The proof is the product

New-gen agentic compliance.
Proof included.

Your AI drafts the policy, assesses the control, and fills the questionnaire in seconds. So does everyone else's. A draft is not evidence. Kanonik makes it one: the right skills going in, every result checked, a person signing off on anything that matters, and a tamper-evident seal your auditor can open and check without trusting you.

Works today with ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA and HIPAA. What your auditor accepts still depends on your program and your auditor.

your aichat connected to kanonik
kanonikrecord connected
canonical record 0 of 14 blocks
happened
2026-03-12
recorded
2026-03-14
offline verifyno login
$ ./verify bundle.tgz building

Your AI plugs into Kanonik in one step

01Skills guide the AISo it uses the right tools, schemas and evidence
02A safety check on every outputNothing touches the record until it passes
03You approve the writes that matterRight in the browser, named and revocable
04A record your auditor can openSigned, hash-chained, verifiable without a login
01The problem

AI can draft compliance work. That does not make it defensible.

Policies, control write-ups, risk assessments, mappings, evidence summaries. Most of it is obvious AI work now. But you end up with text that has no shape, no evidence behind it, and nothing your auditor can walk back through six months later.

Kanonik sits between the AI and your compliance record. Skills keep the AI inside the lines. A Verifier reads what it hands back. A person signs off before anything is written down. Then the event is sealed. A prompt and a reply are not an audit trail.

A draft is not evidenceside by side
AI alone
"The organisation maintains monitoring of systems and networks to detect anomalous behaviour."
  • No approver
  • No evidence link
  • No prior version
  • Not verifiable
text
through Kanonik
Same wording, bound to control A.8.16, effective 2026-07-01.
  • Elena Cruz, CISO
  • 2 artefacts cited
  • Version history kept
  • sha256 f21a88be
evidence
verifyoffline
$ kanonik verify bundle.tgz holds up
no login
02How it works

Work in your AI client. Govern every result in Kanonik.

Bring the model you already use. We bring the skills, the safety check, and the line between a draft and something you can stand behind.

  1. Step 0101 of 06

    Your AI drafts the work

    It assesses a control, maps a framework, writes an evidence summary, or answers a questionnaire, in the tool you already use.

  2. Step 0202 of 06

    A Kanonik skill shapes it

    The skill hands the AI the right tools, schema and evidence rules, so what comes back fits the record it is going into.

  3. Step 0303 of 06

    The Verifier reads the output

    Before anything reaches the record, a server-side check goes through it. Some rules, some LLM review, a clear verdict.

  4. Step 0404 of 06

    You approve it in the browser

    Anything that actually matters waits for a named person to sign off. The approval is scoped and can be pulled back.

  5. Step 0505 of 06

    The record is sealed

    The event joins a signed, hash-chained history with two clocks on it: when it happened, and when Kanonik wrote it down.

  6. Step 0606 of 06

    Your auditor opens it later

    You hand them a bundle. They run the offline verifier in a browser. They never need an account.

The gate

Nothing unproven gets into the record.

Drafts queue on one side. The Verifier reads each one, a named person signs off on anything material, and only then does the event get sealed into the chain. Work that fails the check goes back with a reason attached.

Nothing unproven gets inchecking
AI output
verifier + sign-off
your record
verifyoffline
$ kanonik verify --strict 0 unproven writes
no login
What it does

Four things you actually get out of it.

Get through a security questionnaire in an afternoon.

The questionnaire skill reads your live control record and drafts each answer. The Verifier checks the draft against the evidence you actually have. Every answer you send back points to a specific sealed control, so the customer can follow the thread if they want to.

Security review0 / 120 answered
00:00
elapsed
3 weeks
was the old way
Do you encrypt data at rest?
answered from control A.8.24cited
Describe your access review cadence.
answered from control A.5.18cited
Is MFA enforced for admins?
answered from control CC6.1cited
Every answer points at a control and its evidence.
verifyoffline
$ kanonik answer --pack vendor-review 120 cited
no login

Write a control once. Use it in every framework.

You record the control the way you actually do it. The mapping skill lines it up against each framework, the Verifier checks the fit, and the mapping gets sealed with the reasoning attached. Pick up a new framework next quarter and nothing you wrote already has to change.

Map once, answer everywhere0 frameworks
your real control
Centralised log collection with 400-day retention
owner: Platformevidence: 3 artefacts
verifyoffline
$ kanonik map --coverage no duplicate work
no login

See what was true on any given day.

Every sealed fact carries two dates. One is when it actually happened in your business. The other is when Kanonik wrote it down. You can pull up the record as it stood on any past day, so a March review still reads like March even after you make changes in April.

Time travelas ofbitemporal
Two dates, kept apart: when it was true, and when you wrote it down.
Effective
2026-03-30
when it happened
Recorded
2026-04-02
when you knew it
25-1126-0126-0426-07
A.8.16 Monitoring activities Implemented
asserted by Elena Cruzimmutable prior versions retained
verifyoffline
$ kanonik export --as-of 2026-04-02 reproducible
no login

Give buyers a trust page you can back up.

The trust-site skill builds a public page straight from your sealed record. It skips the marketing tone. Each claim on the page points back to the specific control and evidence behind it, with the date it was sealed.

trust.yourcompany.com live
Trust Center
Generated from the record.
ISO 27001
evidence sealed
SOC 2
in progress
GDPR
documented
Subprocessors
14 listed
Access control policy download
Pen test attestation download
verifyoffline
$ curl trust.yourcompany.com/proof signed index
public

Run every client from one place, without mixing them up.

A vCISO or consultant works across engagements from a single sign-in, but each client sits in its own tenant with its own record, its own approvals and its own chain. There is no shared pool to leak across, and each client's auditor sees only that client's evidence.

Your engagements3 tenants
Northwind Data2 need you
Acme Healthsealed
Riverbend Mutual1 gap
separate tenants
isolation
One record per clientno shared pool
One chain per clientno cross-reads
verify / offline
$ kanonik verify --tenant northwind scoped
no login

Keep the program current without chasing people.

A weekly digest reads the record and tells you what actually moved: evidence going stale, approvals still waiting on someone, and changes an auditor would want to ask about. It is generated from what is sealed, so it cannot flatter you.

Weekly digestthis week
staleEvidence past its review date4
waitingApprovals still open2
changedControls touched since the last audit7
sealedNew records this week19
Read from the sealed record, not from a task list somebody kept by hand.
verify / offline
$ kanonik digest --since 7d from the record
no login
03Why it holds up

Built for proof, not theatre.

01

Non-bypassable safety check

The Verifier runs server-side, inside the commit path, before anything lands. It is not an instruction in a prompt that a model can be talked out of, and it is not a tool your AI can choose to skip.

02

Real human approval

Agreement in a chat window is not consent. Every consequential write waits for a named person to approve it in the browser, scoped to that one change.

03

Tamper-evident record

Each approved change joins a signed, hash-chained history built for reconstruction later. The record cannot be quietly rewritten without the chain showing it.

04

Signed skill library

Kanonik skills are versioned and signed compliance workflows that load into your own AI client, and the exact version that produced a result is recorded on the chain beside it.

05

Bring your own model

Use the AI provider your team already trusts. Kanonik is model-agnostic, and your provider stays your direct contractor rather than becoming something you inherit through us.

06

No standing source-system credentials

Your AI reads the systems you granted it. Kanonik stores the compliance record and references to your evidence, not permanent production access to your stack.

07

Auditor-ready export

One bundle carries the evidence narrative, the approval record, the Verifier verdicts, the chain proof, the framework artifacts and the verification tooling itself. Your auditor checks it on their own machine, with no account and nothing uploaded anywhere.

Who it serves

One product, four ways people buy it.

Small enough to put on a founder's card. Solid enough for a regulated bank.

The same append-only record works whether it is one founder trying to get past a customer security review this week, or a financial institution that needs the control history to still make sense years from now.

1-5 people

Vibecoding startups

The founder writes the policies, drops in the evidence, and gets through the first customer questionnaire without hiring anyone for it.

6-50 people

Small teams

Shared controls, an approval step people actually use, clean exports, and a way to handle customer security reviews without a fire drill each time.

51-500 people

Growth companies

More than one framework in flight, named reviewers on the record, dated history you can pull up later, and something an auditor can replay.

500+ people

Finance and government

Retention rules, separation of duties, deployment options that fit your data-residency story, and a substrate built to comply with the FedRAMP Moderate standard from the first commit.

Compliance starts before headcount does.

Small AI-native teams do not need another GRC suite. They need the AI they already have to leave a real trail behind it, from the first customer security review onward, without waiting on procurement or a full-time security hire.

04The proof is the product

Your auditor does not have to take our word for anything.

Every export carries its own verifier. Your auditor opens it in a browser, drops the export in, and it walks through the signatures, the chain, the verdicts and where each piece of evidence came from. It runs on their machine. Nothing is uploaded anywhere.

  • Signed PDF reportverifiable
  • JSON event bundle and chain rootverifiable
  • Human-readable HTML packverifiable
  • Framework mapping and public keyverifiable
  • Offline verifier (verify.html)verifiable
Check one yourself
2 steps / no account
  1. Download the sample audit pack

    A real Auditor Export, about 110 KB, .tar.gz. Synthetic data, sealed exactly the way a live one is.

    Download sample pack
  2. Drop the pack into the verifier

    The verifier opens in its own tab. Drag the file you just downloaded onto it. It unpacks the archive and runs all eight checks on your own machine. No account, no upload, no network call.

    Open the verifier

The eight checks it runs

  • Hash chain integrity
  • Chain-root signature
  • Verifier verdict presence
  • Separation of duties
  • Skill provenance
  • Reproducibility tuples
  • Prompt integrity
  • File checksums
The same verifier that ships inside every export, byte for byte.
05Frameworks today

Multi-framework by design.

Available
ISO 27001:2022

Statement of Applicability, Annex A, evidence packs.

Available
SOC 2

Trust services criteria, control narratives, walkthroughs.

Available
GDPR

Records of processing, DPIA scaffolds, DPA replies.

Available
NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, Recover.

Available
HIPAA

45 CFR Part 164: administrative, physical and technical safeguards, plus breach notification.

Kanonik helps you create and preserve defensible compliance records. It does not guarantee certification, legal compliance, or auditor acceptance.

06Pricing

Start with Solo. Pay us when you actually seal something.

Two monthly plans, and your Proof Snapshot is free on both. The other prices below are for specific moments, and they only show up on the bill when you seal one. That is the whole price list.

Entry plan, Solo
$99 / month
or $990 a year, two months on us

Your first framework, the Verifier, the approval step, the hash-chained record. Cancel whenever. Your base price does not go up when you renew.

  • ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA and HIPAA. Your first framework is in.
  • Append-only event store, hash chain, two clocks on every record.
  • The Verifier and the signed approval step run on every write.
  • GDPR paperwork: RoPA (Art. 30), DPIAs, processing activities.
  • Bring the model you already use. No token math, no metering.
  • Your Proof Snapshot is free, as often as you want it. Free on Pro too.
  • Your first user is included; extra users are $9.99 a month each.
Pro is $399 a month, or $3,990 a year. It adds verified data flowing into your AI as it works, so answers come out already citing the record, and it includes one Sealed Audit Package a year. Both plans side by side on the pricing page.
What each sealed thing costs
Only shows up when you actually seal one
Free
Your Proof Snapshot

A sealed, point-in-time record of where you stand. Take one whenever somebody asks, as often as you like, on either plan. Whoever you hand it to checks it themselves, with no account.

$499
Turning on a new framework

One-time, for each framework past your first. You get the Statement of Applicability and the control mapping, drafted, checked and sealed.

$1,499
The full audit package

Per audit you close out. The Auditor Export bundle and the evidence narrative with each reviewer named. You only pay when you actually seal it. Inviting your auditor is free, read-only, and does not expire.

If a price changes, it changes through a sealed public event, not a quiet edit to this page. Your base price does not go up at renewal. One note on standards: ISO 27001 and SOC 2 run against your own licensed copy of the standard text; GDPR, NIST CSF 2.0 and HIPAA are public text, so there is nothing to buy. If you need something air-gapped, sovereign, or otherwise not on this page, write to us and a real person answers inside a business day. Full detail on the pricing page.
07Trust posture

Where your AI stops and the record starts.

Your AI can draft and suggest, inside the boundary of a Kanonik skill. It cannot quietly rewrite the compliance record on its own. Kanonik checks what the skill hands back, makes someone approve it in the browser, notes who did, and keeps the trail so your auditor can walk through it later.

Sealed recordverified
A.5.1 Policies for information security
approved by Elena CruzCISO2026-07-01
eventevt_9f31c0a4
prev3d4e1c07
sha256f21a88be
signerkanonik-root / ed25519
verifyoffline
$ kanonik verify evt_9f31c0a4 signature valid
no login
  • Bring the model you already use. OpenAI, Anthropic, Bedrock, Gemini, Azure. Your AI provider stays your direct contractor.
  • Your AI holds the keys to your source systems. We do not.
  • We do not sit on standing production credentials for your stack.
  • The compliance record and the pointers to your evidence live in your tenant.
  • The evidence itself stays where you keep it, unless you explicitly record it.
  • Tenants are kept apart end to end. A vCISO working with two clients cannot cross the wires.
The proof is the product

Put proof around your AI compliance work.

Kanonik gives your AI the skills to do compliance work well, checks what it hands back, waits for a person to sign off on anything real, and keeps a clean copy your auditor can open later.