Self-hosted MCP servers for company documents
Most self-hosted MCP servers for documents are built for one person: point it at a folder, connect your own assistant, and everything in the folder is fair game. A company needs one more thing. When twenty people connect their assistants to the same server, each one should receive only what that person may read. This page sets out what that takes and lists the self-hosted servers that document it, as of September 2026.
Updated
01What a company server needs
A document server that several people's assistants share has to answer six questions. A single-user tool can skip all six.
- Who is asking? Each assistant signs in as a person, or as an agent that acts for one, with its own token or its own OAuth sign-in. A shared key cannot tell the finance team's assistant from the front desk's.
- What may that person read? A rule per document or per folder, checked on every question, so a removed permission applies to the next one.
- When is the rule applied? Before anything is ranked, or after. Our page on permission-aware RAG explains why the order matters.
- What can the assistant do? Read only, or also write, move and delete.
- What about old or unreviewed material? Superseded drafts, expired procedures, and text another AI wrote that nobody has checked.
- What is kept? A record of who asked what and what each assistant was given.
02Single-user servers
These are good at what they do: one person, one machine, their own files. None of them documents per-person permissions.
| Server | License | What it documents |
|---|---|---|
| Minima | MPL 2.0 | "Operate fully on-premises with containers, free from external dependencies such as ChatGPT or Claude." It indexes a local folder and connects to the Claude desktop app over MCP. The only credential documented is a user name and password for one mode. |
| Cognee | Apache 2.0 | Agent memory and a knowledge graph you can "start locally for free without an OpenAI or Anthropic API key", with an MCP server. Access control is set up through a separate permissions guide "for deployment beyond a local demo". |
03Self-hosted servers that check who is asking
Each of these runs on infrastructure you control and documents some form of per-person access for assistants that connect over MCP. What each one says, in its own words:
| Server | License | Who may read what | How assistants connect |
|---|---|---|---|
| Onyx | MIT core; the enterprise directories under the Onyx Enterprise License | "All of your existing Onyx permissions and access controls are enforced automatically." Syncing permissions from source systems is an Enterprise Edition feature. | An MCP server; clients present "either a Personal Access Token or API Key". |
| PipesHub | Apache 2.0 | "Access is resolved when the query runs, against the source system's own permissions, instead of being approximated at build time." | An MCP server and client; "an agent connects as a specific person rather than as the application". |
| Archestra | AGPL 3.0 core, plus an enterprise license | "Auto-sync permissions mirrors the source system's access control into Archestra", an Enterprise feature (free in production under 30 users). Chunks the user cannot read are removed after ranking. | Its MCP gateway, with OAuth 2.1 or an identity provider's tokens, gives agents a query_knowledge_sources tool. |
| Arkon | PolyForm Internal Use 1.0.0 (source available) | "Hard scope enforcement: members only see knowledge from their assigned departments or the global realm - at the API, MCP, and search layers." | OAuth 2.1 with PKCE: "just add the server URL and sign in through the browser". |
| Elasticsearch, self-managed | Elastic's licenses | The network drive connector stores each file's access list once document level security is on: "Permissions are not synced by default." | The Agent Builder MCP endpoint (Elastic 9.2 and later). Per-person OAuth, where "each person consents separately", is documented for Serverless; self-managed clients use API keys. |
| Kiteworks Secure MCP Server | Proprietary | "Kiteworks enforces enterprise role-based and attribute-based access controls on every AI data interaction", over content stored in Kiteworks. | OAuth 2.1 with dynamic client registration and PKCE; "each organization deploys its own private Kiteworks MCP server". |
| Nextcloud Context Agent | Nextcloud's open source licenses | Serves Nextcloud content to "other large language models or applications" over MCP. | An MCP server; "MCP services that require different access tokens for each user are not currently supported." |
| NVIDIA AI-Q blueprint | Apache 2.0 | A research agent that reaches "per-user OAuth-protected MCP sources"; the sources decide what each person may read. | "The standalone, stateless Streamable HTTP server"; deployed with Docker Compose or Helm. |
| Mindbreeze InSpire | Proprietary | Ships as an "appliance box" integrated into your data center. | Its release notes add InSpire tools for AI agents over the Model Context Protocol. |
| Credal | Proprietary | "Every tool call respects the user's existing access." Runs "Air-Gapped On-Prem", on your self-hosted Kubernetes. | A platform "where teams build and govern MCP servers", queried "from Claude, ChatGPT, Cursor, or your own apps". |
04Questions to ask any of them
- Does each assistant get its own credential, tied to one person, or does a team share a key?
- Are permissions read from where the files live, or written into the server by an administrator? Either can be right; you should know which.
- Is the permission check applied before the search ranks anything, or after?
- If an assistant asks for a document it may not read by its exact path, does the server say it is forbidden, or that it does not exist? The first answer confirms the document is there.
- Can a connected assistant write, move or delete anything?
- Are superseded, expired or machine-written documents treated differently from current ones?
- Does the log keep what each assistant was given, and where that assistant's model runs?
Where PremAgentic fits
PremAgentic is a self-hosted server built for the company case. It indexes the Markdown, text, PDF, Word and Excel files your organization keeps and gives your people and your AI assistants cited passages out of them, with your rules enforced before anything is retrieved.
- Who is asking. Every agent has its own token. An agent that acts for a person holds exactly that person's access and never more.
- Who may read what. Set in PremAgentic, folder by folder: ordered allow and deny entries, where the first entry that names the caller decides and no entry means no. Checked on every search.
- Read only. Two read-only MCP tools. A document the rules hold back is reported as absent, not forbidden.
- Old and unreviewed material. Superseded material is held back unless a caller asks for history; a document that declares a machine author is held from agents until a person has reviewed it; past its stale-after date, it is flagged for people and held from agents.
- The record. Every question is logged with who asked, the text of the question, where the assistant's model ran and the passages returned.
It runs on your own servers, Windows or Linux, on stock PostgreSQL 14 or later, with a local embedding model. PremAgentic is open source under the GNU Affero General Public License 3.0. The code is at github.com/premagentic/premagentic, and the latest release has the Linux and Windows archives.
Sources
Every fact about another product comes from that product's own pages, read on September 27 and 28, 2026.
- Minima README
- Cognee README
- Onyx MCP server; Onyx Enterprise Edition; Onyx license
- PipesHub README
- Archestra knowledge base; MCP gateway; pricing model
- Arkon README
- Elastic network drive connector; Agent Builder MCP server
- Kiteworks MCP; Kiteworks developer docs
- Nextcloud Context Agent
- NVIDIA AI-Q blueprint
- Mindbreeze deployment options
- Credal; Credal security