Kanonik

Help center

How risk discovery works.

Your AI does the analysis. Kanonik makes every risk it finds typed, checked, approved, and provable.

With Kanonik, your own AI does the risk analysis, and Kanonik makes every risk it finds typed, checked, approved, and provable. You get reasoning grounded in your actual environment rather than a generic scanner's list. This article explains that flow and why it is built this way.

The short version

You talk to your AI assistant the way you already do. With Kanonik connected, your assistant becomes a disciplined compliance analyst: it learns your environment, reasons about what could go wrong, and proposes risks in plain, audit-ready language. Kanonik checks each one with an independent safety check on its servers and puts it in front of you for a single click. Nothing becomes official until you approve it, and every decision is written to a permanent, tamper-evident record.

The order of the work is risk-first:

Context, then assets and vendors, then risks, then gaps, then controls.

Step by step

1. You describe your environment

You tell your assistant about your business in normal conversation: the systems you run, the data you hold, the vendors you depend on. For example: "We run on AWS. Our customer database holds personal data. We use Stripe for payments and a managed email provider."

From this, your assistant proposes your assets (the systems and data that matter) and your vendors (the third parties you rely on), tagging each with the details that drive risk: how critical it is, what kind of data it holds, what level of access a vendor has.

2. Your AI identifies the risks

This is the heart of it. Your assistant reasons over your environment against the security framework you are working toward, and asks, for each asset and vendor: what could realistically go wrong here, and how bad would it be?

Each risk comes out as a clear statement an auditor can read, naming the threat, the weakness it exploits, the asset it affects, and the impact, together with a clear-eyed rating of how likely it is and how severe the impact would be, and how you intend to handle it (reduce it, accept it, transfer it, or avoid it). Every risk is tied to the specific asset or vendor it threatens, so the picture stays connected rather than becoming a flat list.

Because the analysis is done by a capable AI that understands your specific context rather than a fixed checklist, the risks are relevant to your business, not boilerplate.

3. Kanonik checks every proposed risk

Before any risk reaches you, Kanonik runs an independent safety check on its own servers. Your assistant cannot skip it or talk its way past it. It runs inside Kanonik, every time. If a proposed risk is vague, unsupported, or low-confidence, it is held back for review rather than waved through.

4. You approve with one click

Risks that pass the safety check land in your "Needs you" queue. You review the risk, and a single click makes it official. Nothing is ever applied automatically. The decision is always yours, and the click is recorded as evidence.

5. Gaps tell you what to build next

A risk that has no adequate control protecting against it becomes a gap. Gaps are the engine of the program: they turn "here are your risks" into "here is what to do about them." Each gap points your assistant toward the control it should help you create. Once that control is in place, you link it to the risk it treats, and the gap closes.

6. The whole chain is one connected picture

In Kanonik you can see the full derivation, from asset to risk to gap to control to treatment, and pivot it by asset, by risk, or by control. When an auditor asks for proof, you export the complete, signed record in one action.

Why it is built this way

The division of labor is deliberate:

  • Your AI is the analyst. It does the thinking, understanding your context and reasoning about risk, because a capable, current model is far better at that than any fixed rule set.
  • Kanonik is the substrate that makes that work trustworthy. It supplies the structured model your risks live in, the independent safety check, the human approval gate, and the permanent record: the things that turn an AI's analysis into something you can stand behind in front of an auditor.

That is the whole idea: you get the speed and relevance of having a smart analyst on tap, with the discipline and defensibility of a system that checks the work and remembers every decision.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.