Encryption, screen lock, OS update status, antivirus presence, and Tailscale when installed.
Device-posture evidence for small professional teams
Professional trust should be demonstrable.
Klevely checks the security posture of enrolled Windows, macOS, and Linux devices and turns the latest reported signals into timestamped evidence for clients, insurers, and reviewers. It supports the device access-control and monitoring part of a security program. It is not a certification or a full compliance program.
The agent reports posture results on a 15-minute cadence while it is running.
A single dependency-free Python file, published for inspection.
No files, documents, history, keystrokes, user credentials, or traffic are read.
The product
The latest reported device posture, without the enterprise stack.
Klevely is a lightweight agent, a fleet view, and a timestamped evidence record. It is built for the small firms that still handle serious data but do not have a security operations team.
Enroll each work device
Use one guided command on Windows, macOS, or Linux. The installer verifies the agent's published digest before it runs.
See the latest reported posture
Checks report security configuration to one fleet dashboard, with the result and reporting time recorded.
Answer with a record
Use the latest timestamped posture record when a client, insurer, internal review, or questionnaire asks about device controls.
What the agent checks
Five bounded signals.
Each check is intentionally legible. The public agent shows exactly what is read and transmitted.
Why Klevely exists
The environment of professional trust changed. Most of its assumptions did not.
Client data left the filing cabinet. Work moved into cloud systems and onto laptops outside a central office. At the same time, clients, insurers, procurement teams, and regulators began asking for evidence instead of reassurance.
Klevely exists to help small businesses and independent professionals treat trust as the strategic asset it is becoming—starting with device posture that can actually be checked.
Read the Trust SeriesEvidence beats assertion
The latest reported configuration result is more useful than a policy sentence copied into another questionnaire.
Scope should be explicit
One product cannot make a firm compliant. Klevely says exactly what it checks, what it supports, and what it does not prove.
Small teams deserve serious tools
No 50-seat starting point. No enterprise implementation project. The evidence need is real even when the team is small.
Solutions
Start with the question in front of you.
Choose the profession, framework language, or evidence request that matches what you need to answer.
Device evidence for the Safeguards Rule file
For small accounting firms that need timestamped evidence for the device access-control and monitoring slice, without a full compliance-platform rollout.
Support device-security questions in reviews
For firms handling borrower financial records that need a clearer device-security record for lender, client, and insurer reviews.
Replace “we believe” with a timestamped answer
For questions about encryption, lock configuration, OS update status, antivirus presence, and monitoring cadence.
Endpoint evidence, clearly bounded
Support endpoint evidence requests that use ISO 27001 language. Klevely is not ISO certification or a complete ISMS.
Clear scope
Useful evidence. No borrowed authority.
Klevely supports evidence for device access controls and monitoring, including 16 CFR 314.4(c) and (d). That is a meaningful slice of a security program. It is not the whole program.
Supports
Timestamped configuration evidence for encryption, screen lock, OS update status, antivirus presence, and a 15-minute reporting cadence.
Does not claim
Certification, audit, legal attestation, SOC 2, a complete Safeguards Rule program, or full compliance with any framework.
Important caveats
Screen-lock configuration is not an MFA attestation. Antivirus presence is not an EDR claim.
Data boundary
The agent transmits basic device identity, agent version, a report-authentication credential, and posture results. It does not read your files, documents, browsing history, keystrokes, user credentials, or network traffic.
Products and pricing
Use it once, or keep reporting on a 15-minute cadence.
Buy the one-off pack for a focused evidence request. Choose monthly monitoring when reviews, renewals, or internal checks will keep coming back.
From $19 / month
Keep the latest reported posture visible
For teams that want an ongoing fleet view and the latest timestamped record when the next request arrives.
$49 / once
Answer one device-security section
Thirty days of monitoring for up to five devices, a timestamped report, and a scoped answer sheet. No subscription.
- 14-day trial
- Flat monthly price
- No minimum seat count
- Cancel anytime
Ideas and resources
The larger question is trust.
Klevely publishes practical security thinking and a longer editorial series on how professional trust is changing in a cloud and AI-shaped economy.
Featured series
A six-part investigation into the changing environment of professional trust.
From procurement and cloud custody to AI and the coming verification economy: six arguments for why demonstrating trustworthiness may become a defining competitive consideration.
Explore all six essaysZero Trust isn't just for enterprise anymore
Why small teams need serious device-security practices without enterprise complexity.
Read articleYour clients already assume their data is secure. Is it?
What clients are placing in your hands when they send financial records, contracts, and credentials.
Read articleCybersecurity is also about winning work
How a clearer security story changes procurement conversations and client confidence.
Read articleOur direction
Trust is becoming operational infrastructure.
Klevely is building toward a world where a small professional firm can demonstrate how it handles trust without buying a platform designed for a security department. The standard is simple: verify what can be verified, explain the boundary, and make the evidence useful.
Direction, not a release promiseMore verifiable signals
Extend evidence only where a device can report a signal reliably and the result can be explained plainly.
Clearer evidence sharing
Make reports, answer sheets, and time-bounded proof easier to use in the reviews small firms actually face.
Small-team simplicity
Keep setup light, pricing legible, and the public agent inspectable as the product grows.
Frequently asked questions
Straight answers, with the boundary intact.
If your question is specific to a questionnaire or review, send it to hello@klevely.com.
What is Klevely?
Klevely is an open-source device agent and hosted fleet dashboard for solo professionals and small teams. It turns the latest reported device-security configuration signals into a timestamped posture record.
What does the agent check?
Disk-encryption status, screen-lock configuration, OS update status, antivirus presence, and Tailscale connectivity when Tailscale is installed.
What data does Klevely collect?
Klevely transmits a device hostname, platform and OS version, agent version, a device identifier and report-authentication credential, plus the five posture results. It does not read files, documents, browsing history, keystrokes, user credentials, or network traffic. The agent source and transmitted fields are public.
Does Klevely make my firm compliant?
No. It can provide evidence for the device access-control and monitoring slice, including 16 CFR 314.4(c) and (d)—2 of the Safeguards Rule's 8 elements. It is not a certification, audit, legal attestation, or complete compliance program.
Is screen lock the same as MFA, or antivirus the same as EDR?
No. Klevely reports screen-lock configuration as an access-control signal, not an MFA attestation. Antivirus presence is a baseline device signal, not an EDR claim.
Should I use the $49 pack or monthly monitoring?
Use the pack for one focused device-security questionnaire section or evidence request. Use monthly monitoring when client reviews, renewals, insurer questions, or internal checks will keep returning.
Which platforms and team sizes are supported?
The agent runs on Windows, macOS, and Linux. Klevely is designed for solo professionals and teams with up to 50 devices.
Start where you are
One evidence request, or an ongoing device record.
Choose the $49 pack for a single focused job. Choose monthly monitoring when the question will come back. If you are unsure, send us the question you were asked.