Kanonik

Help center

Exporting your evidence for an audit.

One export, one sealed package, and a proof your auditor can check without trusting you.

When an audit comes around, you do not assemble a folder of screenshots and documents the night before. You produce one export. It gathers the complete record of your compliance work into a single, sealed package that you can hand to your auditor, and that they can check for themselves.

This article explains what that export contains, how to give it to your auditor, and how they confirm it is genuine.

What the export is

From your workspace you produce the export in one action. It covers the whole record for your workspace, or a single audit engagement if you scope it that way. What you get back is one download: a sealed package that holds everything an auditor needs to follow your decisions and trust that the record has not been changed.

You do not prepare anything by hand. The export is built from the record Kanonik already keeps as you work, so it reflects exactly what happened, in the order it happened.

What is inside

The package holds four things, in plain terms:

  • The complete record of decisions. Every change your AI proposed, what it considered, the safety check that ran, the verdict, and the named person who approved it. The full chain, not just the final answer.
  • Your compliance documents. Your Statement of Applicability, and the policies, procedures, and controls produced during the period, each as a readable file.
  • A sealed integrity proof. A cryptographic seal over the whole record, so that if a single entry were added, removed, or altered after the fact, it would be detectable.
  • A verification tool. A small, self-contained program included in the download that an auditor can run on their own computer to confirm the seal, with nothing sent to anyone.

How to hand it to your auditor

Give your auditor the download. That is the whole handover. Because the package is self-contained, they do not need access to your workspace, your systems, or your AI to read it or to check it. The record travels with its own proof.

How your auditor confirms it is genuine

The point of the seal is that your auditor does not have to take your word for it. Their technical reviewer runs the included verification tool, which confirms, without contacting Kanonik:

  • that the record is intact and nothing was changed after it was sealed,
  • that every recorded change was checked before it took effect,
  • that the person who proposed a change was not the person who approved it, and
  • that each AI decision carries the detail needed to reproduce and re-check it.

If any of these did not hold, the tool reports it. A clean result tells your auditor the record in front of them is the record as it was sealed.

What it proves, and what it does not

The seal proves that the record is the complete set captured by Kanonik during the period, and that none of it was changed since it was captured. That is a strong claim, and it is the one auditors most often cannot get from other tools.

It does not, on its own, prove that every event in the real world reached Kanonik in the first place. That is why each population in the export names the source it was drawn from, so your auditor can reconcile the captured record against an independent system and satisfy themselves it is complete. The export is built to make that reconciliation straightforward rather than to claim it away.

For the standard your auditor is measuring this against, see An audit trail that survives scrutiny.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.