Kanonik

The proof is the product

New-gen agentic compliance.
Proof included.

Your AI runs your compliance program; we make every change verifiable and auditor-ready.

Runs ISO 27001:2022, SOC 2, GDPR, and NIST CSF 2.0 today.

Self-serve. No sales call. Solo is $99 a month, unlimited seats, cancel anytime.

The inversion

Your AI can already do the work.
What it lacked was a way to prove it.

Legacy GRC made the human the worker and the tool the filing cabinet. Kanonik inverts it. The canonical model is the system of record, your own language model is the worker, and the Verifier, the approval gate, and the tamper-resistant log sit underneath where the model cannot route around them.

The reasoning belongs to the model. Kanonik is the trust layer that makes that reasoning defensible.

Examples

From founder mode to enterprise audit.
The same record scales.

Three real buying moments: a two-founder startup passing its first customer review, a growing company in audit week, and a regulated enterprise review that sets its own deadline. Every image is the actual product.

01 / 1-5 people

The founder ships evidence before hiring compliance.

A vibecoding startup: two founders, an AI product, a serious enterprise prospect, and no procurement process to fight.

  • draftYour AI drafts the access control policy from how you actually gate production, and proposes it.
  • verifyThe Verifier checks it server-side and records its verdict.
  • sealYou approve from your phone. Sealed by 14:19, customer-ready.

17 minutes and one approval. A founder can buy it on a card and show credible evidence at tomorrow's procurement call.

included in Solo / $99 a month
A real pending approval on a phone: Verifier verdict shown, approve and seal

the approval, on your phone

02 / 50-500 people

The auditor asks how a control changed. You replay it.

Month nine, audit week. A growing fintech with real teams, real approvals, and an auditor who trusts no AI-written paperwork.

The real audit log: policy approved, drafted by your AI, approved by a person, sealed in order

the record, one second after the click

  • askWho wrote this policy, and who signed it off.
  • replayThe record answers: skill version, verdict, named approver.
  • checkThey verify the chain offline on their own laptop. No account, no taking our word.
Sealed Audit Package / $1,499 when you seal
03 / Regulated enterprise

The review package that scales beyond startup chaos.

Friday afternoon. A financial-services or public-sector review team wants evidence before they sign, and they set the deadline.

  • askTwelve months of access-control evidence, with sign-off history and export verification.
  • scopeYou scope the export; your approval gates what leaves.
  • sendA sealed, signed bundle their team verifies independently, with a 90-day window.

Thirty-five minutes, because the record already existed. The same chain a two-person startup starts with.

Sealed Evidence Export / $749 per export
The real approvals page: one thing waits on your click

what waits on your click

Use cases

One record. Seven jobs it does for you.

The core program

Run your whole compliance program

Assets, risks, policies, controls, the Statement of Applicability, evidence, and the gaps you have not closed yet, in one typed, bitemporal record. Your AI proposes; the Verifier checks; you approve; the chain seals. The program is the record, not a folder of documents that drifted apart.

Policies

Draft and maintain policies

Your AI drafts against the loaded framework and your real environment. Every version is pinned to the skill that produced it and the human who approved it.

Controls

Assess controls each quarter

A defensible verdict on whether each control operated as designed, with the reasoning recorded so an auditor can replay it instead of taking your word.

Audit

Walk into the audit with receipts

Seal a finalized audit session into an Auditor Export bundle: narratives, linked evidence, reviewer attribution, and a chain your auditor verifies offline.

Customers

Answer the security review

When a prospect, regulator, or DPA asks for evidence, export a sealed, signed bundle with a 90-day reviewer window instead of a screenshot folder.

GDPR

Keep GDPR records current

RoPA under Article 30, DPIAs, and processing activities, recorded and verified continuously as a Solo feature, not a separate product.

Multi-framework

Author once, map across frameworks

Controls and evidence live once in the canonical record; each framework you activate projects onto them. Adding a framework is a mapping, not a rewrite.

Every one of these ends the same way: verified, human-approved, sealed into the same tamper-evident chain.

Who this is for

Built for two buyers who could not be more different.

Fit 01 / The lean team

Nobody hired for compliance

A 25 to 200 person fintech, healthtech, or AI-native SaaS where compliance landed on a founder or an engineer. You already pay for a frontier AI; Kanonik turns it into the compliance worker and keeps you as the one-click approver.

Solo is $99 a month with unlimited seats. The consultant day rate stays in your pocket.

start today / one plan / your own model key
Fit 02 / The regulated buyer

Your security team reviews first

You buy nothing before the security review, so the review comes first: posture, data handling, sub-processors, and the published DPA, ready to review before you connect anything. FIPS 140-3 validated cryptographic primitives; the substrate is engineered to FedRAMP Moderate design standards from the first commit.

Designed-for is the claim, and the only claim: Kanonik holds no FedRAMP authorization and does not imply one.

security review first / published DPA / seven-year retention

Over MCP

Your AI on the left. The record on the right.

A real session: the AI proposes a seven-part slice, runs a dry-run preview, commits it as one batch, and hands the human a single approval link. The workspace fills in as it works. One click seals all seven.

Your AI, in the editor you already use Kanonik, keeping the record
Split screen: an AI session in an MCP-connected editor proposing a compliance slice on the left; the Kanonik workspace with the proposed vendor, risk, and controls on the right
Actual session, 16 Jul 2026: an MCP-connected editor working against Kanonik, integration environment, synthetic client. Any MCP client works the same way.

How it works

Three things on your side.
Nothing else to install.

Sign up at kanonik.ai, connect the AI you already have in one line, pull our compliance skills on first sign-in. Your first audit-ready output lands the same afternoon.

01

Bring your AI

Claude, ChatGPT, Gemini, Bedrock, or Azure OpenAI. You keep the contract with the AI vendor. Kanonik never sees your conversations.

02

Load our skills

Compliance skills your AI pulls on first sign-in. They turn a generic frontier model into a defensible worker that knows the framework you are working against and what an auditor expects.

03

Keep the receipts

Every change is independently checked, gated by a signed human approval, and sealed into a tamper-evident record with seven-year retention.

connect any MCP client
claude mcp add --transport http --scope user kanonik https://stage-app.kanonik.ai/mcp

The skill library

The skills the consultants used to charge you for.

A generic AI knows a lot. It does not know how an ISO 27001 auditor reads a policy, or what to do when a control evidence chain has a gap. Our skills are the expertise that turns a generic frontier model into a defensible compliance worker. Signed, versioned, and pinned to the output they produced.

Core skill

Policy architectkanonik-policy-architect

Drafts information-security policies against ISO 27001:2022. Loads requirements, drafts, runs the independent check, fires the approval, locks the document to the skill version that produced it.

Replaces: the consultant who charges $5K to write your access control policy.
Core skill

Control assessmentkanonik-control-assessment

Given a control and the evidence your AI can reach, produces a defensible verdict on whether the control operated as designed, with the reasoning an auditor can replay.

Replaces: the consultant who sits with your team for a week each quarter.
Core skill

Audit narrativekanonik-narrative-synthesis

Assembles the auditor-ready account of how a control operated over a period. Linked evidence, reviewer attribution, signed reasoning. The deliverable your auditor reads instead of reconstructing it.

Replaces: the two weeks of audit prep your team currently dreads.

Every skill is signed and versioned, and every sealed output names the exact skill version that produced it. New skills land in your library as they ship; you never install anything.

The trust layer

An audit log outside the system being audited.

Five layers. Your language model sits at the top; the tamper-evident record at the bottom. Between them, three layers it cannot bypass: the Verifier, the approval gate, and the canonical model.

FIPS-signed chain. Single-use, time-boxed, payload-bound approval tokens. Seven-year retention. Your auditor verifies the chain offline with an open-source tool. The full mechanism lives on the security posture page.

Outside boundaryYour language model
Layer 4 / TransportMCP gateway
Layer 3 / Non-bypassableVerifier (rule + LLM cross-check)
Layer 2 / Non-bypassableApproval gate (signed, time-boxed)
Layer 1 / System of recordCanonical model (bitemporal)
Layer 0 / Tamper-evidentHash-chained audit log

Verify it yourself

This page verifies a sample record, live, in your browser.

Below is a signed sample bundle of eight chained events. Press the button and your own browser recomputes every SHA-256 link with WebCrypto. No account, no server call. The same check an auditor runs offline with the open-source CLI.

kanonik / offline-verifier / sample-bundle-2026
  • Load signed bundlesample-evidence-export.json, 8 events
  • Verify hash chainrecompute every prev-hash link with WebCrypto SHA-256
  • Compare root hashexpected root #686c71b7
  • Check FIPS root signatureruns in the shipped CLI; this in-page demo verifies the chain

The partnership

Your AI does the work. Kanonik makes it stand.

What your AI brings
  • Speed. Drafts in minutes what used to take a consultant weeks.
  • Reach. Its own connections into your systems, so evidence comes from where you actually work.
  • Reasoning. Reads a framework, your environment, and your history together.
  • Skills. Kanonik's signed skill library teaches it what an auditor expects.
What Kanonik brings
  • Order. A typed, bitemporal record instead of a folder of documents.
  • Control. A server-side Verifier and a human approval gate the model cannot route around.
  • Proof. A FIPS-signed hash chain your auditor verifies offline.
  • Discipline. Enterprise-grade controls, from a solo plan to an air-gapped deployment.

The model brings power. The substrate brings order and proof. Neither is credible alone. Together they are a compliance program.

Pricing

Start with Solo. Pay when you seal.

One plan runs everything. The other prices are the three moments from the stories above, and you only pay them when you seal.

Solo
$99 / month
or $990 a year, two months free
  • ISO 27001:2022, SOC 2, GDPR, and NIST CSF 2.0 today; first framework included
  • Append-only event store, hash chain, bitemporal timestamps
  • Verifier and signed approval gate on every write
  • GDPR records included: RoPA (Article 30), DPIAs, processing activities
  • Unlimited seats, on your own model key
Start with Solo

Sealed moments, priced per artifact

$499 Framework ActivationOne-time, per additional framework. SoA and control mapping generated, verified, sealed.
$749 Sealed Evidence ExportWhen a regulator, DPA, or enterprise customer asks. 90-day reviewer window. story 03
$1,499 Sealed Audit PackagePer finalized audit session. Auditor Export bundle, evidence narrative, reviewer attribution. story 02
Enterprise / air-gapped. Dedicated or sovereign deployment, custom data retention, and procurement and security-review support. Contact us. Contact us

Price policy: prices change only by a sealed public event, never a quiet edit. The base price never rises at renewal. We never charge for evidence you already recorded, and we never sell defensibility for periods you did not record. One note on standards: ISO 27001 and SOC 2 run against your own licensed copy of the standard text; GDPR and NIST CSF 2.0 are public text, so there is nothing to buy. Full details on the pricing page.

Start in your browser

Your security review first. Then connect.

Built for the way a 45 to 60 person fintech or healthtech actually buys: read the security posture, then connect the AI you already run. No sales gate, no demo to schedule.

01

Start with Solo

Email, a workspace name, and the $99 plan. Unlimited seats from day one, cancel anytime.

stage-dash.kanonik.ai/signup
02

Run your security review

Posture, data handling, sub-processors, and the published DPA, before you connect anything.

stage-dash.kanonik.ai/trust
03

Connect your AI

One line adds Kanonik to any MCP client. OIDC sign-in, PKCE. Skills fetch on first call.

stage-dash.kanonik.ai/setup/connect-ai
04

Land your first record

Ask your AI to draft a policy or assess a control. Approve once. The chain records the rest.

stage-dash.kanonik.ai/setup/first-artifact

The work is no longer asserting that AI can do compliance. The work is showing the chain that proves what the AI did, when, with which version of which skill, against which evidence, and which human approved it. That trust layer is shippable today.

The proof is the product.