New in EE 0.33.1 — auditor-verifiable proof in all seven framework reports: trusted timestamping, opt-in, verified offline by your auditor (requires CE 0.2.37+) →

Security Intelligence
Without Data Exposure.

Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32, mapped from a single pass across AWS, Azure and GCP. 55 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.

nsauditor-ai — scan
$ nsauditor-ai scan --host aws --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr
55 plugins loaded (27 CE + 28 EE)
Frameworks: SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO 27001:2022 · CIS Controls v8 · GDPR Art. 32
scan_compliance_soc2.{md,html,json} → 10/4/37
scan_compliance_hipaa.{md,html,json} → 7/3/45
scan_compliance_nist-csf.{md,html,json} → 13/10/83
scan_compliance_pci-dss.{md,html,json} → 19/9/39 MVP-67
scan_compliance_iso-27001.{md,html,json} → 17/14/62
scan_compliance_cis-v8.{md,html,json} → 17/23/113
scan_compliance_gdpr.{md,html,json} → 4/5/2 Art.32 substrate
Any cloud that could not be scanned is recorded as a fail-closed evidence gap — never as a pass
Zero data exfiltration — no findings left your infra
# Audit a cloud account directly from Claude Desktop (MCP) — "audit my AWS account"
$ nsauditor-ai scan --host aws --env ~/envs/prod.env --compliance soc2
$ nsauditor-ai scan --host aws --aws-profile prod --compliance soc2
Get Started

The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed

What's Inside
🔒

Zero Data Exfiltration

Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.

🎯

Risk-Scored Prioritization

Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.

🤖

AI-Powered Analysis

OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.

📊

55 Scanner Plugins

27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 28 EE plugins, of which 27 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 28th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.

📋

Hepta-Framework Compliance

SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 (Security of Processing) — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.

🔌

MCP Integration — free in Community

The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."

Latest Release — EE 0.33.1 · CE 0.2.38 · agent-skill 0.2.36 · 7 August 2026 · 91st consecutive trio
📦

Proof your auditor can check without us

Every assessor eventually asks how they know an evidence file was not edited after it was produced. All seven framework reports now answer it in writing. Set NSAUDITOR_TSA_URL to a Time-Stamp Authority you choose and every compliance artifact carries an RFC 3161 .tsr sidecar your auditor verifies offline with stock openssl — opt-in, no default ever, with none of our software in the path. Eleven compliance options that nothing could populate now receive values too; the entry points live in the Community Edition, so EE 0.33.1 requires CE 0.2.37 or newer.

🛡️

Zero Data Exfiltration, stated as a register

The claim used to be a negative — nothing leaves — and a negative cannot be audited, because there is no list to check against. It has been rebuilt as a positive register of 17 enumerated outbound paths, each one named and accounted for. A reviewer now compares the register to the code instead of taking the absence on trust.

🔏

Signature records carry algorithm and backend

A signature record that does not say what signed it, and with what, cannot be verified by anyone who did not watch it being made. Algorithm and backend are now frozen into the record at creation — from the first byte, rather than inferred afterwards from whatever the current build happens to do.

⏱️

RFC 3161 timestamping — opt-in

Set NSAUDITOR_TSA_URL and the evidence pack is timestamped by the authority you name, verified against a real timestamp authority on 7 August 2026. It is opt-in and off by default, because it is an outbound call to a third party and the air-gapped posture does not make one unless you ask. Ed25519 suppression signing is still not reachable — no shipped entry point signs a suppression record — so evidence integrity rests on the SHA-256 chain-of-custody sidecars, which verify offline.

📐

Coverage and plugin count unchanged

All seven coverage matrices are unchanged — SOC 2 10/4/37 · HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2. The plugin count is unchanged at 28 EE (55 in total), of which 27 are cloud auditors across AWS, Azure and GCP; the 28th, Zero Trust Assessment, scores posture from a network-host scan and calls no cloud API. All 28 install and load active.

🕘

Previously — EE 0.32.11, 0.32.9 and 0.32.8

0.32.11 (5 August 2026): the dependency-advisory release gate had been auditing the maintainer's development tree while calling itself the production closure — it now packs the tarball, installs it into an empty directory the way a customer does, and audits that, and it refuses to report clean until it has proved an advisory database actually answered. The two measurements barely overlap: development tree 25 advisories / 8 high, customer closure 6 / none high, sharing 5 of 26 packages and not one shared high. The SOC 2 matrix was also enumerated in full at 10 covered · 4 partial · 37 out of scope = 51 — enumeration completeness, not a coverage change. 0.32.9 (29 July 2026): internal engineering identifiers were stripped out of the evidence pack — 686 unexplained internal-marker occurrences → 0 across 105 files, with a positive control in the same run (3,572 benign matches still detected). And a cloud that could not be scanned stopped reading clean: every in-scope control of such a cloud now carries a fail-closed evidence gap. Two migration notes still apply when coming from 0.32.8 or earlier — the evidence-gap finding title changed, so suppression rules matching the old text stop matching (findings resurface rather than hide, but silently); and re-scan rather than re-process scans captured before 0.32.9. 0.32.8 (28 July 2026): capability-claim honesty pass, part 2 — 27 advertised claims across the three published packages were verified against the code and withdrawn: arm64 images, offline installation tarballs, monthly NVD feed bundles, an air-gapped install script, a feed-import CLI command with no implementation, and the Community Edition's absolute "works without internet access" claim. Both releases were matrix-neutral.

Viewing Scan Reports
out/<host>_<timestamp>/ — output files
scan_response_ai.html Styled AI report — CVE links, risk badges, remediation guidance
scan_conclusion_raw.html Full admin detail — interactive filters, all plugin findings unredacted
scan_intelligence.json CVE matches, MITRE ATT&CK mapping, risk scores (Pro)
scan_conclusion_raw.json Full machine-readable conclusion for automation
scan_response_ai.txt AI analysis as plain Markdown — paste into issues, Slack, chat
scan_compliance_soc2.{html,json,md} SOC 2 evidence pack — AICPA TSC 2017, SHA-256 chain-of-custody (EE)
scan_compliance_hipaa.{html,json,md} HIPAA §164.312 evidence pack — R/A discipline, Zero BAA (EE)
scan_compliance_nist-csf.{html,json,md} NIST CSF 2.0 evidence pack — subcategory-level, SP 800-53 refs (EE)
scan_compliance_pci-dss.{html,json,md} PCI DSS v4.0.1 evidence pack — sub-requirement-level for QSA RoC, CHD Scope operator-attested, card-brand AOC enforcement view (EE)
scan_compliance_gdpr.{html,json,md} GDPR Article 32 evidence pack — Security-of-Processing infrastructure substrate (Art. 32 only, not GDPR compliance), 4 covered + 5 partial + 2 OOS across 11 sub-measure units (EE)
Open reports in your browser
# macOS — open AI report open out/192.168.1.1_*/scan_response_ai.html # macOS — open full admin detail open out/192.168.1.1_*/scan_conclusion_raw.html # Linux xdg-open out/192.168.1.1_*/scan_response_ai.html # Custom output directory nsauditor-ai scan --host 10.0.0.1 --out ./reports open ./reports/10.0.0.1_*/scan_response_ai.html # Markdown report (paste-ready) nsauditor-ai scan --host 10.0.0.1 --output-format md
55
Scanner Plugins
7
Compliance Frameworks
MIT
Licensed
0
Data Collected
Three Editions
Community
Free
forever, MIT licensed
npm install -g nsauditor-ai
  • 27 scanner plugins
  • AI analysis (OpenAI, Claude, Ollama)
  • CTEM watch mode
  • SARIF + CSV export
  • MCP server (Claude Desktop / Code / Cursor)
Pro
$39/mo
billed $470/yr · save 20% vs monthly
Learn More & Subscribe →
  • CVE matching + MITRE
  • Parallel analysis agents
  • Finding queue + suppression workflow
  • Risk scoring
  • Intelligence-enriched AI reports