Skip to content

What is available today

Frameworks

Five framework packages are live and selectable: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), GDPR, NIST CSF 2.0, and HIPAA.

The record underneath is framework-agnostic. A control is authored once, and each activated framework projects onto it, so working to a second framework is mostly recognition of work you already did.

Do not read this list as a claim about PCI DSS, HIPAA, or any framework not named above.

Certification status

Kanonik is architected to support SOC 2 and ISO/IEC 27001:2022, and to a FedRAMP-aligned baseline. It runs on a FIPS 140-3 validated cryptographic module.

Kanonik does not yet hold SOC 2, ISO 27001, or FedRAMP authorization. It is pre-certification by design, and we say so plainly rather than imply an attestation that is not in place.

If you need a specific attestation today, email hello@kanonik.ai and you will get a direct answer rather than a maybe.

What that distinction means in practice: the architectural controls an auditor would look for are built and running, and the third-party attestation that they were audited is not yet issued. See Security for the mechanisms themselves.

In development

Capabilities being added:

  • Additional framework content beyond the four live today
  • Richer batch approval and workflow features
  • Smoother onboarding
  • Advanced analytics and reporting
  • More specialised skills across additional compliance domains

These are in active development, and availability is announced as each reaches production readiness. We do not commit to dates for unreleased work.