Skip to content
Klyo Changelog

Compliance report evaluates the running install

The compliance report now evaluates your running install instead of restating policy. Each GDPR, SOC 2, and HIPAA control is checked as a live probe — secrets backend, SMTP, retention job, last verified backup, admin bootstrap password, registered routes, security policies, and audit counts — and reported as pass, warn, or fail with an evidence class. Controls that hold true by design are listed as such and excluded from the score, so the number reflects what is actually verified rather than what is asserted.

New checks cover backup freshness, whether the trash purge is scheduled, whether the bootstrap password is still in use, and whether two-factor authentication is enforced rather than merely available.

No action required.