AI-Driven Network Defense

AI-Powered Network Security Audits Without Data Exposure.

NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and every outbound path is opt-in and off by default.

With 56 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 8 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2.

Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.

One scan. Technical security assessment. Eight compliance frameworks. Verifiable evidence. Zero data exfiltration.

56 Scanner Plugins 8 Frameworks SOC 2 · HIPAA · NIST · PCI DSS · ISO 27001 · CIS v8 · GDPR Art. 32 · NIST SP 800-171 Zero Data Exfiltration MIT Open Core
nsauditor-ai — scan
$ nsauditor-ai scan --host 10.0.0.0/24 --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171
Initializing AI core... [OK]
Scanning 254 hosts · 56 plugins (parallel: 10)…
Critical Vulnerability Found CVE-2024-3321
Mapping to MITRE ATT&CK · SOC 2 CC6.1 · HIPAA §164.312(a) · NIST CSF PR.AC-1 · PCI DSS Req 8.4.1 · ISO 27001 A.8.5 · CIS Safeguard 6.5
Initial Access
Lateral Movement
Engineered for precision

What NSAuditor AI ships

An open-core scanner with risk-scored findings, threat intelligence, and octa-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.

Risk-Scored Prioritization

Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.

Learn more →

Octa-Framework Compliance

One scan produces eight auditor-ready evidence packs: SOC 2 (AICPA TSC 2017), HIPAA §164.312 Technical Safeguards, NIST CSF 2.0, PCI DSS v4.0.1 (sub-requirement-level for QSA RoC; Defined-vs-Customized Approach per Appendix E), ISO/IEC 27001:2022 (per-Annex-A-code with Statement of Applicability discipline), and CIS Critical Security Controls v8 (per-Safeguard with the Implementation Group cumulative discipline — IG1 cyber-insurance baseline / IG2 / IG3; no-certification-body attestation via CSAT / CIS-CAT Pro), and GDPR Article 32 (Security of Processing — infrastructure substrate for Art. 32 only, not GDPR compliance; 4/5/2 across 11 sub-measure units), and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation — all 110 Rev 2 requirements enumerated; 2/49/59). SHA-256 chain-of-custody sidecars you can verify offline, and opt-in outbound push to Vanta, Drata or Secureframe. Zero BAA required.

View Enterprise compliance →
How it works

From your network to auditor-ready evidence

One local scan flows through risk scoring, threat mapping, and the compliance engine — ending in a hash-chained evidence pack your auditor can verify.

The fundamentals

What is a network security audit?

A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.

NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for eight frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.

Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full octa-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).

New to auditing? Read our step-by-step guide: How to Conduct a Network Security Audit — Checklist & Best Practices.

Three editions

Free, Pro, and Enterprise

Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.

Community
Free · MIT
27 Community plugins · forever free · no signup
  • Full scanner plugin set
  • AI analysis (your API keys)
  • CTEM watch mode
  • JSON · HTML · SARIF · CSV
  • MCP server for AI agents
npm install -g nsauditor-ai
Enterprise
$2k+/yr · 3 tiers
29 EE plugins — 28 cloud auditors · octa-framework compliance · air-gapped
  • 56 plugins (27 CE + 29 EE — 28 cloud auditors across AWS · GCP · Azure, plus a zero-trust posture check scored from a network-host scan)
  • Octa-framework compliance — one scan, eight evidence packs
  • SOC 2 (AICPA TSC 2017) — 10/4/37
  • HIPAA §164.312 — 7/3/45 · Zero BAA
  • NIST CSF 2.0 — 13/10/83 subcategories
  • PCI DSS v4.0.1 — 19/9/39 sub-requirements (MVP-67)
  • ISO/IEC 27001:2022 — 17/14/62 Annex A controls
  • CIS Controls v8 — 17/23/113 Safeguards
  • GDPR Article 32 — 4/5/2 across 11 sub-measure units
  • NIST SP 800-171 Rev 2 — 2/49/59 across 110 requirements
  • Zero Data Exfiltration · Air-gapped operation
  • Vanta / Drata / Secureframe GRC connectors (opt-in)
Enterprise tiers →
Latest release

Evidence that says only what it can prove

Enterprise Edition 0.45.0 is the current release, published 7 September 2026 alongside Community Edition 0.2.52 and the agent-skill package 0.2.50. Every field on an evidence pack is backed by the code that produced it. Report time is anchored by RFC 3161 trusted timestamping, opt-in via NSAUDITOR_TSA_URL: each artifact’s .tsr sidecar takes its time from the Time-Stamp Authority you choose rather than from the scanner’s host, so a wrong host clock cannot corrupt a token, and an assessor reads host skew from the token itself — with a signature behind it.

The artifact names its own limits. The scope attestation’s ntp block is frozen at six keys with constant values and a note stating that this scanner does not measure its own clock, on an unchanged nsauditor.scope-attestation/v1 schema — nothing an auditor’s tooling reads has moved, and every sidecar already taken stays verifiable. Consistent with that standard, the NTP clock-attestation probe is WITHDRAWN as of EE 0.45.0 — it attested the scanner’s own host clock, never your estate — and the words that described it are guarded against reappearing on any published surface. The agent skill carries the same discipline into AI assistants, and the change ships as a minor version so it is findable in the version series an auditor reads.

29 Enterprise auditors, 56 plugins overall, all eight frameworks; every coverage matrix is unchanged this cycle. The Community Edition floor is unchanged at 0.2.49 or newer — install Community Edition first. Previously — EE 0.44.0 (4 September 2026): the scan you can send — nsauditor-ai report --from <run> --format executive turned a finished run into a self-contained, print-ready HTML report that states what it could not read, and an S3 audit-trail gap began to mean both trails are missing. See the Enterprise plugin catalog →

Full release history: the Enterprise page and the package changelogs on npm.