Capabilities
The substrate behind audit-defensible AI.
Your own AI does the compliance reasoning. Kanonik is the substrate underneath: a typed data graph, a non-bypassable Verifier, a real human-approval gate, a tamper-evident record, and a private signed skill library, all reached through MCP. Below is what each primitive does, and what it removes from your week.
The substrate primitives
Eight things the substrate gives your AI.
Each one is built for the full long-term product and framework-agnostic by construction. ISO 27001:2022 is the framework content that ships first; the architecture reads framework specifics from a loadable package, never hardcoded.
One typed system of record
A typed, bitemporal, event-sourced graph is the entire system of record. Every entity carries both when it happened and when it was recorded, so "what did our Statement of Applicability say on any past date" is one query. It is framework-agnostic; framework specifics load as a package.
Non-bypassable, server-side
A two-tier check, deterministic rules plus an independent LLM cross-check, runs inside every commit before any write can land. It is not exposed as a tool your AI can call or skip. Low-confidence work routes to a review queue, never to auto-approve.
A real human click
Every external write requires a single-use, signed, payload-bound approval token with a 15-minute window, approved out of band of the AI conversation. In-conversation approval is never sufficient.
Append-only, FIPS-signed
Every change is an event chained to the hash of the one before it, with the chain root signed by a FIPS-validated key and seven-year retention. The store is append-only at the database layer; even Kanonik operators cannot edit or delete an entry.
Private, signed, versioned
Engineered prompts and instructions load into your AI and turn a generic frontier model into a defensible compliance worker. Bundles are signed, subscription-gated, and the active version is recorded in the hash chain on every change it produces. Core skills today: policy architect, control assessment, audit narrative.
Connect in one line
Kanonik exposes its tools over the Model Context Protocol: streamable HTTP with OIDC, dynamic client registration, and PKCE, plus a stdio proxy. Read tools return instantly; write tools always generate proposals, never direct writes.
Verified offline
One click produces a signed bundle: the event sequence, the rendered artifacts, the chain root, the public key, the framework package, the schemas, and an open-source verification tool. Your auditor recomputes the chain on their own laptop, with no contact with us.
Every step traceable
OpenTelemetry tracing spans every hop, gateway to knowledge service to record. Trace ids are cross-referenced from the audit log, so an operator can pivot from "this change landed" to the full trace behind it.
AI governance
The AI Act sits on your desk. The substrate helps you answer it.
Marketing is running one model, engineering another, sales a custom assistant. Compliance is now expected to keep a risk register line and a model card for each, curate the prompt library, and produce traceability records.
The same canonical model and the same hash chain that carry your ISO 27001:2022 work carry the AI governance work: model-card metadata, prompt-library entries, and per-model risk lines, each a structured proposal the Verifier inspects. You stop running a parallel spreadsheet to track the AI.
Captured per model
Provider, model id, version pin. Purpose, scope, data class. Owner and review cadence. The link to its risk register line.
Multi-framework by construction
Map one control statement once; the substrate proposes the mappings into the adjacent frameworks you also satisfy, as structured proposals that pass the Verifier and get signed. A queryable graph, not a spreadsheet you re-reconcile every quarter.
Write targets and your model
Your LLM. Our trust layer.
The substrate turns your own AI into a compliance worker. The canonical model is the source of truth; an external write-back is a translation layer, not the product.
Optional write-back to an external GRC tool
If you keep an external GRC tool, Kanonik can write approved changes back to it with full provenance in the hash chain. This is a supported option you connect, not the headline and not a connector roadmap. Your source systems stay yours: your AI reaches your evidence through its own connections, under your credentials. Kanonik never holds those credentials.
Your AI account stays yours
Anthropic Claude, OpenAI, AWS Bedrock, Google Gemini, or Azure OpenAI. Your account, your key, your billing. Kanonik never becomes a layer between you and your model vendor; it adds itself as a sub-processor (one entry), the model vendor does not become a second. The Verifier's tier-2 cross-check runs server-side on Kanonik's own provider account, deliberately separated from whichever provider you chose for the proposer. No token meters from Kanonik.
Because the canonical model is independent of any one platform, moving between tools, or running with no external platform at all, does not break the audit trail. Your evidence is yours; your chain is portable.
One typed model behind all of it. Your GRC tool, your AI, your auditor relationship, all kept. What changes is that every AI-assisted output now arrives checked, signed, chained, and verifiable.
The proof is the product.