An open-source GRC alternative that keeps what you chose it for¶
Teams pick Eramba or CISO Assistant for a reason that has little to do with price. Nobody can hide the record from you. You can read every table, export every row, and audit the tool itself. We built Kanonik to keep that property and take away the part you were still doing by hand. Your own AI drafts the controls, the risks and the policies. Every change it proposes is checked, approved by a person on your team, and sealed into a record your auditor can verify without asking us anything.
What you chose open source for, and what it looks like here¶
You never have to trust the vendor¶
Every Auditor Export is a signed bundle: the events, the chain root, the public key, and an open-source verification tool that runs in the browser with nothing sent anywhere. Your auditor recomputes the hash chain on their own machine, offline if they like. You can try it now at kanonik.ai/verify with the sample bundle, before you sign up.
The record is a plain event log¶
The canonical record is an append-only, hash-chained log of typed events, exported as JSON with its schemas. There is no proprietary report format between you and your own data, and a point-in-time query returns exactly what the record held on any date.
You choose where it runs¶
Kanonik is one Helm chart on any Kubernetes. Run it in the cloud we operate, in your own cloud account on AWS, Azure, GCP or OCI, or in your own data centre. Self-hosted and air-gapped deployments are on the Enterprise plan. Nothing about the product assumes a particular cloud.
No per-seat tax, no renewal surprise¶
Solo is $99 a month with the full product. Extra users are $9.99, additional frameworks $499 one-time. The base price changes only by a sealed public event and never rises at renewal, which is the clause open-source teams usually leave commercial tools over.
The work moves from your keyboard to your AI¶
In an open-source GRC tool you author every control, risk and policy by hand and the tool stores it. In Kanonik you connect the AI client you already use (Claude, ChatGPT, Gemini, Bedrock or Azure OpenAI) over MCP, load a signed Kanonik skill, and ask it to draft the work from what is actually deployed. A server-side Verifier checks every proposal before it can land, rules first and then a second model on separate credentials. A single-use, signed approval gates every write, and a person clicks it. Only then does the change go on the chain.
Frameworks load as versioned packages. ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0 and HIPAA ship today. Controls and evidence are authored once and projected onto every framework you activate, so adding a framework is a package, not a rebuild. We add new ones in days, and more are on the way now; if you need one that is not on the list, ask.
Kanonik does not connect to, import from, or write to Eramba or CISO Assistant. It replaces them, with a migration path: hand your existing exports to your own AI through its own tools and ask it to propose the equivalent record. Every proposal passes the Verifier and your approval first.
Who this is for¶
A 25 to 200 person team that chose open source for control of its own record and is now spending more time typing controls into forms than running a security programme. If you rely on a decade of built-in workflow modules for incident handling or policy review cycles, the open-source tools have those and Kanonik expresses that work through skills your AI runs instead. If what you want is a record nobody can quietly edit, an AI that cannot commit anything unchecked, and an auditor who can verify the whole chain offline, that is what we built.
Questions open-source GRC teams ask us¶
Is Kanonik an alternative to Eramba?¶
For a 25 to 200 person team, yes. Kanonik replaces the GRC tool rather than sitting beside it. Your own AI does the drafting and assessment, a server-side Verifier checks every change, a person approves it, and the result is sealed into a hash-chained record you can verify without trusting the vendor.
Does Kanonik integrate with Eramba or CISO Assistant?¶
No. There is no connector, import or write-back to any GRC platform, by design. To move, hand your existing exports to your own AI and ask it to propose the equivalent controls, risks and policies in Kanonik. Each one goes through the Verifier and your approval before it lands.
Can we self-host Kanonik?¶
Yes. Kanonik is a single Helm chart that runs on any Kubernetes, in any cloud or on your own hardware, including air-gapped. Self-hosted deployment is on the Enterprise plan; the hosted service is the same software.
Is Kanonik open source?¶
The product is commercial. The offline verification tool that ships inside every Auditor Export bundle is open source, and it is the same bytes you can run at kanonik.ai/verify. That is the part that matters for trust: you never need Kanonik's servers, or Kanonik's word, to confirm the chain.
What does Kanonik cost compared with open-source GRC?¶
Solo is $99 a month or $990 a year and includes one user and one framework. Pro is $399 a month or $3,990 a year. Additional users are $9.99 a month, additional frameworks $499 one-time. Both plans start with a 14-day trial; a card is taken at signup and first charged on day 15. The base price never rises at renewal.
Which frameworks does Kanonik run today?¶
ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0 and HIPAA. ISO 27001 and SOC 2 run against your own licensed copy of the standard text. New frameworks are added as packages in days; ask for the one you need.
Runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0 and HIPAA today, in any cloud or your own data centre. Check a sample export yourself at kanonik.ai/verify. Try Kanonik free for 14 days at kanonik.ai.