<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">

  <url>
    <loc>https://www.nsauditor.com/ai/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pro/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/pro-exploit-first-card.png</video:thumbnail_loc>
      <video:title>NSAuditor AI Pro &#8212; exploit-first vulnerability triage (product overview)</video:title>
      <video:description>The Pro overview covers exploit-first triage with CISA KEV and FIRST EPSS &#8212; free public feeds you download and point Pro at, failing closed when stale &#8212; CVE matching from detected service versions with fully offline support, the suppression workflow where findings are emitted unverified and you adjudicate, AI analysis on your own API keys, and risk-ranked reports built for one-click print to PDF.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Pro.mp4</video:content_loc>
      <video:duration>373</video:duration>
      <video:publication_date>2026-08-31T20:34:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/soc2-hipaa-pci-iso-cis-gdpr-nist-csf2-sp800-171.jpeg</video:thumbnail_loc>
      <video:title>NSAuditor AI Pro &amp; Enterprise &#8212; Full Product Overview: One Scan, Eight Compliance Frameworks, And An Evidence Pack You Can Sign</video:title>
      <video:description>Full product overview recorded on the NSAuditor AI Enterprise 0.40.0 release. NSAuditor AI is a security and compliance-evidence platform that runs on your own infrastructure, scans network hosts and AWS, Azure and GCP accounts agentless with read-only credentials enforced in the product's own code, and produces pre-audit evidence packs mapped to eight frameworks &#8212; SOC 2, HIPAA Security Rule 164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as security-of-processing infrastructure substrate, never GDPR compliance, and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, never a CMMC certification &#8212; each with a SHA-256 chain of custody and an explicit out-of-scope column carrying a reason per control. No customer data is collected, transmitted, or stored by us. The 0.40.0 headline is the eighth framework: NIST SP 800-171 Rev 2 is mapped at SP 800-171A determination-statement level &#8212; all 110 Rev 2 requirements enumerated with no declared subset, and 69 of 172 determination statements across the 51 mapped requirements &#8212; because a C3PAO scores objectives, not requirements; the engine emits no MET or NOT MET determination and no SPRS score. Evidence-pack authorship shipped at 0.38.0: compliance sign-pack signs one framework's chain-of-custody envelope with an operator-held Ed25519 key at an approval station, so the scanning fleet stays keyless by design and a compromised scanner cannot mint authorship; compliance verify-pack establishes authorship from that signature and then recomputes every artifact hash the envelope enumerates against the files on disk, because a verifier that checked only the signature would authenticate artifact claims nothing had ever verified. A verified pack signature covers one framework's envelope and the artifacts that envelope enumerates, relative to your own key custody &#8212; not the output directory, not the pack as a whole, and never a vendor attestation. Two trust anchors are offered and the tool names the one it used: --registry checks the approver's revocation and validity as at the moment of signing, and --public-key discloses in its own output that those checks did not run. The exact signed bytes ship beside the signature, so an auditor reproduces the check with shasum -a 256 and openssl pkeyutl -verify and no NSAuditor code in the path, and exit codes distinguish three states rather than two &#8212; verified, a violation, and the run could not measure. Also covered: exploit-first triage joining a local CISA KEV catalog and a local FIRST EPSS scores file at scan time so a KEV-listed MEDIUM outranks an unexploited CRITICAL, air-gapped operation with offline CVE matching from data you download and carry across yourself, and the published register of enumerated outbound paths, each with its trigger, its default and its off switch. Exploit intelligence is Pro tier and both catalogs are operator-supplied. Enterprise 0.40.x required Community Edition 0.2.45 or newer (current release: EE 0.46.0, requiring Community Edition 0.2.49 or newer).</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor-AI-Enterprise-0-40.mp4</video:content_loc>
      <video:duration>507</video:duration>
      <video:publication_date>2026-08-21T02:54:41+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/soc2-hipaa-pci-iso-cis-gdpr-nist-csf2-sp800-171.jpeg</video:thumbnail_loc>
      <video:title>NSAuditor AI Enterprise — Verifiable Beats Trusted: One Scan, Eight Compliance Frameworks Across AWS, Azure &amp; GCP</video:title>
      <video:description>NSAuditor AI Enterprise walk-through, regenerated on EE 0.46.0 (2026-09-09): one infrastructure scan mapped to eight compliance frameworks &#8212; SOC 2, HIPAA Security Rule &#167;164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as security-of-processing infrastructure substrate only, never GDPR compliance, and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, never a CMMC certification. It opens on the screenshot problem &#8212; an auditor asking how anyone knows a screenshot is real and taken during the audit period &#8212; then walks the five problems one scan solves: evidence rebuilt once per framework, a posture scanner that copies your infrastructure map into a vendor's account, hundreds of findings with no way to tell exploited from theoretical, unsigned risk acceptances, and evidence with no trustworthy clock. 56 plugins in total (27 Community + 29 Enterprise, the Enterprise set being 28 cloud auditors across AWS, Azure and Google Cloud plus one network Zero Trust posture check); read-only credentials enforced in code; nothing goes to Nsasoft, with sixteen outbound paths enumerated in the product's own egress register. Why an auditor should believe it: approvals checked against your own approver registry for approvers whose registry entry carries key material, a chain-of-custody envelope that re-hashes every artifact it names at verification, and a .tsr sidecar from the Time-Stamp Authority you name (opt-in via NSAUDITOR_TSA_URL; nothing is timestamped unless you name one) &#8212; all checkable with standard openssl, without trusting the vendor or the customer. Exploit-first triage joins CISA KEV and FIRST EPSS from stores you supply. It issues no certification and reaches no compliance verdict; the scope of an assessment stays your assertion. Requires Community Edition 0.2.49 or newer. 8 min 06 s.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/NSAuditor_AI_Enterprise.mp4</video:content_loc>
      <video:duration>486</video:duration>
      <video:publication_date>2026-09-09T22:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/unified-compliance-soc2-hipaa-poster.jpg</video:thumbnail_loc>
      <video:title>Unified Compliance: SOC 2 + HIPAA in One Scan — NSAuditor AI Enterprise</video:title>
      <video:description>Short-form explainer of the NSAuditor AI Enterprise dual-framework workflow. HIPAA Security Rule §164.312 Technical Safeguards is supported alongside SOC 2, and a single scan produces both evidence packs. Zero BAA required — the scanner reads infrastructure configuration, never ePHI.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/Unified_Compliance.mp4</video:content_loc>
      <video:publication_date>2026-05-21T14:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/enterprise/technical-specifications/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/pricing/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/getting-started/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/soc2/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/hipaa/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
    <video:video>
      <video:thumbnail_loc>https://www.nsauditor.com/ai/images/unified-compliance-soc2-hipaa-poster.jpg</video:thumbnail_loc>
      <video:title>Unified Compliance: SOC 2 + HIPAA in One Scan — NSAuditor AI Enterprise</video:title>
      <video:description>NSAuditor AI Enterprise HIPAA explainer — Security Rule §164.312 Technical Safeguards supported alongside SOC 2, in a dual-framework one-scan workflow. Zero BAA architecture: the scanner reads infrastructure configuration, never ePHI.</video:description>
      <video:content_loc>https://www.nsauditor.com/ai/videos/Unified_Compliance.mp4</video:content_loc>
      <video:publication_date>2026-05-21T14:00:00+00:00</video:publication_date>
      <video:family_friendly>yes</video:family_friendly>
      <video:live>no</video:live>
    </video:video>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/nist/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/pci/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/iso/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/cis/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/gdpr/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>
  <url>
      <loc>https://www.nsauditor.com/ai/docs/800-171/</loc>
      <lastmod>2026-09-09</lastmod>
      <changefreq>weekly</changefreq>
      <priority>0.95</priority>
    </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/grc/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.95</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/sample-scan/</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.85</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/feeds/ai.xml</loc>
    <lastmod>2026-09-09</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
  </url>

  <url>
    <loc>https://www.nsauditor.com/ai/docs/NSAuditor-AI-Enterprise-Brochure.pdf</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>

</urlset>
