AI-Powered Network Security Audits Without Data Exposure.
NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and nothing goes to Nsasoft. Beyond the scan’s own traffic (your targets and local segment, DNS, your own cloud’s APIs) and NIST’s public NVD API for CVE matching (off with NSAUDITOR_OFFLINE_ONLY=1 and a local NVD store), every outbound path is opt-in and off by default.
With 56 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 8 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2.
Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.
One scan. Technical security assessment. Eight compliance frameworks. Verifiable evidence. Zero data exfiltration.
An open-core scanner with risk-scored findings, threat intelligence, and octa-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.
Risk-Scored Prioritization
Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.
Findings are mapped to MITRE ATT&CK techniques with kill-chain context, so you can show your CISO what an attacker would actually do — not just CVE noise.
One scan produces eight auditor-ready evidence packs: SOC 2 (AICPA TSC 2017), HIPAA §164.312 Technical Safeguards, NIST CSF 2.0, PCI DSS v4.0.1 (sub-requirement-level for QSA RoC; every citation derived from the standard itself), ISO/IEC 27001:2022 (per-Annex-A-code with Statement of Applicability discipline), and CIS Critical Security Controls v8 (per-Safeguard with the Implementation Group cumulative discipline — IG1 cyber-insurance baseline / IG2 / IG3; no-certification-body attestation via CSAT / CIS-CAT Pro), and GDPR Article 32 (Security of Processing — infrastructure substrate for Art. 32 only, not GDPR compliance; 4/5/2 across 11 sub-measure units), and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation — all 110 Rev 2 requirements enumerated; 2/49/59). SHA-256 chain-of-custody sidecars you can verify offline, and opt-in outbound push to Vanta, Drata or Secureframe. Zero BAA required.
A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.
NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for eight frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.
Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full octa-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).
Watch: how do you actually run a network security audit on a cloud account in 2026?
A seven-minute how-to in six steps: scope it before you scan, use read-only credentials, check the scan actually audited, read the findings the way your auditor will, hand over what you did not examine too, and let the auditor verify it with standard shasum and openssl. English captions. Also on YouTube.
Three editions
Free, Pro, and Enterprise
Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.
EE 1.2.0 — a finding on a port, region or producer a scan did not measure is not counted as fixed — two measured limits stated
The most expensive word in a security report is “resolved”. This release refuses to call a finding fixed when the second scan never looked — and states, in the release itself, the two places it still cannot be sure. A finding on a port, region or producer a scan did not measure is not counted as fixed, and with SLA tracking on the control it failed is held FAILED. Two measured limits in this release: after a CVE lookup that failed, the prior CVE rows are not counted as fixed, but the controls they failed are not held FAILED and can read PASS; and when two compared scans ran different --plugins sets, a row an analysis agent or the CVE mapper derived from a plugin only one of them requested can read RESOLVED or NEW. When the later scan left the plugin out, the row also counts as closed in MTTR and its control can read PASS. Keep --plugins identical between compared scans. In the Pro and Enterprise delta report — what is new, what is resolved and what changed severity since the last scan — when the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE, with the reason on the row, instead of calling it resolved — among the reasons: a host that was not scanned; a finding that carries no producer identity; a plugin that did not run, errored or timed out; an analysis agent that did not run; an Enterprise package that failed to load; an evidence gap, including a CVE lookup that failed; a narrower scope; a port whose check could not complete; a TCP port the port scanner saw open that stopped answering between the two scans, or a UDP port the other scan did not record as closed or answering; a producer whose identity basis changed across an upgrade; and a CVE the vulnerability data stopped attributing while the same program and version still answer. A finding that could not be compared is not a finding that was fixed. Measured, not promised: on a real router run compared with a twin that drops its 22 UDP rows, the previous release reported all 22 resolved and this release reports all 22 not comparable. And when NVD stopped matching five CVEs to a dnsmasq 2.78 that was still answering, the previous delta called all five resolved and the compliance pack counted them closed with an MTTR of about a day; this release files them NOT COMPARABLE — the vulnerability data changed, not the estate. Enterprise Edition 1.2.0 is the current release, published 2026-10-04 alongside Community Edition 0.2.56 and the agent-skill package 0.2.54. Coverage: all eight coverage matrices unchanged since EE 1.1.0.
29 Enterprise auditors, 56 plugins overall, all eight frameworks. The Community Edition floor is 0.2.56 or newer — install Community Edition first. Upgrade both packages together: on the previous Community release, Enterprise’s plugins still load and license --plugins reports Enterprise (loaded), but the scan skips the CVE, analysis-agent and compliance stages without a word; this Community release names a failed Enterprise load on stderr. See the Enterprise plugin catalog →
Full release history: the Enterprise page and the package changelogs on npm.