AI-Powered Network Security Audits Without Data Exposure.
NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and your security data never leaves your environment.
With 56 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 8 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2.
Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.
One scan. Technical security assessment. Eight compliance frameworks. Verifiable evidence. Zero data exfiltration.
An open-core scanner with risk-scored findings, threat intelligence, and octa-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.
Risk-Scored Prioritization
Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.
Findings are mapped to MITRE ATT&CK techniques with kill-chain context, so you can show your CISO what an attacker would actually do — not just CVE noise.
A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.
NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for eight frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.
Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full octa-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).
Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.
Sovereign and government estates, audited as themselves
Enterprise Edition 0.42.0 is the current release, published alongside Community Edition 0.2.49 and the agent-skill package 0.2.47. AWS auditing is now partition-correct across GovCloud, the China regions, the intelligence-community partitions and the European Sovereign Cloud — resource names, severity ladders and region handling all follow the partition your estate actually runs in, so a finding in GovCloud lands with the same weight it would in commercial.
Azure sovereign clouds are now selected explicitly and fail closed. Point the scanner at Azure Government or China with AZURE_ENVIRONMENT, and every scan states in its own summary which estate it addressed — so the subject of the report is visible on the face of the report, and an unrecognised selection asks for the variable that fixes it instead of guessing.
The release also adds an on-demand software bill of materials in CycloneDX or SPDX, generated over the package you actually install rather than a maintainer’s working tree, and a published FIPS posture statement that names the FIPS-approved algorithms the product employs and states plainly that the product is not itself a FIPS 140-validated cryptographic module. 29 Enterprise auditors, 56 plugins overall, all eight frameworks; the coverage matrices are unchanged because this release deepens correctness on controls already covered. The Community Edition floor rises to 0.2.49 or newer — install Community Edition first. See the Enterprise plugin catalog →
Full release history: the Enterprise page and the package changelogs on npm.