What is available today¶
Frameworks¶
Five framework packages are live and selectable: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), GDPR, NIST CSF 2.0, and HIPAA.
The record underneath is framework-agnostic. A control is authored once, and each activated framework projects onto it, so working to a second framework is mostly recognition of work you already did.
A framework is a versioned package that loads onto the controls and evidence you already have, not a rebuild, so the catalog grows quickly and on demand. The five named above are what ships today. If you need one that is not yet live, ask for the one you need at [email protected].
Certification status¶
Kanonik is architected to support SOC 2 and ISO/IEC 27001:2022, and to a FedRAMP-aligned baseline. It runs on a FIPS 140-3 validated cryptographic module.
Kanonik does not yet hold SOC 2, ISO 27001, or FedRAMP authorization. It is pre-certification by design, and we say so plainly rather than imply an attestation that is not in place.
If you need a specific attestation today, email [email protected] and you will get a direct answer rather than a maybe.
What that distinction means in practice: the architectural controls an auditor would look for are built and running, and the third-party attestation that they were audited is not yet issued. See Security for the mechanisms themselves.
In development¶
Capabilities being added:
- Additional framework content beyond the five live today
- Richer batch approval and workflow features
- Smoother onboarding
- Advanced analytics and reporting
- More specialised skills across additional compliance domains
These are in active development, and availability is announced as each reaches production readiness. We do not commit to dates for unreleased work.