Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 55 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 28 EE plugins, of which 27 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 28th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
NIST SP 800-171 Rev 2 joins SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32 — eight frameworks, one agentless read-only scan. Every mapped requirement carries the full list of its SP 800-171A determination statements alongside the 81 of 172 this engine supplies examine-method material for, across the 51 mapped requirements — so a C3PAO reads exactly which objectives your configuration already evidences, and “partial” names which of three shortfalls it actually is. All 110 Rev 2 requirements are enumerated with no declared subset, and Rev 2 is pinned deliberately because CMMC assesses Rev 2 by rule. Scoped as evidence substrate for CMMC Level 2 preparation: it feeds your System Security Plan and POA&M and leaves the determination with your assessor. Read the coverage page →
Eight coverage matrices, seven of them unchanged — SOC 2 10/4/37 · HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2 · and the new NIST SP 800-171 Rev 2 at 2/49/59 = 110. The plugin count is unchanged at 28 EE (55 in total), of which 27 are cloud auditors across AWS, Azure and GCP; the 28th, Zero Trust Assessment, scores posture from a network-host scan and calls no cloud API. All 28 install and load active.
0.38.0: an evidence pack can be signed — compliance sign-pack signs one framework’s chain-of-custody envelope with an operator-held Ed25519 key, and compliance verify-pack establishes authorship and then recomputes every artifact hash against disk, because checking the signature alone would authenticate a manifest whose artifact claims nothing had verified. 0.37.0: vulnerability data you can carry onto a network that cannot fetch it — feed bundle merges the NVD files you downloaded, feed import ingests them on the isolated host. 0.36.0: a report stopped taking an approval record at its word and began checking the signature against the approver’s registered key material, with verified and cryptoValid kept as separate questions so a revoked key makes them disagree. 0.35.0: suppression approvals got a command line — an accepted risk carries an owner, a rationale, a date and an expiry. Full changelog →