Frameworks
Four frameworks live today. One record underneath.
Kanonik runs ISO 27001:2022, SOC 2, GDPR, and NIST CSF 2.0 today. Each loads as a versioned package onto the same substrate: the same canonical record, the same Verifier, the same approval gate, the same sealed export. Your first framework is included in Solo; each additional one is a $499 Framework Activation.
Live today
What you get with each framework.
Every activated framework gives you the same three things: a Statement of Applicability, a control mapping onto your canonical record, and a sealed, tamper-evident trail behind every change.
ISO 27001:2022
The full requirement set and Annex A control taxonomy, end to end. Your AI drafts the Statement of Applicability and the control mapping; the Verifier checks each decision; you approve; the record seals it. The output is the artifact set an ISO auditor actually asks for, with the reasoning trail behind every applicability call.
SOC 2 (Trust Services Criteria)
The Trust Services Criteria load onto the same canonical record, so the controls and evidence you already recorded project onto SOC 2 rather than being retyped into it. You get the applicability statement, the criteria-to-control mapping, and sealed records that show who wrote, verified, and approved every entry.
GDPR
Records of Processing Activities under Article 30, DPIAs, and processing activities, recorded and verified continuously as part of Solo. When a regulator, a data protection authority, or an enterprise customer asks, a Sealed Evidence Export produces the signed bundle with a 90-day reviewer window.
NIST CSF 2.0
The CSF 2.0 functions and categories load as a package and map onto the controls you already hold in the canonical record. You get the profile-style applicability statement, the category-to-control mapping, and the same sealed chain behind every assessment your AI proposes and you approve.
Standard text licensing
Your own licensed copy, where one is required.
ISO 27001 and SOC 2 are copyrighted standards. Kanonik does not resell or redistribute their text: those frameworks run against your own licensed copy, and you attest to your licence when you activate the framework. Your licence, your relationship with the standards body, our substrate.
GDPR and NIST CSF 2.0 are public text. There is nothing to buy and nothing to attest; activate and go.
This is the same posture your auditor already expects: the organization under audit holds its own copy of the standard it certifies against.
ISO 27001:2022 and SOC 2
Bring your own licensed standard text. You attest to your licence at activation; Kanonik runs the framework package against your copy.
GDPR and NIST CSF 2.0
Public text. No licence needed, no attestation step. Included the moment the framework is active.
Author once
Author once, map across frameworks.
The canonical record is shared across every framework you activate. Your access-control policy exists once; ISO 27001:2022 sees it through Annex A, SOC 2 through the Trust Services Criteria, NIST CSF 2.0 through its categories. Evidence recorded for one framework carries to the others through the mapping, not through copy-paste.
Adding a framework is a projection onto the record you already keep, which is why Framework Activation is a one-time $499 rather than a second subscription. The activation generates the new framework's Statement of Applicability and control mapping, runs them through the Verifier, and seals them.
Four frameworks, one record, one trust layer. Your first framework is included in Solo; activating another is a sealed, one-time event, not a second subscription.
Runs ISO 27001:2022, SOC 2, GDPR, and NIST CSF 2.0 today.