<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">

  <url>
    <loc>https://www.nsauditor.com/ai/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pro/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/soc2-hipaa-nist-pci-iso-cis-gdpr.png</video:thumbnail_loc>
      <video:title>NSAuditor AI Pro &amp; Enterprise 0.38.0 &#8212; Full Product Overview: One Scan, Seven Compliance Frameworks, And An Evidence Pack You Can Sign</video:title>
      <video:description>Full product overview recorded on the NSAuditor AI Enterprise 0.38.0 release. NSAuditor AI is a security and compliance-evidence platform that runs on your own infrastructure, scans network hosts and AWS, Azure and GCP accounts agentless with read-only credentials enforced in the product's own code, and produces pre-audit evidence packs mapped to seven frameworks &#8212; SOC 2, HIPAA Security Rule 164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32 as security-of-processing infrastructure substrate, never GDPR compliance &#8212; each with a SHA-256 chain of custody and an explicit out-of-scope column carrying a reason per control. No customer data is collected, transmitted, or stored by us. The 0.38.0 headline is evidence-pack authorship: compliance sign-pack signs one framework's chain-of-custody envelope with an operator-held Ed25519 key at an approval station, so the scanning fleet stays keyless by design and a compromised scanner cannot mint authorship; compliance verify-pack establishes authorship from that signature and then recomputes every artifact hash the envelope enumerates against the files on disk, because a verifier that checked only the signature would authenticate artifact claims nothing had ever verified. A verified pack signature covers one framework's envelope and the artifacts that envelope enumerates, relative to your own key custody &#8212; not the output directory, not the pack as a whole, and never a vendor attestation. Two trust anchors are offered and the tool names the one it used: --registry checks the approver's revocation and validity as at the moment of signing, and --public-key discloses in its own output that those checks did not run. The exact signed bytes ship beside the signature, so an auditor reproduces the check with shasum -a 256 and openssl pkeyutl -verify and no NSAuditor code in the path, and exit codes distinguish three states rather than two &#8212; verified, a violation, and the run could not measure. Also covered: exploit-first triage joining a local CISA KEV catalog and a local FIRST EPSS scores file at scan time so a KEV-listed MEDIUM outranks an unexploited CRITICAL, air-gapped operation with offline CVE matching from data you download and carry across yourself, and the published register of enumerated outbound paths, each with its trigger, its default and its off switch. Exploit intelligence is Pro tier and both catalogs are operator-supplied. Enterprise 0.38.0 requires Community Edition 0.2.43 or newer.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Enterprise_0.38.mp4</video:content_loc>
      <video:duration>655</video:duration>
      <video:publication_date>2026-08-18T15:21:43+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/soc2-hipaa-nist-pci-iso-cis-gdpr.png</video:thumbnail_loc>
      <video:title>NSAuditor AI Enterprise — Extended Walk-Through: One Scan, Seven Compliance Frameworks Across AWS, Azure &amp; GCP</video:title>
      <video:description>Overview of NSAuditor AI Enterprise, the local-first, zero-data-exfiltration AI security auditor for AWS, Azure, and GCP. One scan generates seven framework-mapped evidence packs in parallel, each with SHA-256 chain-of-custody sidecars — SOC 2, HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, and the newest framework GDPR Article 32 (Security of Processing) — the Article 32 infrastructure substrate only, NOT GDPR compliance, with four-factor proportionality and the Art. 83(4) lower fine tier. Covers the 28 Enterprise plugins — 27 cloud auditors plus a Zero Trust posture assessment scored from a network-host scan — with multi-region fan-out, honest coverage matrices with explicit out-of-scope declarations, the published egress register of 17 enumerated outbound paths, air-gapped operation, and the MCP server for AI agents.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Enterprise.mp4</video:content_loc>
      <video:publication_date>2026-06-12T14:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/unified-compliance-soc2-hipaa-poster.jpg</video:thumbnail_loc>
      <video:title>Unified Compliance: SOC 2 + HIPAA in One Scan — NSAuditor AI Enterprise</video:title>
      <video:description>Short-form explainer of the NSAuditor AI Enterprise dual-framework workflow. HIPAA Security Rule §164.312 Technical Safeguards is supported alongside SOC 2, and a single scan produces both evidence packs. Zero BAA required — the scanner reads infrastructure configuration, never ePHI.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/Unified_Compliance.mp4</video:content_loc>
      <video:publication_date>2026-05-21T14:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/technical-specifications/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pricing/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/getting-started/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/soc2/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/hipaa/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/unified-compliance-soc2-hipaa-poster.jpg</video:thumbnail_loc>
      <video:title>Unified Compliance: SOC 2 + HIPAA in One Scan — NSAuditor AI Enterprise</video:title>
      <video:description>NSAuditor AI Enterprise HIPAA explainer — Security Rule §164.312 Technical Safeguards supported alongside SOC 2, in a dual-framework one-scan workflow. Zero BAA architecture: the scanner reads infrastructure configuration, never ePHI.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/Unified_Compliance.mp4</video:content_loc>
      <video:publication_date>2026-05-21T14:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/nist/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/pci/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/iso/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/cis/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/gdpr/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/grc/</loc>
    <lastmod>2026-08-17</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/sample-scan/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.85</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/feeds/ai.xml</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/NSAuditor-AI-Enterprise-Brochure.pdf</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>

</urlset>
