Kanonik

How it works

You ask your AI. We make the work hold up.

You ask your AI to do compliance work in plain language. The Verifier checks every proposal server-side. You approve with one click, outside the conversation. The change lands in your canonical record and the chain captures the full reasoning. No opt-out, no bypass. The trust layer enforces the workflow, and the workflow is what makes the work defensible.

How it works

Three things on your side.
Nothing else to install.

Sign up at kanonik.ai, connect the AI you already have in one line, pull our compliance skills on first sign-in. Your first audit-ready output lands the same afternoon. No infrastructure to deploy, no models to host.

01

Bring your AI

Anthropic Claude, OpenAI, Google Gemini, AWS Bedrock, or Azure OpenAI. You keep the contract with the AI vendor. Kanonik never sees your conversations.

02

Load our skills

Compliance skills your AI pulls on first sign-in. They turn a generic frontier model into a defensible worker that knows ISO 27001:2022 and what an auditor expects.

03

Keep the receipts

Every change is independently checked, gated by a signed human approval, and sealed into a tamper-evident record with seven-year retention.

connect any MCP client
claude mcp add --transport http --scope user kanonik https://stage-app.kanonik.ai/mcp

What happens when you ask

From "draft this policy" to a defensible trail.

Every operation that changes state walks through the same path. None of it is skippable. The trust layer enforces the workflow by architecture; nothing inside the AI session can route around it.

You
01

You ask

In the AI tool you already use, in plain language.

Your AI
02

It does the work

Using Kanonik's skills and the data you point it at.

Kanonik
03

We check it

The Verifier runs server-side before anything is real.

You
04

You approve

One click, out of band. Nothing lands without it.

Kanonik
05

We seal it

Into a record that cannot be quietly changed.

One request, start to finish

YouDraft an access-control policy for ISO 27001:2022 and show me the evidence behind it.
Your AI, with Kanonik skillsDrafts the policy from the access-control requirement and your own environment, and returns it with the evidence it used.
checkedThe independent Verifier confirms the draft covers the requirement and is well formed. Weak or low-confidence work is held back for review.
your turnOne approval link. You read it and click. Until you do, nothing is committed.
sealedLogged with who proposed it, who approved it, and the reasoning. Your auditor sees the same trail you do, and no one can rewrite it.

The flow, step by step

Six steps. None of them skippable.

The same six steps run on every state-changing operation, enforced server-side. Nothing inside the AI session can route around them.

Step 01

You ask your AI

Inside your AI client you describe the work: draft a policy for ISO 27001:2022 A.5.1, assess a change-management control for Q1. Anything you would ask a senior compliance analyst.

Step 02

Your AI calls Kanonik

Loaded with the matching Kanonik skill, your AI uses a curated set of MCP tools. Read tools return instantly. Write tools always generate proposals, never direct writes.

Step 03

The Verifier checks

Server-side, inside every commit tool, before any write can land: a rule layer (schema, scope, framework reference) plus an LLM cross-check that catches hallucination and out-of-policy reasoning. Not bypassable, by your AI or by you.

Step 04

You approve, out of band

Verified proposals generate a signed approval token delivered to your tenant URL or Slack. The approver sees the proposal, the reasoning, the Verifier verdict, and the exact diff. One click. In-conversation approval is never sufficient.

Step 05

The change lands

Once approved, the write commits to your canonical record. Versioned, bitemporal, reversible. The skill version that produced it is pinned to the event.

Step 06

Chained to the audit log

Proposal, verification, approval, commit: each captured as a signed event chained to the one before. The full chain exports on demand as a signed bundle your auditor verifies offline.

Getting started

From signup to your first output, the same afternoon.

Setup is about five minutes. Bring the AI you already have, load the skills, ask for the work. Solo is $99 a month, unlimited seats, cancel anytime.

01

Sign up and connect your AI

Sign up at kanonik.ai. Paste a single setup command into your AI client. OIDC sign-in with PKCE handles the rest. About two minutes.

02

Pull the skill library

Your tenant fetches the signed skill bundles on first sign-in. Core skills today: policy architect, control assessment, audit narrative. More ship continuously.

03

Configure approvals

Pick who approves: an email, a Slack channel, or both. The approval gate routes there automatically.

No new tool to learn and no console to fill in. You ask in plain language; Kanonik is the part that checks the answer, holds it for your approval, and seals it into a record an auditor can trust.

The proof is the product.