<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">

  <url>
    <loc>https://www.nsauditor.com/ai/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pro/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/pro-exploit-first-card.png</video:thumbnail_loc>
      <video:title>NSAuditor AI Pro &#8212; exploit-first vulnerability triage (product overview)</video:title>
      <video:description>The Pro overview covers exploit-first triage with CISA KEV and FIRST EPSS &#8212; free public feeds you download and point Pro at, failing closed when stale &#8212; CVE matching from detected service versions with fully offline support, the suppression workflow where findings are emitted unverified and you adjudicate, AI analysis on your own API keys, and risk-ranked reports built for one-click print to PDF.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Pro.mp4</video:content_loc>
      <video:duration>373</video:duration>
      <video:publication_date>2026-08-31T20:34:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/</loc>
    <lastmod>2026-09-16</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/nsauditor-ai-enterprise-1-0-video-poster.jpg</video:thumbnail_loc>
      <video:title>Network Security Audit Evidence, Not Screenshots — NSAuditor AI Enterprise 1.0</video:title>
      <video:description>NSAuditor AI Enterprise walk-through, regenerated for EE 1.0.0 (2026-09-16): the Friday before the audit &#8212; a folder of console screenshots, a spreadsheet of unsigned exceptions, the same bucket mapped by hand to three frameworks, and an auditor asking how anyone knows a screenshot is real and taken during the audit period &#8212; then the same week after one read-only infrastructure scan mapped to eight compliance frameworks: SOC 2, HIPAA Security Rule &#167;164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as security-of-processing infrastructure substrate only, never GDPR compliance, and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, never a CMMC certification. Six problems, before and after: evidence rebuilt once per framework, a posture scanner that copies your infrastructure map into a vendor's account, hundreds of findings with no way to tell exploited from theoretical (exploit-first triage joins CISA KEV and FIRST EPSS from stores you supply), unsigned risk acceptances, evidence with no trustworthy clock, and an integration built on a vendor whose output shape keeps moving. What 1.0 means: eight integration surfaces are frozen and semver-governed from 1.0.0, so a breaking change is a major version with a migration note &#8212; a stability promise, not a certification. 56 plugins in total (27 Community + 29 Enterprise, the Enterprise set being 28 cloud auditors across AWS, Azure and Google Cloud plus one network Zero Trust posture check); read-only credentials enforced in code; nothing goes to Nsasoft, with sixteen outbound paths enumerated in the product's own egress register &#8212; nine on by default, four carrying scan content, of which the NVD CVE lookup is on by default and yours to turn off and the other three go only to destinations you configure. Why an auditor should believe it: approvals checked against your own approver registry for approvers whose registry entry carries key material, a chain-of-custody envelope that re-hashes every artifact it names at verification, and a .tsr sidecar from the Time-Stamp Authority you name (opt-in via NSAUDITOR_TSA_URL; nothing is timestamped unless you name one) &#8212; all checkable with standard openssl, without trusting the vendor or the customer. It issues no certification and reaches no compliance verdict; the scope of an assessment stays your assertion. Offline use: distribution is restricted, and the container image is amd64-only; the bundle itself installs on native arm64 hosts too. Requires Community Edition 0.2.49 or newer. 8 min 43 s.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Enterprise.mp4</video:content_loc>
      <video:duration>523</video:duration>
      <video:publication_date>2026-09-16T18:30:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/technical-specifications/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pricing/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/getting-started/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/soc2/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/hipaa/</loc>
    <lastmod>2026-09-16</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/nsauditor-ai-enterprise-1-0-video-poster.jpg</video:thumbnail_loc>
      <video:title>Network Security Audit Evidence, Not Screenshots — NSAuditor AI Enterprise 1.0</video:title>
      <video:description>NSAuditor AI Enterprise walk-through, regenerated for EE 1.0.0 (2026-09-16): the Friday before the audit &#8212; a folder of console screenshots, a spreadsheet of unsigned exceptions, the same bucket mapped by hand to three frameworks, and an auditor asking how anyone knows a screenshot is real and taken during the audit period &#8212; then the same week after one read-only infrastructure scan mapped to eight compliance frameworks: SOC 2, HIPAA Security Rule &#167;164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as security-of-processing infrastructure substrate only, never GDPR compliance, and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, never a CMMC certification. Six problems, before and after: evidence rebuilt once per framework, a posture scanner that copies your infrastructure map into a vendor's account, hundreds of findings with no way to tell exploited from theoretical (exploit-first triage joins CISA KEV and FIRST EPSS from stores you supply), unsigned risk acceptances, evidence with no trustworthy clock, and an integration built on a vendor whose output shape keeps moving. What 1.0 means: eight integration surfaces are frozen and semver-governed from 1.0.0, so a breaking change is a major version with a migration note &#8212; a stability promise, not a certification. 56 plugins in total (27 Community + 29 Enterprise, the Enterprise set being 28 cloud auditors across AWS, Azure and Google Cloud plus one network Zero Trust posture check); read-only credentials enforced in code; nothing goes to Nsasoft, with sixteen outbound paths enumerated in the product's own egress register &#8212; nine on by default, four carrying scan content, of which the NVD CVE lookup is on by default and yours to turn off and the other three go only to destinations you configure. Why an auditor should believe it: approvals checked against your own approver registry for approvers whose registry entry carries key material, a chain-of-custody envelope that re-hashes every artifact it names at verification, and a .tsr sidecar from the Time-Stamp Authority you name (opt-in via NSAUDITOR_TSA_URL; nothing is timestamped unless you name one) &#8212; all checkable with standard openssl, without trusting the vendor or the customer. It issues no certification and reaches no compliance verdict; the scope of an assessment stays your assertion. Offline use: distribution is restricted, and the container image is amd64-only; the bundle itself installs on native arm64 hosts too. Requires Community Edition 0.2.49 or newer. 8 min 43 s.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Enterprise.mp4</video:content_loc>
      <video:duration>523</video:duration>
      <video:publication_date>2026-09-16T18:30:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/nist/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/pci/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/iso/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/cis/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/gdpr/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>
  <url>
      <loc>https://www.nsauditor.com/ai/docs/800-171/</loc>
      <lastmod>2026-09-09</lastmod>
      <changefreq>weekly</changefreq>
      <priority>0.95</priority>
    </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/grc/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/sample-scan/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.85</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/feeds/ai.xml</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/NSAuditor-AI-Enterprise-Brochure.pdf</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>

</urlset>
