Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32, mapped from a single pass across AWS, Azure and GCP. 55 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 28 EE cloud plugins: AWS S3, GCP, Azure, Zero Trust, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 (Security of Processing) — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
A compliance report is a document you hand your auditor, so it should read like one. Ours carried internal engineering identifiers — roadmap ids, internal release stamps, the name of an internal audit review — in finding titles, on the attestation cover page and in the chain-of-custody record. Measured on a rebuilt three-cloud evidence pack: 686 unexplained internal-marker occurrences → 0 across 105 files, with a positive control in the same run (3,572 benign matches still detected), so the zero is a measurement rather than an absence of looking.
When a cloud plugin could not start — an optional SDK absent, credentials unusable — it refused to report, and that refusal evaporated one layer up: the compliance report came out byte-identical to one where the scanner ran and found nothing. Ten controls read PASS, no violation, no warning. The dangerous shape is ordinary: AWS and GCP scan for real, Azure's SDK is absent, and the combined pack reads as a clean three-cloud audit. Now every in-scope control of a cloud that could not be scanned carries a fail-closed evidence gap.
An archived scan re-processed by the new build warns instead of failing clean. Four report surfaces that contradicted each other on trusted timestamping now say the same verifiable thing. In the Community Edition, --out <dir> no longer writes to the parent directory when the directory name contains a dot; the MCP scan_cloud summary handles both spellings of the evidence-gap prefix; and validate no longer misreports where plugins came from. New instrument: a pack scanner that fails closed when its own positive control comes back empty.
First, the evidence-gap finding title changed, so suppression rules matching the old text stop matching. That is the safe direction — findings resurface rather than hide — but the change is silent, so re-check your suppression rules. Second, re-scan rather than re-process scans captured before 0.32.9; the engine now warns when it is handed one.
Nothing about coverage moved. 28 cloud plugins and all seven coverage matrices are identical to 0.32.8, counts and control-id membership alike: SOC 2 10/4/33 · HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2.
Capability-claim honesty pass, part 2 (28 July 2026): 27 advertised claims across the three published packages were verified against the code and withdrawn — arm64 images, offline installation tarballs, monthly NVD feed bundles, an air-gapped install script, a feed-import CLI command with no implementation, and the Community Edition's absolute "works without internet access" claim. Also matrix-neutral.