Kanonik
Menu

Kanonik checks what your AI writes before anyone on your team approves it.

Drafts come from the AI assistant your team already uses, or from @Kanonik in Slack, Microsoft Teams and Claude. Kanonik's Verifier checks every one, a named person approves it, and the record keeps it in a form your auditor can check on their own computer.

Five steps from a draft to a line on the record.

  1. Your AI drafts the work

    Your assistant connects to Kanonik over MCP, a standard way for AI assistants to work with other software. It reads your record and the systems it can already reach, then drafts a control, a piece of evidence, a questionnaire answer or a vendor entry. It can't write to the record, so a draft changes nothing on its own.

  2. Kanonik checks every draft

    The Verifier runs on Kanonik's servers, as part of saving to the record, so no AI can skip it. Fixed rules run first, then Kanonik's own model compares the draft with your record. A draft that falls short goes back with the reasons, and your AI fixes it before a person sees it.

  3. A person approves it

    Drafts that pass go to a named approver, with anything the Verifier wasn't sure about marked to open first. The approver opens a signed link and approves in the Kanonik web app.

  4. The record keeps it

    Kanonik only adds entries; it never edits or deletes one. Each entry is linked to the one before it and the chain is signed, so a later change would show. Every entry carries two dates: when it took effect and when it was recorded.

  5. Anyone you share it with can check it

    Send a customer or auditor a Proof Snapshot or a Sealed Audit Package. They can check on their own computer, without a Kanonik account, that nothing changed after it was signed.

If you're the security architect who has to sign off on Kanonik, the technical walkthrough shows how each step is built.

Approval happens in the app, through a signed link, never in a chat message.

The approval request can arrive in the chat, from @Kanonik or from your own assistant. The link works once, for the person signed in, and expires within an hour. Your AI never gets the signed approval, and typing yes in a chat doesn't count. The record names who approved each item.

We recommend separation of duties, so someone other than the person who proposed the change approves it. If you're the only user, you can approve your own AI's work, and Kanonik records a sealed exception showing there was no second reviewer.

Harbor Ledger, a sample company

  1. Your AI sent three drafts, and one link opens them all. Nothing counts until a person approves them.

    Access control policy v2 and two applicability decisions

    3 items. You accept 3.expires in 45 min

  2. Each draft shows what changed and what the check found.

    Access control policy: passed

    The review frequency now matches the access review control.

  3. You tick that you've read each one, then accept it. You do that for all three.

    I have read this item.

    Accept
  4. Done. Sam confirms next.

    Access control policy v2 and two applicability decisions

    3 items. Done at 14:20.Waiting on Sam

Foresight checks a change against your promises before you make it.

Tell your AI or @Kanonik about a vendor you plan to add or replace, or send a photo of the contract page. Kanonik pulls out the facts that matter, a named person approves them, and Foresight checks the change against every promise you've approved: where customer data is stored, how long backups are kept, a signed DPA with every sub-processor, notice before a new sub-processor, and no training of AI models on customer data.

No conflict
The change doesn't affect the promise.
Needs information
Kanonik is missing a fact it needs, or the fact is out of date. It tells you which one.
Conflict
The change would break the promise. Kanonik shows the fact behind it, the clause it came from and the answer sets that contain the promise.

A promise the change doesn't touch comes back Not applicable. Foresight writes nothing to your record; what to do about a Conflict is your team's call.

See one change from a phone photo to a sign-off: moving backups to Brookvale Backup.

Put your next questionnaire through that check.

Solo is $99 a month and starts with a 14-day trial.