New in EE 0.37.0 — a compliance report now checks a suppression signature against the approver's key material, wherever the identity registry carries it (requires CE 0.2.43+) →

Security Intelligence
Without Data Exposure.

Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32, mapped from a single pass across AWS, Azure and GCP. 55 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.

nsauditor-ai — scan
$ nsauditor-ai scan --host aws --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr
55 plugins loaded (27 CE + 28 EE)
Frameworks: SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO 27001:2022 · CIS Controls v8 · GDPR Art. 32
scan_compliance_soc2.{md,html,json} → 10/4/37
scan_compliance_hipaa.{md,html,json} → 7/3/45
scan_compliance_nist-csf.{md,html,json} → 13/10/83
scan_compliance_pci-dss.{md,html,json} → 19/9/39 MVP-67
scan_compliance_iso-27001.{md,html,json} → 17/14/62
scan_compliance_cis-v8.{md,html,json} → 17/23/113
scan_compliance_gdpr.{md,html,json} → 4/5/2 Art.32 substrate
Any cloud that could not be scanned is recorded as a fail-closed evidence gap — never as a pass
Zero data exfiltration — no findings left your infra
# Audit a cloud account directly from Claude Desktop (MCP) — "audit my AWS account"
$ nsauditor-ai scan --host aws --env ~/envs/prod.env --compliance soc2
$ nsauditor-ai scan --host aws --aws-profile prod --compliance soc2
Get Started

The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed

What's Inside
🔒

Zero Data Exfiltration

Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.

🎯

Risk-Scored Prioritization

Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.

🤖

AI-Powered Analysis

OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.

📊

55 Scanner Plugins

27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 28 EE plugins, of which 27 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 28th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.

📋

Hepta-Framework Compliance

SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 (Security of Processing) — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.

🔌

MCP Integration — free in Community

The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."

Latest Release — EE 0.38.0 · CE 0.2.43 · agent-skill 0.2.41 · 17 August 2026 · 96th consecutive trio
🖊️

An evidence pack can be signed, and the verifier checks more than the signature

A pack already carried SHA-256 sidecars — integrity, but nothing that says who produced it. EE 0.38.0 adds compliance sign-pack and compliance verify-pack: the chain-of-custody envelope is signed at an approval station with an operator-held Ed25519 key, so the scanning fleet stays keyless and authorship is relative to your own key custody — never a vendor attestation. The verifier also recomputes every artifact hash against disk, because a check of the signature alone would authenticate a manifest whose artifact claims nothing had ever verified. Scope, stated plainly: a verified signature proves the holder of a key asserted authorship of one framework’s envelope at a stated time, relative to your own key custody — never a vendor attestation, and never proof the findings are true. Verify it offline with openssl and nothing of ours.

📐

Coverage and plugin count unchanged

All seven coverage matrices are unchanged — SOC 2 10/4/37 · HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2. The plugin count is unchanged at 28 EE (55 in total), of which 27 are cloud auditors across AWS, Azure and GCP; the 28th, Zero Trust Assessment, scores posture from a network-host scan and calls no cloud API. All 28 install and load active.

🕘

Previously — EE 0.37.0 and earlier

0.37.0: vulnerability data you can carry onto a network that cannot fetch it — feed bundle merges the NVD files you downloaded, feed import ingests them on the isolated host. 0.36.0: a report stopped taking an approval record at its word and began checking the signature against the approver’s registered key material, with verified and cryptoValid kept as separate questions so a revoked key makes them disagree. 0.35.0: suppression approvals got a command line — an accepted risk carries an owner, a rationale, a date and an expiry. 0.33.0: RFC 3161 trusted timestamping, opt-in to the authority you name, with no default and refused under NSAUDITOR_OFFLINE_ONLY. Full changelog →

Viewing Scan Reports
out/<host>_<timestamp>/ — output files
scan_response_ai.html Styled AI report — CVE links, risk badges, remediation guidance
scan_conclusion_raw.html Full admin detail — interactive filters, all plugin findings unredacted
scan_intelligence.json CVE matches, MITRE ATT&CK mapping, risk scores (Pro)
scan_conclusion_raw.json Full machine-readable conclusion for automation
scan_response_ai.txt AI analysis as plain Markdown — paste into issues, Slack, chat
scan_compliance_soc2.{html,json,md} SOC 2 evidence pack — AICPA TSC 2017, SHA-256 chain-of-custody (EE)
scan_compliance_hipaa.{html,json,md} HIPAA §164.312 evidence pack — R/A discipline, Zero BAA (EE)
scan_compliance_nist-csf.{html,json,md} NIST CSF 2.0 evidence pack — subcategory-level, SP 800-53 refs (EE)
scan_compliance_pci-dss.{html,json,md} PCI DSS v4.0.1 evidence pack — sub-requirement-level for QSA RoC, CHD Scope operator-attested, card-brand AOC enforcement view (EE)
scan_compliance_gdpr.{html,json,md} GDPR Article 32 evidence pack — Security-of-Processing infrastructure substrate (Art. 32 only, not GDPR compliance), 4 covered + 5 partial + 2 OOS across 11 sub-measure units (EE)
Open reports in your browser
# macOS — open AI report open out/192.168.1.1_*/scan_response_ai.html # macOS — open full admin detail open out/192.168.1.1_*/scan_conclusion_raw.html # Linux xdg-open out/192.168.1.1_*/scan_response_ai.html # Custom output directory nsauditor-ai scan --host 10.0.0.1 --out ./reports open ./reports/10.0.0.1_*/scan_response_ai.html # Markdown report (paste-ready) nsauditor-ai scan --host 10.0.0.1 --output-format md
55
Scanner Plugins
7
Compliance Frameworks
MIT
Licensed
0
Data Collected
Three Editions
Community
Free
forever, MIT licensed
npm install -g nsauditor-ai
  • 27 scanner plugins
  • AI analysis (OpenAI, Claude, Ollama)
  • CTEM watch mode
  • SARIF + CSV export
  • MCP server (Claude Desktop / Code / Cursor)
Pro
$39/mo
billed $470/yr · save 20% vs monthly
Learn More & Subscribe →
  • CVE matching + MITRE
  • Parallel analysis agents
  • Finding queue + suppression workflow
  • Risk scoring
  • Exploit intelligence — CISA KEV + FIRST EPSS (stores you populate)
  • Intelligence-enriched AI reports