Kanonik

Capabilities

The substrate behind audit-defensible AI.

Your own AI does the compliance reasoning. Kanonik is the substrate underneath: a typed data graph, a non-bypassable Verifier, a real human-approval gate, a tamper-evident record, and a private signed skill library, all reached through MCP. Below is what each primitive does, and what it removes from your week.

The substrate primitives

Eight things the substrate gives your AI.

Each one is built for the full long-term product and framework-agnostic by construction. ISO 27001:2022 is the framework content that ships first; the architecture reads framework specifics from a loadable package, never hardcoded.

Canonical model

One typed system of record

A typed, bitemporal, event-sourced graph is the entire system of record. Every entity carries both when it happened and when it was recorded, so "what did our Statement of Applicability say on any past date" is one query. It is framework-agnostic; framework specifics load as a package.

Verifier

Non-bypassable, server-side

A two-tier check, deterministic rules plus an independent LLM cross-check, runs inside every commit before any write can land. It is not exposed as a tool your AI can call or skip. Low-confidence work routes to a review queue, never to auto-approve.

Approval gate

A real human click

Every external write requires a single-use, signed, payload-bound approval token with a 15-minute window, approved out of band of the AI conversation. In-conversation approval is never sufficient.

Hash chain

Append-only, FIPS-signed

Every change is an event chained to the hash of the one before it, with the chain root signed by a FIPS-validated key and seven-year retention. The store is append-only at the database layer; even Kanonik operators cannot edit or delete an entry.

Skill library

Private, signed, versioned

Engineered prompts and instructions load into your AI and turn a generic frontier model into a defensible compliance worker. Bundles are signed, subscription-gated, and the active version is recorded in the hash chain on every change it produces. Core skills today: policy architect, control assessment, audit narrative.

MCP transport

Connect in one line

Kanonik exposes its tools over the Model Context Protocol: streamable HTTP with OIDC, dynamic client registration, and PKCE, plus a stdio proxy. Read tools return instantly; write tools always generate proposals, never direct writes.

Auditor export

Verified offline

One click produces a signed bundle: the event sequence, the rendered artifacts, the chain root, the public key, the framework package, the schemas, and an open-source verification tool. Your auditor recomputes the chain on their own laptop, with no contact with us.

Telemetry

Every step traceable

OpenTelemetry tracing spans every hop, gateway to knowledge service to record. Trace ids are cross-referenced from the audit log, so an operator can pivot from "this change landed" to the full trace behind it.

AI governance

The AI Act sits on your desk. The substrate helps you answer it.

Marketing is running one model, engineering another, sales a custom assistant. Compliance is now expected to keep a risk register line and a model card for each, curate the prompt library, and produce traceability records.

The same canonical model and the same hash chain that carry your ISO 27001:2022 work carry the AI governance work: model-card metadata, prompt-library entries, and per-model risk lines, each a structured proposal the Verifier inspects. You stop running a parallel spreadsheet to track the AI.

Captured per model

Provider, model id, version pin. Purpose, scope, data class. Owner and review cadence. The link to its risk register line.

Multi-framework by construction

Map one control statement once; the substrate proposes the mappings into the adjacent frameworks you also satisfy, as structured proposals that pass the Verifier and get signed. A queryable graph, not a spreadsheet you re-reconcile every quarter.

Write targets and your model

Your LLM. Our trust layer.

The substrate turns your own AI into a compliance worker. The canonical model is the source of truth; an external write-back is a translation layer, not the product.

Write-back, optional

Optional write-back to an external GRC tool

If you keep an external GRC tool, Kanonik can write approved changes back to it with full provenance in the hash chain. This is a supported option you connect, not the headline and not a connector roadmap. Your source systems stay yours: your AI reaches your evidence through its own connections, under your credentials. Kanonik never holds those credentials.

Bring your own model

Your AI account stays yours

Anthropic Claude, OpenAI, AWS Bedrock, Google Gemini, or Azure OpenAI. Your account, your key, your billing. Kanonik never becomes a layer between you and your model vendor; it adds itself as a sub-processor (one entry), the model vendor does not become a second. The Verifier's tier-2 cross-check runs server-side on Kanonik's own provider account, deliberately separated from whichever provider you chose for the proposer. No token meters from Kanonik.

Because the canonical model is independent of any one platform, moving between tools, or running with no external platform at all, does not break the audit trail. Your evidence is yours; your chain is portable.

One typed model behind all of it. Your GRC tool, your AI, your auditor relationship, all kept. What changes is that every AI-assisted output now arrives checked, signed, chained, and verifiable.

The proof is the product.