Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 56 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 29 EE plugins, of which 28 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 29th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Customized Approach eligibility read from each requirement's own objective cell, identifiers derived from the standard. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Run nsauditor-ai mcp install-key and paste the mcpServers block it prints into your claude_desktop_config.json (it names node and the server script by absolute path), or in Claude Code: claude mcp add nsauditor-ai --env NSA_MCP_AUTH_KEY=<from: nsauditor-ai mcp install-key> -- nsauditor-ai-mcp. Then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
The most expensive word in a security report is “resolved”. This release refuses to call a finding fixed when the second scan never looked — and states, in the release itself, the two places it still cannot be sure. A finding on a port, region or producer a scan did not measure is not counted as fixed, and with SLA tracking on the control it failed is held FAILED. Two measured limits in this release: after a CVE lookup that failed, the prior CVE rows are not counted as fixed, but the controls they failed are not held FAILED and can read PASS; and when two compared scans ran different --plugins sets, a row an analysis agent or the CVE mapper derived from a plugin only one of them requested can read RESOLVED or NEW. When the later scan left the plugin out, the row also counts as closed in MTTR and its control can read PASS. Keep --plugins identical between compared scans. Measured, not promised: on a real router run compared with a twin that drops its 22 UDP rows, the previous release reported all 22 resolved and this release reports all 22 not comparable; and five dnsmasq 2.78 CVEs that NVD stopped matching while the same dnsmasq 2.78 still answered — called resolved by the previous delta and counted closed by the compliance pack with an MTTR of about a day — now read NOT COMPARABLE: the vulnerability data changed, not the estate. See the Pro delta report.
In the delta report — nsauditor-ai report --from <dir> --format executive --since prior, what is new, what is resolved and what changed severity in the client-ready HTML report — when the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE, with the reason on the row, instead of calling it resolved — among the reasons: a host that was not scanned; a finding that carries no producer identity; a plugin that did not run, errored or timed out; an analysis agent that did not run; an Enterprise package that failed to load; an evidence gap, including a CVE lookup that failed; a narrower scope; a port whose check could not complete; a TCP port the port scanner saw open that stopped answering between the two scans, or a UDP port the other scan did not record as closed or answering; a producer whose identity basis changed across an upgrade; and a CVE the vulnerability data stopped attributing while the same program and version still answer. A finding that could not be compared is not a finding that was fixed. Two measured limits remain: when the two scans ran different --plugins sets, a row an analysis agent or the CVE mapper derived from a plugin only one of them requested can read RESOLVED or NEW, so keep --plugins identical between compared scans; and after a CVE lookup that failed, the prior CVE rows are not counted as fixed, but the controls they failed are not held FAILED and can read PASS. Beside every comparison the report states that framework-enumeration movement is not evaluated, and the baseline’s integrity state. Two scans of one host whose plugin runs finished in the same second no longer share an output directory.
Upgrade both packages together: on the previous Community release, Enterprise’s plugins still load and license --plugins reports Enterprise (loaded), but the scan skips the CVE, analysis-agent and compliance stages without a word; this Community release names a failed Enterprise load on stderr. Coverage: all eight coverage matrices unchanged since EE 1.1.0. 29 Enterprise auditors (28 cloud auditors + 1 non-cloud), 56 plugins overall; floor CE ≥ 0.2.56. Release notes live in the package CHANGELOG.md.
report --from <dir> --format executive → self-contained executive HTML, or --format jira → a Jira-importer CSV