Agents read cleaned copies of your files: PII replaced with local consistent tokens. Read-only.
Your AI agent reads everything. This gateway hands it redacted copies instead.
AI agents are getting file access — and they over-read. Israel's Privacy Protection Authority put it bluntly in its guidance on AI agents: an email-sorting agent can analyze 15 years of correspondence for a 2-year task, infer your health and finances along the way, and leak what it learned. Their recommendation: strict permission minimization — read-only, dedicated folders, minimum necessary data.
balmas-mcp turns that advice into code, and goes one step further: it minimizes not just which files the agent reads, but what's inside them.
PERSON_001, ID_001)
before the content is returned. Secrets too: API keys (OpenAI,
Anthropic, GitHub, AWS, Stripe, Slack…), JWTs, private-key blocks,
password: values and .env credentials become SECRET_001 at every
level — and are never written back by restore_text. The same person is PERSON_001 in every
file, so the agent's reasoning stays coherent. Detection runs in this
process — deterministic patterns, lexicons and checksums (Israeli ID
included). Hebrew and English.restore_text maps the tokens in the
agent's final output back to the original values — locally.Read-only by design: the server exposes no write tools at all.
bk_...) at balmasai.com/app/team.{
"mcpServers": {
"balmas": {
"command": "npx",
"args": ["-y", "balmas-mcp", "/Users/me/Documents/work", "--level", "strict"],
"env": { "BALMAS_API_KEY": "bk_..." }
}
}
}
Options: allowed folders as positional args (required, one or more) ·
--level standard|strict|maximum (default strict).
| Tool | What the agent gets |
|---|---|
list_files | Names, sizes, types inside allowed folders — never contents |
read_clean_file | The file's text after local anonymization |
restore_text | Real values back into its output (session tokens only) |
Supported inputs: txt csv md docx xlsx pptx pdf (text layer).
| Leaves your machine? | |
|---|---|
| File contents | Never |
| File names / paths | Never |
| The replacement map | Never |
| Metering counters (file type + item counts) | Yes — that's all |
Each file read counts as one document against your account's monthly quota (free 10 / PRO 200 / TEAM 1,000). Full processing happens in this local process.
Built by BALMAS AI — sensitive data stops here. Docs: balmasai.com/mcp
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y balmas-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"com-balmasai-balmas-mcp": {
"command": "npx",
"args": [
"-y",
"balmas-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencebalmas-mcpnpmcom.balmasai/balmas-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.