Support
Help center.
Ask the assistant, browse the guides, or email a person who works on the product.
Ask the assistant
Get an answer right now.
The Kanonik assistant answers from the same material as the guides below: what Kanonik does, how approvals and frameworks work, pricing, and security. It can also take your email so a person follows up.
If the assistant does not load, the guides below cover the same ground, and support@kanonik.ai always works.
Guides
Getting started.
Getting started with Kanonik
What Kanonik is, how the core loop works (your AI drafts, the safety check runs, you approve, it is recorded), and the right first move.
Connecting your AI
How to connect Claude Code, Claude Desktop, or any MCP-capable client to your workspace, and what happens once you do.
Navigating your workspace
What each part of the dashboard is for, and the one habit that matters: you ask your AI and approve, you do not edit objects by hand.
How your next step is recommended
Where the recommended next step and suggested prompts come from: fixed rules over your own recorded data, with no model call involved.
Working with your AI.
How risk discovery works
How your AI helps you find, score, and treat your risks: assets and vendors first, then risks, then gaps, then controls.
Revising a draft before you approve
How the back-and-forth works: every revision is re-checked, and you only ever approve a version checked in the exact state it lands.
Closing the loop on a change
Why a change is not done until it is connected, and how Kanonik surfaces the missing next step in the moment.
Keeping your compliance current
How to amend risks, controls, and policies over time, how often to review, and what continuous evidence means for SOC 2 Type 2.
Approvals and the record.
Why you approve every change
The approval gate and your role: nothing lands without your click, and that recorded act is what makes the record defensible.
Approving a batch of changes in one click
What batch approval does and does not change, what can be approved together, and how to set the level of review you want.
How confidence scoring works
What the confidence score is made of, how it decides quick approval versus review versus rejected, and how to set the scrutiny.
When you and the safety check disagree
You have the final say. How a reasoned, acknowledged override becomes a permanent, defensible part of your record.
Frameworks and audits.
Proving your controls cover your requirements
Why declaring a control's requirements is not proof, why you approve each connection, and how to read the coverage states.
Working to more than one framework
How one program serves several frameworks, why one control usually satisfies many, and why nothing is credited without your approval.
Your program as it stood on any date
Every fact carries two dates, so you can prove what your program was on the audit date, and prove you did not change it afterward.
Law, standard, or guidance
How to tier the EU AI Act, ISO/IEC 42001, and the NIST and Singapore frameworks, and why the tier changes what you must do.
How Kanonik supports your AI-governance work
A precise map of what Kanonik supports and maps to across the named AI frameworks, and what it deliberately does not do.
Evidence and exports.
Exporting your evidence for an audit
What the sealed audit export contains, how to hand it to your auditor, and how they confirm independently that it is genuine.
An audit trail that survives scrutiny
The full-decision-chain standard buyers now ask for, and the four properties that make a record defensible.
From evidence to accountability
Why the bar moved from evidence collection to accountability and verification of autonomous action, and where Kanonik fits.
Account and security.
Accounts, sign-in, and security
Password reset, changing account details, inviting teammates, multi-factor authentication options, and single sign-on.
Your data and privacy
What Kanonik stores, what it never holds (your source-system credentials), and how the record is protected.
When things go wrong.
When something goes wrong
Expired links, a batch still sealing, a spinner after you approve, and how to confirm what actually landed on your record.
Quick answers
Frequently asked questions.
What is Kanonik?
Kanonik is new-gen GRC: your compliance system of record, where your own AI does the compliance work. Every change your AI proposes runs through a server-side safety check, waits for a named person's one-click approval, and is sealed into a tamper-evident audit log. Your assets, vendors, risks, controls, policies, and framework decisions live in Kanonik, with the proof behind each one.
Which AI can I use?
The one you already use. Kanonik is model-agnostic and connects over MCP (Model Context Protocol): Anthropic Claude, OpenAI, Google Gemini, AWS Bedrock, Azure OpenAI, or any MCP-capable client. You bring your own model key for your side of the work, so your AI provider stays your direct contractor.
Which frameworks run today?
ISO 27001:2022, SOC 2 (Trust Services Criteria), GDPR, and NIST CSF 2.0 are shipped and selectable. The record underneath is framework-agnostic: you author a control once and each activated framework projects onto it, so a second framework is mostly recognition of work you already did.
How do approvals work?
Nothing lands in your record until a person clicks a single-use, signed approval link created for that exact change, after the safety check has reached a verdict on it. The person who proposed a change can never be the one who approves it. Related changes can be approved as a batch in one click, with every item still sealed as its own entry.
Who runs the safety check?
The safety check (the Verifier) runs server-side on Kanonik's own model account, independent of the AI and the key you bring. The check never depends on the model it is checking, and your AI cannot skip it or talk its way past it.
What does my auditor get?
A single sealed export: the complete decision record, your Statement of Applicability and documents, a cryptographic integrity proof, and a self-contained verification tool the auditor runs on their own machine, with nothing sent to anyone. The auditor of record also gets free read-only access on every paid tier.
What data does Kanonik store?
Your compliance record and its full history, isolated per workspace. Kanonik never holds your source-system credentials (your cloud, code, and tickets stay connected to your AI, not to us) and never receives your conversation with your AI. It sees only the tool calls your AI makes against your record.
How does pricing work?
Start with Solo at $99 per month (or $990 per year), with unlimited seats and your first framework included. Framework Activation is $499 one-time per additional framework. A Sealed Evidence Export is $749 per export and a Sealed Audit Package is $1,499 per finalized audit session, billed only when you choose to seal. No token meters. Details on the Pricing page.
Do I need to install anything?
No. You connect your AI client to your workspace link once, sign in, and Kanonik's signed skills load over the connection on their own. From then on the work happens in your AI client and the results wait for your approval in the dashboard.
How do I get support?
Ask the assistant at the top of this page, or email support@kanonik.ai; a person who works on the product answers. Security questions live on the security page; the binding documents are the Terms, Privacy Policy, and DPA.