AI-Powered Network Security Audits Without Data Exposure.
NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and every outbound path is opt-in and off by default.
With 56 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 8 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2.
Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.
One scan. Technical security assessment. Eight compliance frameworks. Verifiable evidence. Zero data exfiltration.
An open-core scanner with risk-scored findings, threat intelligence, and octa-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.
Risk-Scored Prioritization
Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.
Findings are mapped to MITRE ATT&CK techniques with kill-chain context, so you can show your CISO what an attacker would actually do — not just CVE noise.
A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.
NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for eight frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.
Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full octa-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).
Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.
Enterprise Edition 0.45.0 is the current release, published 7 September 2026 alongside Community Edition 0.2.52 and the agent-skill package 0.2.50. Every field on an evidence pack is backed by the code that produced it. Report time is anchored by RFC 3161 trusted timestamping, opt-in via NSAUDITOR_TSA_URL: each artifact’s .tsr sidecar takes its time from the Time-Stamp Authority you choose rather than from the scanner’s host, so a wrong host clock cannot corrupt a token, and an assessor reads host skew from the token itself — with a signature behind it.
The artifact names its own limits. The scope attestation’s ntp block is frozen at six keys with constant values and a note stating that this scanner does not measure its own clock, on an unchanged nsauditor.scope-attestation/v1 schema — nothing an auditor’s tooling reads has moved, and every sidecar already taken stays verifiable. Consistent with that standard, the NTP clock-attestation probe is WITHDRAWN as of EE 0.45.0 — it attested the scanner’s own host clock, never your estate — and the words that described it are guarded against reappearing on any published surface. The agent skill carries the same discipline into AI assistants, and the change ships as a minor version so it is findable in the version series an auditor reads.
29 Enterprise auditors, 56 plugins overall, all eight frameworks; every coverage matrix is unchanged this cycle. The Community Edition floor is unchanged at 0.2.49 or newer — install Community Edition first. Previously — EE 0.44.0 (4 September 2026): the scan you can send — nsauditor-ai report --from <run> --format executive turned a finished run into a self-contained, print-ready HTML report that states what it could not read, and an S3 audit-trail gap began to mean both trails are missing. See the Enterprise plugin catalog →
Full release history: the Enterprise page and the package changelogs on npm.