Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 56 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 29 EE plugins, of which 28 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 29th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Customized Approach eligibility read from each requirement's own objective cell, identifiers derived from the standard. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Run nsauditor-ai mcp install-key and paste the mcpServers block it prints into your claude_desktop_config.json (it names node and the server script by absolute path), or in Claude Code: claude mcp add nsauditor-ai --env NSA_MCP_AUTH_KEY=<from: nsauditor-ai mcp install-key> -- nsauditor-ai-mcp. Then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
A compliance report is only as honest as its history. This release stops scan history from misreporting in both directions: a finding the scanner stopped looking at is not counted as fixed, and a finding that never went away is no longer counted as closed and new again on every scan — so SLA clocks and time-to-remediate measure remediation. A finding on a port, region or producer a scan did not measure is not counted as fixed, and with SLA tracking on the control it failed is held FAILED — including the prior CVE rows on a service whose lookup failed, the CVE mapper's and the service agent's rows on a TCP port whose service the scan could not identify, and an analysis agent's or the CVE mapper's rows when a plugin they read was left out of the scan or did not complete. Two measured limits: a scan made before EE 1.3.0 could not record a plugin left out of it, so in a comparison with one, an agent's row that scan lacks is not refused — the report's Basis cell says so on the row; and a scan that discovered ports with the Nmap plugin (024) alone records no port oracle, so an analysis agent's or the CVE mapper's row on a port it did not measure can read RESOLVED and count as closed in MTTR, and the control it failed can read PASS — include the port scanner (003). What that buys you: since Enterprise 0.32.4, in the HIPAA, NIST CSF, PCI DSS, ISO 27001, CIS, GDPR and NIST SP 800-171 packs, most cloud findings were counted as closed on each later scan and as newly found, so their age never reached an SLA threshold — a finding is now keyed on its prose with every framework’s control ids removed, so a history written by any earlier release reads correctly with no pack regenerated. A failed CVE lookup’s record now fails, as an evidence gap, the controls its CVE rows map to — 14 controls in seven frameworks; and a plugin left out of a scan is recorded, so the delta refuses its analysis agent’s earlier rows instead of calling them resolved. See the Pro delta report.
In the delta report — nsauditor-ai report --from <dir> --format executive --since prior, what is new, what is resolved and what changed severity in the client-ready HTML report — when the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE, with the reason on the row, instead of calling it resolved — among the reasons: a host that was not scanned; a finding that carries no producer identity; a plugin that did not run, errored or timed out; an analysis agent that did not run, or whose input plugin was left out of the scan or did not complete; an Enterprise package that failed to load; an evidence gap, including a CVE lookup that failed; a narrower scope; a port whose check could not complete; a TCP port the port scanner saw open that stopped answering between the two scans, or that answered without its service being identified (for a CVE or end-of-life row); a UDP port the other scan did not record as closed or answering; a producer whose identity basis changed across an upgrade; and a CVE the vulnerability data stopped attributing while the same program and version still answer. A finding that could not be compared is not a finding that was fixed. Two measured limits remain: a scan made before Enterprise 1.3.0 could not record a plugin left out of it, so in a comparison with one, an agent’s row that scan lacks is not refused — the report’s Basis cell says so on the row; and a scan that discovered ports with the Nmap plugin (024) alone records no port oracle, so an analysis agent’s or the CVE mapper’s row on a port it did not measure can read RESOLVED and count as closed in MTTR, and the control it failed can read PASS — include the port scanner (003) in scans you compare. Beside every comparison the report states that framework-enumeration movement is not evaluated, and the baseline’s integrity state; each new, resolved and changed row’s Basis cell says what was checked for that row.
Upgrade both packages together: below the Community floor, Enterprise does not load while license --plugins still lists the Enterprise plugins and the scan skips the CVE, analysis-agent and compliance stages — Community 0.2.56 names the failed load on stderr, and an older Community says nothing. Rescan after upgrading before you compare: the exposure agent’s, the service agent’s and plugin 1160’s rows changed what identifies them, so a comparison across the upgrade reads them identity-basis-changed, never RESOLVED or NEW. Coverage: all eight coverage matrices unchanged since EE 1.2.0. 29 Enterprise auditors (28 cloud auditors + 1 non-cloud), 56 plugins overall; floor CE ≥ 0.2.57. Release notes live in the package CHANGELOG.md.
report --from <dir> --format executive → self-contained executive HTML, or --format jira → a Jira-importer CSV