Pricing
Two plans. Pay when you seal.
Solo at $99 a month checks every change, seals it, and gives you a Proof Snapshot whenever you need one, free. Pro at $399 puts that proof in your AI's hands as it works, so answers come out already citing the record instead of you assembling it afterwards. Extra users are $9.99 each, and the other prices are sealed moments you pay only when you seal.
The price list
Two plans. Proof is free on both.
+ $9.99 a month per extra user
- Your first framework included, whichever one you choose
- Append-only event store, hash chain, bitemporal timestamps
- Verifier and signed approval gate on every write
- GDPR records included: RoPA (Article 30), DPIAs, processing activities
- Your AI reads your program through Kanonik, on your own model key
+ $9.99 a month per extra user
- Everything in Solo
- Your AI gets the proof inline as it works: what checked each record, when, who approved it, and the log entry to look up
- Answer a security questionnaire with answers a prospect can verify
- One Sealed Audit Package a year included
Your first user is included on either plan. You are billed for the people who actually have access, so removing someone stops the charge, and auditors you invite are read-only and never counted.
What you pay for, only when you seal it
Price policy: prices change only by a sealed public event, never a quiet edit. The base price never rises at renewal. We never charge for evidence you already recorded, and we never sell defensibility for periods you did not record. One note on standards: ISO 27001 and SOC 2 run against your own licensed copy of the standard text; GDPR, NIST CSF 2.0 and HIPAA are public text, so there is nothing to buy.
How pricing works
Priced against the work, not your size.
Set against the consultant day rate
A GRC consultant or auditor bills roughly 1,500 to 3,000 a day. A Sealed Audit Package at $1,499 is set against that: what you would have paid a person to reconstruct how your controls operated into a defensible, reviewer-attributed narrative. It is priced against the work it replaces, not against how much of your estate you record.
You pay your AI provider directly
Bring your own model key: your AI usage is billed by your provider, under your contract, at your negotiated terms. Kanonik does not resell AI, does not meter your tokens, and shows you no token counter. Your provider stays your direct contractor and never lands on Kanonik's sub-processor list because of us.
Renewal is not a repricing moment
The $99 you sign at is the $99 you renew at. Any change to the price list is a sealed, published event, never a quiet edit, so we cannot silently reprice you. Cancel anytime; the sealed moments you already paid for stay yours.
You keep what you recorded
The audit log is preserved according to your retention policy and your record is exportable on request. After your confirmation, we crypto-erase your encryption keys and your encrypted data becomes unrecoverable. The chain still verifies; the content becomes unreadable.
Bring your own model
The AI you already pay for. No metering, no markup.
Kanonik is model-agnostic. Connect the AI subscription you already have and it works. We do not sell you an AI license, we do not meter your usage, and we never see your conversations.
Goes to your provider
Your primary AI session runs on your own account. Anthropic Claude, OpenAI, AWS Bedrock, Google Gemini, or Azure OpenAI. Your key, your billing.
One new entry, not two
Under GDPR Article 28, Kanonik becomes a sub-processor on your list (one new entry). Your model vendor does not. If you already have Anthropic or OpenAI on your DPA, that line is unaffected.
The Verifier is independent of your key
The Verifier's tier-2 LLM cross-check runs server-side on Kanonik's own provider account, deliberately separated from whichever provider you chose for the proposer. A model cross-checking itself is not a cross-check. There is no per-call billing from Kanonik; the Verifier is in your plan price on both plans, at the same quality.
Frequently asked
The questions we get most.
Is there a free tier?
No. Solo at $99 a month is the entry plan, and it runs the whole product: your first framework, the Verifier, the approval gate, the hash-chained record. Extra users are $9.99 a month each and additional frameworks are $499 one-time, so you only add cost when you add scope. You can cancel anytime, and the base price never rises at renewal.
Do I have to pay to prove anything?
No. The Proof Snapshot is free on both plans, with no cap on how many you take. It is a sealed, point-in-time record of where your program stands, and whoever you hand it to can check it at kanonik.ai/verify without an account. Pro is not what gives you proof; it is how proof reaches your AI continuously as it works, instead of you downloading a document when somebody asks.
Are there token meters?
No. Kanonik does not meter your usage and shows you no token counter. Your own AI runs on your own model key, so that cost sits with your provider under your contract. The server-side Verifier is the exception, and it runs on Kanonik's account rather than yours: we carry that cost and it is in your plan price, never a per-call charge to you.
Which frameworks does Solo include?
Kanonik runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA, and HIPAA today, and your first framework is included in Solo. Each additional framework is a one-time $499 Framework Activation. ISO 27001 and SOC 2 run against your own licensed copy of the standard text; GDPR, NIST CSF 2.0 and HIPAA are public text, so there is nothing to buy.
What if I run an audit later?
You pay when you seal. A Sealed Audit Package is $1,499, billed only when you finalize and seal a session. If what you need is for someone to be able to check your answers rather than a full audit ceremony, that is Pro at $399 a month. Nothing pushes you onto a bigger recurring plan.
Why $1,499 to seal an audit?
Because a Sealed Audit Package is work an auditor or consultant would otherwise bill roughly a day for: the Auditor Export bundle and the evidence narrative with reviewer attribution. You pay it only when you seal the session, not on a schedule. Auditor access itself is never what you are paying for; that is free.
What happens to my data if I cancel?
The audit log is preserved according to your retention policy. Source-of-truth data is exportable on request. After your confirmation, we crypto-erase your encryption keys and your encrypted data becomes unrecoverable. The audit-log chain still verifies; the content becomes unreadable.
Can I bring my own model account?
Yes. Bring-your-own-model is the default: Anthropic Claude, OpenAI, AWS Bedrock, Google Gemini, or Azure OpenAI. You operate your own model account; we never see your conversations. The server-side Verifier is the deliberate exception: it runs on Kanonik's own provider account, independent of your key, so the cross-check never depends on the model it is checking.
Enterprise
Enterprise and air-gapped deployments.
A dedicated or sovereign deployment: custom retention, EU data residency, tenant-private skills you author with your own signing key, SAML/OIDC federation, and procurement and security-review support.
Read the price, then decide. The work we produce is set against what a consultant would charge to do it by hand. Self-serve, no sales gate.
The proof is the product.