Kanonik

Help center

Your data and privacy.

What Kanonik holds, what it deliberately does not, and how the record is protected.

Before a buyer connects anything to Kanonik, they usually run a security review. This page answers the questions that review asks: what Kanonik holds, what it deliberately does not hold, and how the data it does hold is protected. It is written to be read by your security team, so it is precise about what is a finished property and what is a design commitment.

What Kanonik stores

Kanonik holds your compliance record. That is your assets, vendors, risks, controls, policies, procedures, mappings, and the decisions made about them, together with the full history of how each one changed over time. This record lives in your own workspace, which is isolated from every other customer's data at the database, application, and access layers. One customer cannot read or reach another customer's record.

The record is the product. Kanonik does not copy your source systems and does not try to. It is the structured, reviewable account of your compliance posture and the decisions behind it.

What Kanonik does not hold

Kanonik does not hold the credentials to your source systems. Your cloud accounts, your code repositories, your ticketing system, and the rest of your estate stay connected to your AI, not to us. When your AI needs to read from one of those systems, it does so through its own tools, with credentials you control. Those credentials are never sent to Kanonik and are never stored by us.

This is a design choice. By never receiving your source-system credentials, Kanonik removes itself as a place where that access could be stolen or misused. There is no Kanonik-owned connector holding standing keys to your infrastructure.

Your AI provider

You bring your own AI. For example, you might connect Claude or another compatible assistant. Your conversation with that assistant is between you and your AI provider, under your agreement with them. Kanonik does not sit in the middle of that conversation and does not receive it.

What Kanonik sees is the specific tool calls your AI makes against your record: the policy it proposes, the mapping it suggests, the change it asks you to approve. It does not see your wider discussion with your AI. The boundary is deliberate and narrow: Kanonik governs the writes to your record, not your dialogue.

A record that cannot be quietly rewritten

Every change to your record is appended to a permanent, tamper-evident history. Each entry is linked to the one before it, so if any earlier entry were altered or removed, the break would be detectable. The history is append-only: entries are added, never edited in place and never silently deleted.

This protection applies to everyone, including Kanonik. We cannot reach into your record and rewrite past decisions without that change being visible. The point is that anyone reviewing the record, including an outside auditor, can confirm that the history they are reading is the history that actually happened. Records are retained so they are available when a review or an audit needs them.

A person approves every change

No change lands in your record on the strength of an AI suggestion alone. Each proposed change runs through a server-side safety check and then waits for a named person to approve it. That approval is recorded as part of the entry, so the record always shows not only what changed and why, but who authorized it and when. An AI can propose, but only a human commits.

You can export the full history

You can produce an auditor-ready export of your complete decision history on request. The export includes the proposals, the safety-check verdicts, the reasoning, the approvals, and the integrity proof for the tamper-evident history, so a reviewer can verify that the record has not been altered. This is built so that the account you give an auditor is the same account the system can prove.

On certifications

Kanonik is engineered to the standards expected of systems that hold compliance data, including the controls associated with frameworks such as SOC 2 (Trust Services Criteria) and FedRAMP Moderate. These describe the standard the design targets. They are not a claim that any specific certification or authorization has been achieved today. Where a formal certification matters to your review, ask us directly and we will tell you its current status plainly.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.