KVM Fleet
Access governance and tamper-evident audit for out-of-band server management.
KVM Fleet is a management platform for your servers' out-of-band controllers — enterprise BMCs (Dell iDRAC, HPE iLO, Supermicro, Lenovo XCC and other Redfish/IPMI BMCs) and IP-KVM devices (PiKVM and other KVM-over-IP appliances). It gives IT, MSP and compliance teams one place to govern who can reach those interfaces, log every action, and hand an auditor verifiable evidence.
Why KVM Fleet?
The out-of-band layer — iDRAC, iLO, IPMI, PiKVM — is usually the one place with no real access control or audit trail. A shared admin password, a handful of people who know it, and no record of who power-cycled a host, mounted virtual media, or opened a console — until an auditor or an incident asks who could reach that BMC and who actually did.
KVM Fleet solves this with:
- One dashboard for every BMC and IP-KVM, with real-time status
- Just-in-time access — time-limited, approved access instead of a shared BMC password
- Tamper-evident audit log — SHA-256 hash chain with customer-owned signing keys, verifiable offline
- RBAC + SAML SSO across the fleet
- Console + power control — browser-based, audit-logged (BMCs via Redfish; IP-KVMs via an outbound-only agent — no port forwarding)
- Compliance reports — one-click evidence for NIS2, SOC 2, ISO 27001, GDPR, HIPAA, NIST 800-53, DORA, with an auditor share-link
- MCP integration — AI assistants can query and act on your fleet via the MCP server
Quick links
- Quick Start — get running in 5 minutes
- Redfish / BMC setup — enrol an iDRAC, iLO, Supermicro or Lenovo XCC
- Install the Agent — one-command install on an IP-KVM device
- API Reference — REST API documentation
- Architecture — how it works under the hood
- GitHub: Agent — open-source agent (Apache 2.0)
Platform
- Dashboard: app.kvmfleet.io
- Landing page: kvmfleet.io
- Status: Hosted on Hetzner (Falkenstein, Germany). NIS2 and GDPR compliant.