The eighth compliance framework — NIST SP 800-171 Rev 2, evidence substrate for CMMC Level 2 preparation, from the same single scan →

Security Intelligence
Without Data Exposure.

Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 56 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.

nsauditor-ai — scan
$ nsauditor-ai scan --host aws --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171
56 plugins loaded (27 CE + 29 EE)
Frameworks: SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO 27001:2022 · CIS Controls v8 · GDPR Art. 32 · NIST SP 800-171
scan_compliance_soc2.{md,html,json} → 10/4/37
scan_compliance_hipaa.{md,html,json} → 7/3/45
scan_compliance_nist-csf.{md,html,json} → 13/10/83
scan_compliance_pci-dss.{md,html,json} → 19/9/39 MVP-67
scan_compliance_iso-27001.{md,html,json} → 17/14/62
scan_compliance_cis-v8.{md,html,json} → 17/23/113
scan_compliance_gdpr.{md,html,json} → 4/5/2 Art.32 substrate
Any cloud that could not be scanned is recorded as a fail-closed evidence gap — never as a pass
Zero data exfiltration — no findings left your infra
# Audit a cloud account directly from Claude Desktop (MCP) — "audit my AWS account"
$ nsauditor-ai scan --host aws --env ~/envs/prod.env --compliance soc2
$ nsauditor-ai scan --host aws --aws-profile prod --compliance soc2
Get Started

The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed

What's Inside
🔒

Zero Data Exfiltration

Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.

🎯

Risk-Scored Prioritization

Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.

🤖

AI-Powered Analysis

OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.

📊

56 Scanner Plugins

27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 29 EE plugins, of which 28 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 28th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.

📋

Octa-Framework Compliance

SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.

🔌

MCP Integration — free in Community

The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."

Latest Release — EE 0.42.0 · CE 0.2.49 · agent-skill 0.2.47 · 27 August 2026 · 102nd consecutive trio
🍃

The 29th plugin: Amazon DocumentDB gets its own auditor

DocumentDB answers the same AWS APIs as RDS, and that shared control plane hid a real blind spot: a DocumentDB cluster with storage encryption disabled could read clean under the RDS auditor’s Aurora-only filter. The new 1230 AWS DocumentDB Auditor owns the docdb engine across seven dimensions — storage encryption with KMS key custody, TLS via the tls cluster parameter, audit logging with the CloudWatch export, backup retention, deletion protection, replica/AZ availability topology under the cluster lens DocumentDB actually uses, and whether manual cluster snapshots are restorable publicly or by accounts you did not intend. The RDS auditor now engine-filters DocumentDB and Neptune off the shared plane with a standing disclosure that a Neptune estate is unaudited. Verified live against paired fixtures — before the fix, 26 of 26 findings misattributed DocumentDB under RDS vocabulary; after it, zero. See a sample scan →

📐

Plugin count 28 → 29; all eight matrices unchanged

All eight coverage matrices are unchanged — SOC 2 10/4/37 · HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2 · NIST SP 800-171 Rev 2 2/49/59. The 1230 DocumentDB auditor routes to already-covered controls, so it is evidence depth, not new coverage. The plugin count is now 29 EE (56 in total), of which 28 are cloud auditors across AWS, Azure and GCP; the 29th, Zero Trust Assessment, scores posture from a network-host scan and calls no cloud API. All 29 install and load active.

🕘

Previously — EE 0.40.0 and earlier

0.40.0: the eighth compliance framework — NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, all 110 Rev 2 requirements enumerated at the SP 800-171A determination-statement level. 0.40.3: the evidence chain checks itself — on the opt-in RFC 3161 path every timestamp token is matched against the exact artifact digest it attests before anything is written, and the verification instruction on the report cover page runs exactly as printed. 0.38.0: an evidence pack can be signed — compliance sign-pack signs one framework’s chain-of-custody envelope with an operator-held Ed25519 key, and compliance verify-pack establishes authorship and then recomputes every artifact hash against disk, because checking the signature alone would authenticate a manifest whose artifact claims nothing had verified. 0.37.0: vulnerability data you can carry onto a network that cannot fetch it — feed bundle merges the NVD files you downloaded, feed import ingests them on the isolated host. 0.36.0: a report stopped taking an approval record at its word and began checking the signature against the approver’s registered key material, with verified and cryptoValid kept as separate questions so a revoked key makes them disagree. 0.35.0: suppression approvals got a command line — an accepted risk carries an owner, a rationale, a date and an expiry. Full changelog →

Viewing Scan Reports
out/<host>_<timestamp>/ — output files
scan_response_ai.html Styled AI report — CVE links, risk badges, remediation guidance
scan_conclusion_raw.html Full admin detail — interactive filters, all plugin findings unredacted
scan_intelligence.json CVE matches, MITRE ATT&CK mapping, risk scores (Pro)
scan_conclusion_raw.json Full machine-readable conclusion for automation
scan_response_ai.txt AI analysis as plain Markdown — paste into issues, Slack, chat
scan_compliance_soc2.{html,json,md} SOC 2 evidence pack — AICPA TSC 2017, SHA-256 chain-of-custody (EE)
scan_compliance_hipaa.{html,json,md} HIPAA §164.312 evidence pack — R/A discipline, Zero BAA (EE)
scan_compliance_nist-csf.{html,json,md} NIST CSF 2.0 evidence pack — subcategory-level, SP 800-53 refs (EE)
scan_compliance_pci-dss.{html,json,md} PCI DSS v4.0.1 evidence pack — sub-requirement-level for QSA RoC, CHD Scope operator-attested, card-brand AOC enforcement view (EE)
scan_compliance_gdpr.{html,json,md} GDPR Article 32 evidence pack — Security-of-Processing infrastructure substrate (Art. 32 only, not GDPR compliance), 4 covered + 5 partial + 2 OOS across 11 sub-measure units (EE)
Open reports in your browser
# macOS — open AI report open out/192.168.1.1_*/scan_response_ai.html # macOS — open full admin detail open out/192.168.1.1_*/scan_conclusion_raw.html # Linux xdg-open out/192.168.1.1_*/scan_response_ai.html # Custom output directory nsauditor-ai scan --host 10.0.0.1 --out ./reports open ./reports/10.0.0.1_*/scan_response_ai.html # Markdown report (paste-ready) nsauditor-ai scan --host 10.0.0.1 --output-format md
55
Scanner Plugins
8
Compliance Frameworks
MIT
Licensed
0
Data Collected
Three Editions
Community
Free
forever, MIT licensed
npm install -g nsauditor-ai
  • 27 scanner plugins
  • AI analysis (OpenAI, Claude, Ollama)
  • CTEM watch mode
  • SARIF + CSV export
  • MCP server (Claude Desktop / Code / Cursor)
Pro
$39/mo
billed $470/yr · save 20% vs monthly
Learn More & Subscribe →
  • CVE matching + MITRE
  • Parallel analysis agents
  • Finding queue + suppression workflow
  • Risk scoring
  • Exploit intelligence — CISA KEV + FIRST EPSS (stores you populate)
  • Intelligence-enriched AI reports