New in EE 1.2.0 — a finding on a port, region or producer a scan did not measure is not counted as fixed — two measured limits stated →

Security Intelligence
Without Data Exposure.

Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 56 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.

nsauditor-ai — scan
$ nsauditor-ai scan --host aws --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171
✓ 56 plugins loaded (27 CE + 29 EE)
✓ Frameworks: SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO 27001:2022 · CIS Controls v8 · GDPR Art. 32 · NIST SP 800-171
✓ scan_compliance_soc2.{md,html,json} → 10/4/37
✓ scan_compliance_hipaa.{md,html,json} → 7/3/45
✓ scan_compliance_nist-csf.{md,html,json} → 13/10/83
✓ scan_compliance_pci-dss.{md,html,json} → 19/9/44 · 72 enumerated
✓ scan_compliance_iso-27001.{md,html,json} → 17/14/62
✓ scan_compliance_cis-v8.{md,html,json} → 17/23/113
✓ scan_compliance_gdpr.{md,html,json} → 4/5/2 Art.32 substrate
✓ Any cloud that could not be scanned is recorded as a fail-closed evidence gap — never as a pass
✓ Zero data exfiltration — no findings left your infra
# Audit a cloud account directly from Claude Desktop (MCP) — "audit my AWS account"
$ nsauditor-ai scan --host aws --env ~/envs/prod.env --compliance soc2
$ nsauditor-ai scan --host aws --aws-profile prod --compliance soc2
Get Started

The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed

What's Inside
🔒

Zero Data Exfiltration

Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.

🎯

Risk-Scored Prioritization

Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.

🤖

AI-Powered Analysis

OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.

📊

56 Scanner Plugins

27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 29 EE plugins, of which 28 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 29th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.

📋

Octa-Framework Compliance

SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Customized Approach eligibility read from each requirement's own objective cell, identifiers derived from the standard. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.

🔌

MCP Integration — free in Community

The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Run nsauditor-ai mcp install-key and paste the mcpServers block it prints into your claude_desktop_config.json (it names node and the server script by absolute path), or in Claude Code: claude mcp add nsauditor-ai --env NSA_MCP_AUTH_KEY=<from: nsauditor-ai mcp install-key> -- nsauditor-ai-mcp. Then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."

Latest Release — EE 1.2.0 · CE 0.2.56 · agent-skill 0.2.54 · 2026-10-04
📖

EE 1.2.0 — a finding on a port, region or producer a scan did not measure is not counted as fixed — two measured limits stated

The most expensive word in a security report is “resolved”. This release refuses to call a finding fixed when the second scan never looked — and states, in the release itself, the two places it still cannot be sure. A finding on a port, region or producer a scan did not measure is not counted as fixed, and with SLA tracking on the control it failed is held FAILED. Two measured limits in this release: after a CVE lookup that failed, the prior CVE rows are not counted as fixed, but the controls they failed are not held FAILED and can read PASS; and when two compared scans ran different --plugins sets, a row an analysis agent or the CVE mapper derived from a plugin only one of them requested can read RESOLVED or NEW. When the later scan left the plugin out, the row also counts as closed in MTTR and its control can read PASS. Keep --plugins identical between compared scans. Measured, not promised: on a real router run compared with a twin that drops its 22 UDP rows, the previous release reported all 22 resolved and this release reports all 22 not comparable; and five dnsmasq 2.78 CVEs that NVD stopped matching while the same dnsmasq 2.78 still answered — called resolved by the previous delta and counted closed by the compliance pack with an MTTR of about a day — now read NOT COMPARABLE: the vulnerability data changed, not the estate. See the Pro delta report.

In the delta report — nsauditor-ai report --from <dir> --format executive --since prior, what is new, what is resolved and what changed severity in the client-ready HTML report — when the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE, with the reason on the row, instead of calling it resolved — among the reasons: a host that was not scanned; a finding that carries no producer identity; a plugin that did not run, errored or timed out; an analysis agent that did not run; an Enterprise package that failed to load; an evidence gap, including a CVE lookup that failed; a narrower scope; a port whose check could not complete; a TCP port the port scanner saw open that stopped answering between the two scans, or a UDP port the other scan did not record as closed or answering; a producer whose identity basis changed across an upgrade; and a CVE the vulnerability data stopped attributing while the same program and version still answer. A finding that could not be compared is not a finding that was fixed. Two measured limits remain: when the two scans ran different --plugins sets, a row an analysis agent or the CVE mapper derived from a plugin only one of them requested can read RESOLVED or NEW, so keep --plugins identical between compared scans; and after a CVE lookup that failed, the prior CVE rows are not counted as fixed, but the controls they failed are not held FAILED and can read PASS. Beside every comparison the report states that framework-enumeration movement is not evaluated, and the baseline’s integrity state. Two scans of one host whose plugin runs finished in the same second no longer share an output directory.

Upgrade both packages together: on the previous Community release, Enterprise’s plugins still load and license --plugins reports Enterprise (loaded), but the scan skips the CVE, analysis-agent and compliance stages without a word; this Community release names a failed Enterprise load on stderr. Coverage: all eight coverage matrices unchanged since EE 1.1.0. 29 Enterprise auditors (28 cloud auditors + 1 non-cloud), 56 plugins overall; floor CE ≥ 0.2.56. Release notes live in the package CHANGELOG.md.

Viewing Scan Reports
out/<host>_<timestamp>/ — output files
scan_response_ai.html Styled AI report — CVE links, risk badges, remediation guidance
scan_conclusion_raw.html Full admin detail — interactive filters, all plugin findings unredacted
scan_intelligence.json CVE matches, MITRE ATT&CK mapping, risk scores (Pro)
scan_conclusion_raw.json Full machine-readable conclusion for automation
scan_response_ai.txt AI analysis as plain Markdown — paste into issues, Slack, chat
scan_compliance_soc2.{html,json,md} SOC 2 evidence pack — AICPA TSC 2017, SHA-256 chain-of-custody (EE)
scan_compliance_hipaa.{html,json,md} HIPAA §164.312 evidence pack — R/A discipline, Zero BAA (EE)
scan_compliance_nist-csf.{html,json,md} NIST CSF 2.0 evidence pack — subcategory-level, SP 800-53 refs (EE)
scan_compliance_pci-dss.{html,json,md} PCI DSS v4.0.1 evidence pack — sub-requirement-level for QSA RoC, CHD Scope operator-attested, card-brand AOC enforcement view (EE)
scan_compliance_gdpr.{html,json,md} GDPR Article 32 evidence pack — Security-of-Processing infrastructure substrate (Art. 32 only, not GDPR compliance), 4 covered + 5 partial + 2 OOS across 11 sub-measure units (EE)
Open reports in your browser
# macOS — open AI report open out/192.168.1.1_*/scan_response_ai.html # macOS — open full admin detail open out/192.168.1.1_*/scan_conclusion_raw.html # Linux xdg-open out/192.168.1.1_*/scan_response_ai.html # Custom output directory nsauditor-ai scan --host 10.0.0.1 --out ./reports open ./reports/10.0.0.1_*/scan_response_ai.html # Markdown report (paste-ready) nsauditor-ai scan --host 10.0.0.1 --output-format md
56
Scanner Plugins
8
Compliance Frameworks
MIT
Licensed
0
Data Collected
Three Editions
Community
Free
forever, MIT licensed
npm install -g nsauditor-ai
  • 27 scanner plugins
  • AI analysis (OpenAI, Claude, Ollama)
  • CTEM watch mode
  • SARIF + CSV export
  • MCP server (Claude Desktop / Code / Cursor)
Pro
$39/mo
billed $470/yr · save 20% vs monthly
Learn More & Subscribe →
  • CVE matching + MITRE
  • Parallel analysis agents
  • Finding queue + suppression workflow
  • Risk scoring
  • Exploit intelligence — CISA KEV + FIRST EPSS (stores you populate)
  • Send-ready reports — report --from <dir> --format executive → self-contained executive HTML, or --format jira → a Jira-importer CSV
  • Delta reports — what changed since the last scan, and a not-comparable list with the reason on every row
  • Intelligence-enriched AI reports