAPÉ smart bud is built and maintained by Luciano Arrezze. Both current products are released under the GPL-3.0-only license and documented in the open — including what is not yet verified.

Contact

Tell us what you're trying to build.

Fill in the form below and we'll get back to you at the address you provide.

What are you connecting, and what should the model be allowed to do?