Kanonik
Menu

What a busy month on Kanonik looks like for one company.

Harbor Ledger is a 40-person fintech. It's our sample company, and you can try it yourself in the demo.

Want the long version of the first story? Follow the Brookvale change step by step.

Harbor Ledger checks a backup vendor before anyone signs.

The team wants to move database backups from Amazon Web Services to Brookvale Backup. An engineer photographs page 4 of Brookvale's data processing addendum and sends it to @Kanonik in the team chat with the question everyone has: does this break anything we've promised?

Kanonik pulls three facts from the page, each with its clause, and Dana Reyes approves them through her signed link. Foresight then checks the move against Harbor Ledger's promises. Three conflict: backups would be kept 14 days instead of 30, stored in the United States instead of the EU, and customers would get 10 days' notice of a new sub-processor instead of 30. Page 4 says nothing about training AI models, so that promise needs more information.

Nothing on the record changed. Dana decides, before the contract is signed, whether to ask Brookvale for different terms or keep the backups where they are.

Harbor Ledger gets its first bank due-diligence questionnaire

Northshore Bank wants to use Harbor Ledger's product. Before anyone signs, the bank's third-party risk team sends a due-diligence questionnaire and asks for the SOC 2 report. The answers are spread across a few policy documents and whatever the engineer who set up the cloud account remembers.

Dana Reyes pastes the questionnaire into Claude Desktop, the assistant she already uses. It answers from the record: Ferrow Card Services processes card payments and its SOC 2 Type II report is on file. Kanonik marks every answer as backed by an approved record or as stated, so the gaps show, and where the record has nothing to say the assistant says so instead of guessing.

Dana approves the set once. Northshore gets its file in its own question numbering, and the approved answers stay saved for the next questionnaire.

Harbor Ledger prepares for SOC 2 without a compliance hire

Customers keep asking for a SOC 2 report, and the Type I audit is booked for December. Nobody at Harbor Ledger does compliance full time, so Dana asks Priya Shah of Shah Assurance for a readiness review first.

Dana turns on SOC 2 and her assistant drafts the systems, vendors, risks, policies and controls it finds, with the evidence attached. With no one else to review, she approves them herself, and the record notes that the same person drafted and approved.

Standing shows which SOC 2 criteria have a control backed by dated evidence and which are still open, so Dana knows what's left before Priya starts. For the review, Priya gets read-only access with an end date, and a Sealed Audit Package.

Carefield Health asks how Harbor Ledger handles the HIPAA Security Rule

Harbor Ledger is taking over patient billing for Carefield Health, so it will sign Carefield's BAA as a business associate. First, Carefield's security team wants to see the risk analysis, the policies and who is responsible for what.

Harbor Ledger turns on HIPAA. Its assistant drafts a risk analysis from the systems and vendors in the record, including Amazon Web Services and Google Workspace, along with the policies the Security Rule expects, each linked to the control and evidence behind it. Dana reads and approves each draft, starting with the ones the Verifier marked. Sam Okafor takes over the risks the analysis found.

Harbor Ledger then sends Carefield a Proof Snapshot, a signed, dated copy of the record that Carefield's team can check for themselves.

Three more situations Kanonik handles the same way.

  • Support wants to switch on an AI assistant

    The tool drafts replies from customer conversations, and its standard terms let the vendor train on them. Harbor Ledger told Brightwater Payments it doesn't use customer data to train AI models. Sam Okafor asks @Kanonik to check the tool before anyone signs, and Foresight comes back with a Conflict on that promise and on the notice the DPA promises before a new sub-processor.

  • Your data has to stay inside your network

    Private or self-hosted deployment is available to enterprise customers: talk to us. Kanonik is deployed as infrastructure as code, so we go through the platform with you and test it with you. Send your requirements, such as data residency, key management or single sign-on, and we'll tell you what we can support and on what terms.

  • Consultants work inside each client's own workspace

    The client owns the workspace and invites the consultant in. Every workspace is a separate record, the client approves the work, and if the engagement ends the record stays with the client.

More examples by industry are in the scenario library. The guides cover how the work gets done, and the glossary explains the terms.

Start Solo with the work in front of you.

Solo is $99 a month and starts with a 14-day trial.