balmas-mcp
MCP serverFiles & storageAgents read cleaned copies of your files: PII replaced with local consistent tokens. Read-only.
Unavailable. This server has no hosted endpoint yet, so ahel can't serve it.
Connect ahel once, and every AI you use reads what you have installed.
From the project's README
As published by yaakovtzedek/balmas-mcp in README.md.
Your AI agent reads everything. This gateway hands it redacted copies instead.
Why
AI agents are getting file access — and they over-read. Israel's Privacy Protection Authority put it bluntly in its guidance on AI agents: an email-sorting agent can analyze 15 years of correspondence for a 2-year task, infer your health and finances along the way, and leak what it learned. Their recommendation: strict permission minimization — read-only, dedicated folders, minimum necessary data.
balmas-mcp turns that advice into code, and goes one step further: it minimizes not just which files the agent reads, but what's inside them.
How it works
- You allowlist folders. The agent can't reach anything else — enforced with realpath checks, not honor rules.
- Every read is anonymized locally. Names, ID numbers, phones, emails,
companies and amounts become consistent tokens (
PERSON_001,ID_001) before the content is returned. Secrets too: API keys (OpenAI, Anthropic, GitHub, AWS, Stripe, Slack…), JWTs, private-key blocks,password:values and.envcredentials becomeSECRET_001at every level — and are never written back byrestore_text. The same person isPERSON_001in every file, so the agent's reasoning stays coherent. Detection runs in this process — deterministic patterns, lexicons and checksums (Israeli ID included). Hebrew and English. - The answer comes back real.
restore_textmaps the tokens in the agent's final output back to the original values — locally.
Read-only by design: the server exposes no write tools at all.
Quickstart
- Create a free account at balmasai.com/signup (10 documents/month free).
- Create an API key (
bk_...) at balmasai.com/app/team. - Add to your MCP client config (Claude Desktop shown; Cursor and others are the same idea):
{
"mcpServers": {
"balmas": {
"command": "npx",
"args": ["-y", "balmas-mcp", "/Users/me/Documents/work", "--level", "strict"],
"env": { "BALMAS_API_KEY": "bk_..." }
}
}
}
Options: allowed folders as positional args (required, one or more) ·
--level standard|strict|maximum (default strict).
Tools
| Tool | What the agent gets |
|---|---|
list_files | Names, sizes, types inside allowed folders — never contents |
read_clean_file | The file's text after local anonymization |
restore_text | Real values back into its output (session tokens only) |
Supported inputs: txt csv md docx xlsx pptx pdf (text layer).
Privacy model
| Leaves your machine? | |
|---|---|
| File contents | Never |
| File names / paths | Never |
| The replacement map | Never |
| Metering counters (file type + item counts) | Yes — that's all |
Each file read counts as one document against your account's monthly quota (free 10 / PRO 200 / TEAM 1,000). Full processing happens in this local process.
Honest limits
- The gateway helps only when the agent reads files through it — grant it instead of raw filesystem access, not alongside.
- Detection is deterministic: excellent, not clairvoyant. Review output where the stakes demand it.
- Scanned PDFs (no text layer) need the OCR flow at balmasai.com/clean.
Built by BALMAS AI — sensitive data stops here. Docs: balmasai.com/mcp
Signals
- Last commit
- Sep 2026
- Weekly downloads
- 614
Advanced
- Delivery
- balmas-mcp MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
com-balmasai-balmas-mcp- Source
- github.com/yaakovtzedek/balmas-mcp