Kanonik
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@KanonikDraft an access control policy for ISO 27001:2022."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Kanonik
Governance runtime for compliance work, connected to Grok over MCP.
Kanonik gives your AI a typed compliance model to work in, a tamper-evident record of everything it does, a server-side Verifier that checks its work, and a human-approval gate in front of every write. Your AI does the reasoning. Kanonik makes the result defensible.
What you can do with it
Ask your AI to work on your compliance program in plain language:
Draft and revise policies and procedures against a loaded framework
Assess internal controls and record the evidence behind each judgement
Find the gaps between what a framework requires and what you actually have
Build an audit trail an assessor can verify independently
Produce a Statement of Applicability, or the equivalent artifact for your framework
The framework in scope comes from your workspace. Kanonik runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0 and HIPAA today. Nothing in the plugin is specific to any one of them.
Related MCP server: PolicyGuard
Installing
/marketplaceThen pick Kanonik. Or from the CLI:
grok plugin install kanonik --trustOn first use your AI connects to https://app.kanonik.ai/mcp and a browser
window opens for sign-in. You will need a Kanonik account; sign up at
kanonik.ai.
What this plugin contains
One file that tells Grok where the Kanonik MCP server lives:
{
"mcpServers": {
"kanonik": { "type": "http", "url": "https://app.kanonik.ai/mcp" }
}
}That is the whole plugin. There is no bundled code, no install script, no hook, and no local process. Everything runs server-side at Kanonik.
Permissions and data
Network. One endpoint,
https://app.kanonik.ai/mcp. Nothing else.Authentication. OAuth 2.1 with Dynamic Client Registration and PKCE, against
https://auth.kanonik.ai. Tokens are held by your Grok client. The plugin holds no credential and ships no secret.Scopes.
kanonik:readto read your compliance record,kanonik:proposeto draft changes,kanonik:committo submit them for approval.Writes. No change reaches your record without a signed single-use approval token and a human clicking to approve it. Your AI cannot approve its own work.
Your other systems. Kanonik never holds credentials to your source systems. If your AI reads from GitHub, Jira, or your identity provider, it does so through its own connections, not through Kanonik.
Links
Site: kanonik.ai
Documentation: kanonik.ai/docs
Contact: kanonik.ai/contact
License
See LICENSE. The Kanonik service itself is proprietary; this repository contains only the connection manifest and documentation for it.
This server cannot be deployed
Maintenance
Related MCP Connectors
Runtime AI governance: decision gates, human approval, hash-chained audit, compliance mapping.
Compliance frameworks (SOC 2, ISO 27001, CMMC, NIST, more) delivered to AI agents as MCP tools.
Register every AI agent, log every action, prove it. EU AI Act compliance built in.
EU compliance corpus across 8 frameworks (NIS2, DORA, AI Act, ISO 27001 + more) via MCP.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceThe only Multi-LLM Compliance Engine (GPT-4o + Claude + DeepSeek). Auto-fix GDPR/LGPD risks and more 15 frameworks. code.guard.eu5 npm1MIT
- FlicenseAqualityFmaintenanceProvides policy-based access control, incident tracking, and compliance monitoring to govern AI agent behavior. It enables organizations to enforce security rules and maintain audit trails by validating agent actions against trust levels and pattern-based policies.61-
- AlicenseAqualityBmaintenanceProvides cryptographic signing and verification for AI decisions to generate verifiable, Ed25519-signed receipts for compliance and auditing. It automatically maps AI actions to regulatory frameworks like HIPAA and SOX with high-performance, sub-3ms signing.4MIT
- AlicenseNot gradedqualityBmaintenanceIntegrates authoritative security compliance frameworks (ISO 27001, NIST 800-53, OWASP ASVS, NIST SSDF) into AI-assisted development, offering control lookups, cross-framework mappings, build-time guardrails, and automated audit evidence generation.123 npm3MIT