Compliance work you can actually prove.

AI can already write your policies and fill out your questionnaires. Kanonik makes sure that work holds up: every draft checked against your framework, approved by a named person, and sealed into a record your auditor can verify on their own - no need to take your word for it.

Works today with ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, and HIPAA. What your auditor accepts still depends on your program and your auditor.

Claudeacme-prod skill: kanonik-control-assessment

Three tools shipped this quarter. Reconciling our third parties against the SOC 2 and ISO supplier controls, from the app inventory and egress logs you gave me read access to.

10:04
okta.list_apps() aws.flow_logs --30d19 third parties
kanonik.get_estate()15 of 19 already mapped

4 process customer data. One has a service account whose key has not rotated in 412 days. Drafting the review and a remediation, then sending it to Kanonik to check.

10:09

yes, send the review to Sarah

10:10
Kanonikacme-prod recordread-only
Awaiting sign-off
Third-party risk review, 4 vendors

Proposed by your AI from the app inventory. Four vendors process customer data.

routed S. ChenCC9.2ISO A.5.19
Held by Verifier
Meterly DPA, claim unsupported

Your AI said a DPA is on file. No evidence link found, so this was not recorded.

confidence 0.41below the 0.60 bar
Risk
Northwind Warehouse, stale service account

Key last rotated 412 days ago. Remediation proposed.

detected 10:08severity high
Sealed
15 vendors reconciled, no change

Already mapped to current controls. Nothing to do.

happened 2026-08-27recorded 2026-08-27
bundle: acme-vendor-review-2026-08-27.tar.gz verify offline0.8s

Your AI does the work. Kanonik checks it, gates it, and seals it.

Skills guide the AISo it uses the right tools, schemas and evidence
A safety check on every outputNothing touches the record until it passes
You approve the writes that matterRight in the browser, named and revocable
A record your auditor can openSigned, hash-chained, verifiable without a login
The problem

AI can draft compliance work. It can't prove it's right.

Policies, controls, risk assessments, questionnaire answers: most of it's AI-drafted now. A draft isn't proof. Nothing says who checked it, or whether it'll hold up when an auditor, a customer, or your board asks. Kanonik answers that: every result checked against your framework, approved by a named person, sealed into the record.

A draft is not evidenceside by side
AI alone
"The organisation maintains monitoring of systems and networks to detect anomalous behaviour."
  • No approver
  • No evidence link
  • No prior version
  • Not verifiable
text
through Kanonik
Same wording, bound to control A.8.16, effective 2026-07-01.
  • Elena Cruz, CISO
  • 2 artefacts cited
  • Version history kept
  • sha256 f21a88be
evidence
verifyoffline
$ kanonik verify bundle.tgz holds up
no login
How it works

Work in your AI client. Govern every result in Kanonik.

Bring the model you already use. We bring the skills, the safety check, and the line between a draft and something you can stand behind.

  1. Step 1

    Your AI drafts the work

    It assesses a control, maps a framework, writes an evidence summary, or answers a questionnaire, in the tool you already use.

  2. Step 2

    A Kanonik skill shapes it

    The skill hands the AI the right tools, schema and evidence rules, so what comes back fits the record it is going into.

  3. Step 3

    The Verifier reads the output

    Before anything reaches the record, a server-side check goes through it. Some rules, some LLM review, a clear verdict.

  4. Step 4

    You approve it in the browser

    Anything that actually matters waits for a named person to sign off. The approval is scoped and can be pulled back.

  5. Step 5

    The record is sealed

    The event joins a signed, hash-chained history with two clocks on it: when it happened, and when Kanonik wrote it down.

  6. Step 6

    Your auditor opens it later

    You hand them a bundle. They run the offline verifier in a browser. They never need an account.

The gate

Nothing unproven gets into the record.

Drafts queue on one side. The Verifier reads each one, a named person signs off on anything material, and only then does the event get sealed into the chain. Work that fails the check goes back with a reason attached.

Nothing unproven gets inchecking
AI output
verifier + sign-off
your record
verifyoffline
$ kanonik verify --strict 0 unproven writes
no login
What this actually fixes

The parts of the job that were eating your week.

Turn a week-long questionnaire into a few hours.

The questionnaire skill drafts every answer from your live control record, and the Verifier checks it against evidence you actually have. Each answer points to a sealed control, so the buyer's security team can check your work too.

Security review0 / 120 answered
00:00
elapsed
3 weeks
was the old way
Do you encrypt data at rest?
answered from control A.8.24cited
Describe your access review cadence.
answered from control A.5.18cited
Is MFA enforced for admins?
answered from control CC6.1cited
Every answer points at a control and its evidence.
verifyoffline
$ kanonik answer --pack vendor-review 120 cited
no login

Stop rewriting the same control for the next framework.

Write the control once, the way you actually run it. Kanonik maps it to whatever framework you add next, the Verifier checks the fit, and the reasoning gets sealed with it. Add a framework later and nothing you already wrote has to change.

Map once, answer everywhere0 frameworks
your real control
Centralised log collection with 400-day retention
owner: Platformevidence: 3 artefacts
verifyoffline
$ kanonik map --coverage no duplicate work

See what was true on any given day.

Every sealed fact carries two dates: when it happened, and when Kanonik recorded it. Pull up any past day and the record reads exactly like it did then, even if you've changed it since.

Time travelas ofbitemporal
Two dates, kept apart: when it was true, and when you wrote it down.
Effective
2026-03-30
when it happened
Recorded
2026-04-02
when you knew it
25-1126-0126-0426-07
A.8.16 Monitoring activities Implemented
asserted by Elena Cruzimmutable prior versions retained
verifyoffline
$ kanonik export --as-of 2026-04-02 reproducible

Give buyers a trust page you can back up.

Generated straight from your sealed record, not a static PDF nobody's updated since the SOC 2 kickoff call. Every claim points back to the actual control and evidence behind it, so a prospect's security reviewer can check it themselves instead of emailing to ask.

trust.yourcompany.com live
Trust Center
Generated from the record.
ISO 27001
evidence sealed
SOC 2
in progress
GDPR
documented
Subprocessors
14 listed
Access control policy download
Pen test attestation download
verifyoffline
$ curl trust.yourcompany.com/proof signed index
public

Run every client from one place, without mixing them up.

Each client gets its own tenant, record, and chain, so client A's evidence can never end up in client B's audit. You work from one login. Each client's auditor sees only that client's evidence.

Your engagements3 tenants
Northwind Data2 need you
Acme Healthsealed
Riverbend Mutual1 gap
separate tenants
isolation
One record per clientno shared pool
One chain per clientno cross-reads
verify / offline
$ kanonik verify --tenant northwind scoped

Stop being accurate for exactly one week a year.

The weekly digest reads straight from the sealed record and shows what actually moved: evidence going stale, approvals still open, controls touched since the last audit. It's generated from what's true, so it can't flatter you.

Weekly digestthis week
staleEvidence past its review date4
waitingApprovals still open2
changedControls touched since the last audit7
sealedNew records this week19
Read from the sealed record, not from a task list somebody kept by hand.
verify / offline
$ kanonik digest --since 7d from the record

Find the risks that are actually yours.

Your AI reasons over your environment and proposes typed risks - threat, vulnerability, asset, impact - not a generic scanner list. Each one is yours to weigh and approve before it lands.

Risk registerRISK-118
threatCredential stuffing against the admin console
vulnerabilityMFA not enforced for administrators
assetCustomer DB, holds PII
impactMass exposure of customer records
likelihoodReasoned from your access review and egress logsHigh
treatmentReduce, proposed by your AI, awaiting S. Chenopen
verify / offline
$ kanonik verify RISK-118 typed, cited, yours
no login

Govern the AI you already run, on the same record.

Marketing runs one model, engineering another, sales a custom assistant. Track them as first-class, provable artifacts - model, data class, owner, risk line - on the same hash chain as your ISO work. You stop keeping a parallel spreadsheet to track the AI.

Model registerEU AI Act
gpt-4.1Support assistant, customer PIIRISK-141
sonnetCode review, no PIIPlatform
mistral-7bLead scoring, no data class declaredheld
Same canonical model, same chain as your ISO 27001 and SOC 2 work.
verify / offline
$ kanonik verify ai-governance EU AI Act Art. 12 present
same chain

The audit narrative writes itself, from the record.

The synthesis skill assembles an audit-defensible narrative from your sealed events. Every sentence traces back to a sealed record, so there is nothing to reconcile the week before the audit.

Audit narrativeA.8.16

Monitoring of production systems runs continuously; alerts route to the on-call rotation and are triaged against the documented SLA.evt_9f31c0a4 The control was reviewed and approved by E. Cruz on 2026-07-01.EV-2231

assembled by kanonik-narrative-synthesis v1.2.0, sealed
every sentence traces to a sealed event
verify / offline
$ kanonik verify narrative --strict 0 unsourced claims
no login

Fail the audit here first, on purpose.

An adversarial dry-run auditor scores your package before the real one - major and minor nonconformities, each citing the clause and the record behind it. It can flag, but it can't fix: remediation goes back through approval.

Readiness reviewbefore Stage 2
2major5minor3observations
majorA.5.19 supplier control: DPA claim has no evidence linkcl. 8.1
minorA.8.24 crypto policy not reviewed in 12 monthscl. 5.2
A read-only reviewer. It cannot change the record, and remediation goes back through approval.
verify / offline
$ kanonik audit --dry-run run before Stage 2
no surprises
Why it holds up

Built for proof.

Non-bypassable safety check

The Verifier runs server-side, inside the commit path, before anything lands. It is not an instruction in a prompt that a model can be talked out of, and it is not a tool your AI can choose to skip.

Real human approval

Agreement in a chat window is not consent. Every consequential write waits for a named person to approve it in the browser, scoped to that one change.

Tamper-evident record

Each approved change joins a signed, hash-chained history built for reconstruction later. The record cannot be quietly rewritten without the chain showing it.

Signed skill library

Kanonik skills are versioned and signed compliance workflows that load into your own AI client, and the exact version that produced a result is recorded on the chain beside it.

Bring your own model

Use the AI provider your team already trusts. Kanonik is model-agnostic, and your provider stays your direct contractor rather than becoming something you inherit through us.

No standing source-system credentials

Your AI reads the systems you granted it. Kanonik stores the compliance record and references to your evidence, not permanent production access to your stack.

Auditor-ready export

One bundle carries the evidence narrative, the approval record, the Verifier verdicts, the chain proof, the framework artifacts and the verification tooling itself. Your auditor checks it on their own machine, with no account and nothing uploaded anywhere.

Who it serves

One product, five ways people buy it.

Small enough to put on a founder's card. Solid enough for a regulated bank.

The same append-only record works whether it is one founder trying to get past a customer security review this week, or a financial institution that needs the control history to still make sense years from now.

1-5 people

Startups

You're the founder, and compliance is standing between you and the deal that would change your year. There's no security hire coming before this questionnaire's due. You write the policies. Kanonik keeps them true enough to pass without one.

6-50 people

Small teams

Compliance is somebody's second job here, probably yours. Every new security review used to mean a scramble. Now one person signs off on what's real, the evidence lives in one place, and there's no fire drill the next time a deal needs a clean export.

51-500 people

Growth companies

You're running more than one framework now, and you finally have someone whose actual job is compliance. They need named reviewers on the record, history they can pull up later, and an audit that doesn't mean reconstructing six months of Slack messages.

500+ people

Finance and government

At this size, "trust us" has never been enough for a regulator, a board, or an examiner, and an AI-written draft doesn't change that. Retention rules, separation of duties, and data residency are non-negotiable. Kanonik's trust layer was built to the FedRAMP Moderate standard from the first commit.

For consultants and vCISOs.

If you run compliance for other companies, as a consultant, a vCISO, or a managed compliance firm, none of the brackets above are really about you. You're several companies, not one, each with its own risk if something goes wrong. Every client gets its own tenant, record, and chain - no chance of mixing them up.

Compliance starts before headcount does.

Small AI-native teams do not need another GRC suite. They need the AI they already have to leave a real trail behind it, from the first customer security review onward, without waiting on procurement or a full-time security hire.

The proof is the product

Your auditor does not have to take our word for anything.

Every export carries its own verifier. Your auditor opens it in a browser, drops the export in, and it walks through the signatures, the chain, the verdicts and where each piece of evidence came from. It runs on their machine. Nothing is uploaded anywhere.

  • Signed PDF reportverifiable
  • JSON event bundle and chain rootverifiable
  • Human-readable HTML packverifiable
  • Framework mapping and public keyverifiable
  • Offline verifier (verify.html)verifiable
Check one yourself
2 steps / no account
  1. Download the sample audit pack

    A real Auditor Export, about 110 KB, .tar.gz. Synthetic data, sealed exactly the way a live one is.

    Download sample pack
  2. Drop the pack into the verifier

    The verifier opens in its own tab. Drag the file you just downloaded onto it. It unpacks the archive and runs all eight checks on your own machine. No account, no upload, no network call.

    Open the verifier

The eight checks it runs

  • Hash chain integrity
  • Chain-root signature
  • Verifier verdict presence
  • Separation of duties
  • Skill provenance
  • Reproducibility tuples
  • Prompt integrity
  • File checksums
The same verifier that ships inside every export, byte for byte.
Frameworks today

Multi-framework by design.

Available
ISO 27001:2022

Statement of Applicability, Annex A, evidence packs.

Available
SOC 2

Trust services criteria, control narratives, walkthroughs.

Available
GDPR

Records of processing, DPIA scaffolds, DPA replies.

Available
NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, Recover.

Available
HIPAA

45 CFR Part 164: administrative, physical and technical safeguards, plus breach notification.

Kanonik helps you create and preserve defensible compliance records. It does not guarantee certification, legal compliance, or auditor acceptance.

Pricing

Start your 14-day trial. Pay us when you actually seal something.

Two monthly plans, and your Proof Snapshot is free on both. The other prices below are for specific moments, and they only show up on the bill when you seal one. That is the whole price list.

Entry plan, Solo
$99 / month
or $990 a year, two months on us

Your first framework, the Verifier, the approval step, the hash-chained record. Cancel whenever. Your base price does not go up when you renew.

Starts with a 14-day trial. We check your card but do not charge it.

  • ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, and HIPAA. Your first framework is in.
  • Append-only event store, hash chain, two clocks on every record.
  • The Verifier and the signed approval step run on every write.
  • GDPR paperwork: RoPA (Art. 30), DPIAs, processing activities.
  • Bring the model you already use. No token math, no metering.
  • Your Proof Snapshot is free, as often as you want it. Free on Pro too.
  • Your first user is included; extra users are $9.99 a month each.
Pro is $399 a month, or $3,990 a year. It adds verified data flowing into your AI as it works, so answers come out already citing the record, and it includes one Sealed Audit Package a year. Both plans side by side on the pricing page.
What each sealed thing costs
Only shows up when you actually seal one
Free
Your Proof Snapshot

A sealed, point-in-time record of where you stand. Take one whenever somebody asks, as often as you like, on either plan. Whoever you hand it to checks it themselves, with no account.

$499
Turning on a new framework

One-time, for each framework past your first. You get the Statement of Applicability and the control mapping, drafted, checked and sealed.

$1,499
The full audit package

Per audit you close out. The Auditor Export bundle and the evidence narrative with each reviewer named. You only pay when you actually seal it. Inviting your auditor is free, read-only, and does not expire.

If a price changes, it changes through a sealed public event, not a quiet edit to this page. Your base price does not go up at renewal. One note on standards: ISO 27001 and SOC 2 run against your own licensed copy of the standard text; GDPR, NIST CSF 2.0 and HIPAA are public text, so there is nothing to buy. If you need something air-gapped, sovereign, or otherwise not on this page, write to us and a real person answers inside a business day. Full detail on the pricing page.
Trust posture

Where your AI stops and the record starts.

Your AI can draft and suggest, inside the boundary of a Kanonik skill. It cannot quietly rewrite the compliance record on its own. Kanonik checks what the skill hands back, makes someone approve it in the browser, notes who did, and keeps the trail so your auditor can walk through it later.

Sealed recordverified
A.5.1 Policies for information security
approved by Elena CruzCISO2026-07-01
eventevt_9f31c0a4
prev3d4e1c07
sha256f21a88be
signerkanonik-root / ed25519
verifyoffline
$ kanonik verify evt_9f31c0a4 signature valid
no login
  • Bring the model you already use. OpenAI, Anthropic, Bedrock, Gemini, Azure. Your AI provider stays your direct contractor.
  • Your AI holds the keys to your source systems. We do not.
  • We do not sit on standing production credentials for your stack.
  • The compliance record and the pointers to your evidence live in your tenant.
  • The evidence itself stays where you keep it, unless you explicitly record it.
  • Tenants are kept apart end to end. A vCISO working with two clients cannot cross the wires.
The proof is the product

Put proof around your AI compliance work.

Whether you're one founder trying to clear a security review this week, or the person whose name is on a program that has to hold up years from now, Kanonik gives your AI the skills to do the work well, checks what it hands back, waits for a person to sign off on anything real, and keeps a clean copy your auditor can open later.