For consultants
Run more client programs, without thinning the record.
You are the fractional CISO or the GRC consultant who carries several clients at once. The constraint is not your judgement, it is the hours spent drafting policies, assessing controls, and assembling evidence by hand. Kanonik does that drafting, keeps a defensible record per client, and leaves you as the reviewer who approves every change.
How it changes the work
Your judgement scales; the typing does not have to.
The skill library turns your client's own model into a compliance worker. You stop being the person who fills in forms and stay the person who decides what is right.
A workspace for each engagement
Each client is an isolated workspace with its own data, its own record, and its own framework state. Nothing crosses between them. You switch context without mixing one client's controls into another's audit trail.
The skill library does the heavy first pass
Policies, control assessments, and audit narratives are drafted by the signed skill library running in the client's model. The first draft arrives in minutes, grounded in that client's real environment rather than a generic template.
You stay the reviewer and approver
Nothing lands until you approve it through a single-use, time-boxed, signed token. The Verifier runs server-side first; you make the final call. Your name is on the approval, which is exactly where your value sits.
A record per client that holds up
Every change is hash-chained and append-only, naming who proposed it and who approved it. When a client asks how a control was assessed eight months ago, the answer is in the record, attributed and unedited.
A signed export for the client's auditor
At audit time you hand the client a signed bundle: the events, the rendered artifacts, the chain root, and an open-source tool to verify it offline. The auditor confirms the chain without trusting Kanonik's servers or yours.
Bring the model key you already use
The client's AI provider stays their direct contractor, never one more sub-processor on their DPA. Supported providers are Anthropic Claude, OpenAI, AWS Bedrock, Google Gemini, and Azure OpenAI.
What you are not getting
Not another GRC platform to administer.
Kanonik is new-gen GRC. It replaces the category for the client rather than adding one more tool you have to populate and maintain. There is no controls-and-policies data entry to keep current by hand, because the client's model manages those through skills and you approve the result.
The product surfaces two things: what the AI did, and what is waiting for a human click. That is the part you own.
Can I keep my clients separated?
Yes. Each client is a separate workspace with database-level isolation. One client's data, controls, and audit trail never touch another's. You move between them; the records do not.
Whose AI key is used?
The client's. They bring their own model key under their own provider contract, so the provider is their direct processor and never lands on Kanonik's sub-processor list because of us. The server-side Verifier is the deliberate exception: it runs on Kanonik's own provider account, independent of the client's key, so the cross-check never depends on the model it is checking. Kanonik itself is a sub-processor.
Do you run a partner or reseller program?
Not as a committed program yet. If you run several client programs and want to talk about how that could work, write to us at [email protected].
Kanonik runs ISO 27001:2022, SOC 2, GDPR, and NIST CSF 2.0 today. The substrate is framework-agnostic by construction, so a new framework is loaded as a package rather than rebuilt.
More clients. Same standard of proof.