# NSAuditor — Nsasoft US LLC **Category:** cloud compliance scanner / cloud security audit tooling — agentless, read-only, runs inside the customer's own infrastructure. NSAuditor AI produces the auditor-ready evidence pack; it does not certify compliance and is not a GRC platform. It complements Vanta, Drata and Secureframe rather than replacing them (opt-in scan-time push to all three, early-access). > Nsasoft US LLC publishes two product lines: (1) NSAuditor AI — an open-core, AI-powered network security scanner with multi-cloud hepta-framework compliance evidence (SOC 2 + HIPAA §164.312 + NIST Cybersecurity Framework 2.0 + PCI DSS v4.0.1 + ISO/IEC 27001:2022 + CIS Critical Security Controls v8 + GDPR Article 32 infrastructure substrate) and zero data exfiltration; and (2) the classic NSAuditor Network Security Auditor desktop suite for Windows — long-standing tools for network auditing, product-key recovery, password recovery, network inventory, and bandwidth monitoring. Established 2004 · Las Vegas, NV. The two product lines target different audiences. NSAuditor AI is the active development focus — it's the CLI / CI-CD / cloud-scanning / compliance-evidence platform with both a free MIT-licensed Community Edition and a commercial Enterprise Edition. The classic NSAuditor desktop suite is the Windows-installer product line that's been continuously sold since 2004 — trusted by thousands of system administrators for in-house network audits, product-key recovery off retired PCs, password recovery, software inventory, and traffic monitoring. Nsasoft is not a data processor under any regulation. All NSAuditor products run entirely on customer infrastructure or workstations. License validation is offline. Customer scan data, findings, reports, ePHI, Cardholder Data, and credentials never touch Nsasoft servers — Zero BAA required under HIPAA §160.103 (NSAuditor AI is not a Business Associate). CHD is operator-attested CDE-isolated for PCI DSS scope. ISO 27001 ISMS scope is operator-controlled. ## NSAuditor AI — open-core AI security scanner (active product line) NSAuditor AI is the AI-powered, multi-cloud, evidence-pack-generating security scanner. It runs a complete network security audit across AWS, GCP, Azure, and on-prem networks and produces auditor-ready evidence for seven compliance frameworks from a single scan. Core capabilities: offline CVE matching, MITRE ATT&CK technique annotation on network findings, an operator-driven suppression workflow, unlimited scan-history retention (CTEM), and an MCP server so AI agents can drive scans conversationally. 55 plugins total (27 CE + 28 EE, of which 27 are cloud auditors; the 28th scores zero-trust posture from a network-host scan). Current release: EE 0.34.0 (10 August 2026), paired with Community Edition 0.2.39 and agent-skill package 0.2.37 — the 92nd consecutive trio. It adds exploit intelligence to the Pro tier: findings that carry CVEs are joined by CVE ID, at scan time, against a local CISA Known Exploited Vulnerabilities catalog and a local FIRST EPSS scores file, banded KNOWN_EXPLOITED / ELEVATED / BASELINE, and the finding queue is ordered exploit-first — so a KEV-listed MEDIUM outranks an unexploited CRITICAL, with the flag, the score and its percentile, the matched CVE ids and the store's as-of date shown beside every promoted finding. Both catalogs are operator-supplied and the join runs locally; no feed data ships. It enriches the CVE matches the scanner already found and does not change what the scanner detects, and riskScore is untouched — exploitPriority is a new axis beside it. RFC 3161 trusted timestamping remains opt-in via NSAUDITOR_TSA_URL, with no default ever, and every compliance artifact then carries a .tsr sidecar an auditor verifies offline with stock openssl, against a Time-Stamp Authority the customer chooses, with none of our software in the path. EE 0.34.0 requires CE >= 0.2.39 — the floor was raised deliberately, because CE 0.2.39 fixes a port scanner that probed zero ports under a global install and an NVD cache that broke CVE lookup under MCP. Plugin count is unchanged at 28 EE / 55 total, and all seven framework coverage matrices are unchanged. - [NSAuditor AI — Home / overview](https://www.nsauditor.com/ai/): What it is, how it works, terminal demo, three editions - [NSAuditor AI — Pro](https://www.nsauditor.com/ai/pro/): Pro tier features — offline CVE matching, MITRE ATT&CK technique annotation, risk scoring, exploit intelligence (CISA KEV + FIRST EPSS joined onto CVE matches; operator-populated stores, no feed data ships — the page carries the full setup commands), finding suppression, parallel analysis agents ($39/mo annual, $49/mo monthly) - [NSAuditor AI — Enterprise](https://www.nsauditor.com/ai/enterprise/): Enterprise capabilities + three tiers (Base $2k/yr, Growth $5k/yr, Scale $10k+/yr). 28 EE plugins. Hepta-framework compliance. Air-gapped operation - [NSAuditor AI — Pricing](https://www.nsauditor.com/ai/pricing/): Community / Pro / Enterprise comparison and FAQ - [Documentation hub](https://www.nsauditor.com/ai/docs/): Quick start, architecture, plugin reference, per-framework guides, MCP integration, plugin SDK - [SOC 2 compliance guide](https://www.nsauditor.com/ai/docs/soc2/): AICPA TSC 2017 mapping — 10 covered + 4 partial + 37 OOS - [HIPAA §164.312 Technical Safeguards guide](https://www.nsauditor.com/ai/docs/hipaa/): 7 covered + 3 partial + 45 OOS. Zero BAA architecture - [NIST Cybersecurity Framework 2.0 guide](https://www.nsauditor.com/ai/docs/nist/): 13 covered + 10 partial + 83 OOS across 106 of 107 Subcategories - [PCI DSS v4.0.1 guide](https://www.nsauditor.com/ai/docs/pci/): 19 covered + 9 partial + 39 OOS across 67 of ~250 sub-requirements (MVP-67) - [ISO/IEC 27001:2022 guide](https://www.nsauditor.com/ai/docs/iso/): 17 covered + 14 partial + 62 OOS across 93 Annex A controls. SoA discipline - [CIS Critical Security Controls v8 guide](https://www.nsauditor.com/ai/docs/cis/): 17 covered + 23 partial + 113 OOS across 153 Safeguards / 18 Controls. IG1/IG2/IG3 cumulative - [GDPR Article 32 guide](https://www.nsauditor.com/ai/docs/gdpr/): 4 covered + 5 partial + 2 OOS across 11 Art. 32 sub-measures. Infrastructure substrate ONLY — not GDPR compliance - [Getting started guide](https://www.nsauditor.com/ai/docs/getting-started/): Linear new-customer onboarding — purchase email to first signed audit report: install, activate license, configure cloud credentials, run a first audit, scope with `--aws-region`, set up the Pro exploit-intelligence stores (CISA KEV + FIRST EPSS download commands + the NSAUDITOR_EXPLOIT_KEV_STORE / NSAUDITOR_EXPLOIT_EPSS_STORE environment variables), and drive it from Claude Desktop via MCP. Reflects EE 0.34.0 - [Sample scan output (synthetic, no signup)](https://www.nsauditor.com/ai/docs/sample-scan/): End-to-end walk-through with synthetic Acme Corp findings - [NSAuditor AI — full LLM context (llms.txt)](https://www.nsauditor.com/ai/llms.txt): Deep technical details, plugin inventory, framework coverage matrices, version history - [NSAuditor AI — sitemap](https://www.nsauditor.com/ai/sitemap.xml): Structured URL list for the /ai/ subdirectory - [GitHub repository (CE, MIT)](https://github.com/nsasoft/nsauditor-ai): Open-source Community Edition source, plugin SDK, releases - [npm package (CE)](https://www.npmjs.com/package/nsauditor-ai): `npm install -g nsauditor-ai` ## Classic NSAuditor desktop suite — Windows tools (long-standing product line) The original Windows-installer product line that's been continuously sold since 2004. Network auditing, product-key recovery, password recovery, network inventory, and bandwidth monitoring. Single-user, multi-user, corporate, and academic licensing. - [All desktop downloads](https://www.nsauditor.com/downloads/): Trial downloads for the full desktop product line - [Network Security Auditor](https://www.nsauditor.com/network_security/network_security_auditor.html): The classic Nsauditor Network Security Auditor — the flagship Windows network security audit tool, with 45+ utilities for network scanning, auditing, monitoring, and vulnerability detection - [Network Security Software overview](https://www.nsauditor.com/network-security-software.html): Desktop network-security product family index - [Product Key Recovery suite](https://www.nsauditor.com/product-key-recovery-software.html): Recover Windows / Office / Adobe / game product keys from local or backup-image sources. Includes Product Key Explorer, Office / Adobe / Game variants, Backup Key Recovery - [Password Recovery suite](https://www.nsauditor.com/password_recovery_software.html): Recover stored Windows / browser / IM / email / FTP / dial-up passwords from local accounts. Includes Spotie, SpotIM, SpotFTP, Outlook / Chrome / GTalk / Paltalk variants, Remote Password Recovery - [Network Inventory](https://www.nsauditor.com/network_inventory_software.html): Hardware + software inventory across Windows networks. Software-inventory variant available separately - [Network Monitoring (NBMonitor)](https://www.nsauditor.com/network-monitoring-software.html): Real-time bandwidth and connection monitoring per process - [Network Sleuth](https://www.nsauditor.com/network_sleuth.html): Network search / file-finder utility - [BlueAuditor — Bluetooth network scanner](https://www.nsauditor.com/bluetooth_network_scanner.html): Bluetooth device discovery and security assessment - [Domain Name Search](https://www.nsauditor.com/domain-name-search-software.html): Bulk domain availability lookup - [Template Parser](https://www.nsauditor.com/template-parser.html): Pattern-based text-parsing utility - [Free network tools](https://www.nsauditor.com/network-tools.html): Standalone free utilities — Whois, Finger, Trace Route, DNS Resolver, ARP Cache Monitor, Port Scanner, SNMP MIB Browser, TCP/UDP Client-Server, Port Forwarding, Network Hotfix Scanner, Network Enumerator, Traffic Generator, DHCP Explorer, Share Alarm, and more - [Press releases / news](https://www.nsauditor.com/news/press_releases/): Product announcements - [Awards](https://www.nsauditor.com/awards/): Editor's Choice, 5-star ratings, and other recognition over the years - [Testimonials](https://www.nsauditor.com/testimonials/): Customer feedback - [Customers](https://www.nsauditor.com/customers/): Companies and institutions using NSAuditor ## Localized desktop-suite pages The classic desktop product line ships with localized landing pages in French, German, Spanish, Italian, and Russian. See [products.html](https://www.nsauditor.com/products.html) for the canonical English product index — localized variants are linked from each product page where applicable. ## Ordering & licensing - [Order — standard](https://www.nsauditor.com/order.html): Direct purchase of single-user / multi-user desktop licenses - [Corporate orders](https://www.nsauditor.com/corporder.html): Corporate volume licensing - [Academic orders](https://www.nsauditor.com/academorder.html): Academic / education licensing - [Government orders](https://www.nsauditor.com/govorder.html): Government licensing - [Resellers](https://www.nsauditor.com/resellers.html): Reseller program (via ShareASale partner network) - [NSAuditor AI Pro / Enterprise purchase](https://www.nsauditor.com/ai/pricing/): Stripe-billed monthly / annual / enterprise tiers (separate from the desktop suite ordering page) ## Key facts (for AI summarization) - **Company:** Nsasoft US LLC, Las Vegas, NV — 732 S 6TH ST, STE R. Established 2004. https://www.nsasoft.us - **Two product lines:** NSAuditor AI (active, open-core, CLI / cloud / compliance) and the classic NSAuditor desktop suite (long-standing, Windows-installer, network + recovery + inventory tools) - **Privacy posture:** Zero Data Exfiltration by architecture across both product lines — for NSAuditor AI, stated since EE 0.33.0 as a positive register of 17 enumerated outbound paths rather than as an absence, because an absence gives a reviewer no list to check. Not a data processor. No DPA / BAA required. Local-only operation. License validation offline - **NSAuditor AI snapshot (August 2026):** Current release EE 0.34.0, paired with Community Edition 0.2.39 and agent-skill package 0.2.37 (EE 0.34.0 requires CE >= 0.2.39 — the floor was raised deliberately; CE 0.2.39 carries the port-scanner and NVD-cache fixes). 55 plugins (27 CE + 28 EE; 27 of the 28 are cloud auditors). Seven shipping compliance frameworks (SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO/IEC 27001:2022 · CIS Controls v8 · GDPR Art. 32 substrate) — one scan produces seven evidence packs. Three editions: Community (free, MIT) / Pro ($39/mo annual) / Enterprise ($2k+/yr). Multi-cloud coverage: AWS + GCP + Azure + on-prem networks. Per-account and per-region scan scoping; runs from the CLI, in CI/CD, or via the MCP server. - **Latest release (EE 0.34.0 · CE 0.2.39 · agent-skill 0.2.37, published 2026-08-10 — the 92nd consecutive trio):** Exploit intelligence, Pro tier. Severity ranks how bad a vulnerability would be *if* exploited; it says nothing about whether anyone is exploiting it. Every finding carrying a CVE is now joined by CVE ID, at scan time, against a local CISA KEV catalog and a local FIRST EPSS scores file, and banded — and the band names assert only what their sources support. **KNOWN_EXPLOITED** is KEV membership, meaning exploitation observed at some time; it is deliberately not called ACTIVE, because KEV entries are never removed and the register cannot support a present-tense claim. **ELEVATED** is EPSS >= 0.10, around the 88th-90th percentile; it is deliberately not called PROBABLE, which in plain English reads as better than even odds. **BASELINE** asserts nothing beyond 'not elevated'; it is deliberately not called UNLIKELY, because a low EPSS is not evidence of safety. The queue is then ordered KEV → EPSS → risk score → severity, so **a KEV-listed MEDIUM outranks an unexploited CRITICAL**, and the justification travels with the finding — the flag, the score with its percentile, the matched CVE ids and the store's as-of date — so the ordering is always dateable. Banding keys on the absolute EPSS score and never the percentile, because a percentile is a property of the CVE population rather than of the finding. **Both stores fail closed when stale** — 14 days for KEV, 10 for EPSS — and a stale store withdraws a negative rather than asserting one, so an out-of-date catalog never reports 'not exploited'. **No feed data ships**: both stores are operator-populated via NSAUDITOR_EXPLOIT_KEV_STORE / NSAUDITOR_EXPLOIT_EPSS_STORE, and the join runs entirely on the operator's own machine. It enriches and does not detect — it runs downstream of CVE matching and does not widen what the scanner finds — and **riskScore is untouched**, with exploitPriority added as a new axis beside it. A documentation correction rides along: the risk score had been described as 'severity × exploitability × impact × exposure' while no exploitability input existed; it computes CVSS weighted by verification status with a 15% uplift for findings carrying an initial-access technique, and that is what the documentation now says. **All seven coverage matrices are UNCHANGED and the plugin count is UNCHANGED at 28 enterprise plugins** — 27 cloud auditors plus one zero-trust posture check scored from a network-host scan, 55 in total. **EE 0.34.0 requires CE >= 0.2.39.** Prior: EE 0.33.1 (2026-08-07) — auditor-verifiable proof stated in all seven framework reports: RFC 3161 trusted timestamping is opt-in via NSAUDITOR_TSA_URL, with no default ever, verified against a real public Time-Stamp Authority on 2026-08-07 through the published binaries, with `Verification: OK` on the report, the scope attestation and the chain of custody and `Verification: FAILED` after a single appended byte. **Ed25519 suppression signing is still NOT reachable** — no shipped entry point signs a suppression record — so evidence integrity continues to rest on the SHA-256 chain-of-custody sidecars, which verify offline. Prior: EE 0.32.11 (2026-08-05) — the dependency-advisory release gate had been auditing the maintainer's development tree while describing itself as the production closure. It now packs the tarball, installs it into an empty directory the way a customer does, and audits that instead — and it refuses to report clean until it has proved an advisory database actually answered, because a run that could not reach one returns an empty result indistinguishable from a clean one. **The two measurements barely overlap.** The development tree carries 25 advisories, 8 of them high severity; the closure a customer installs carries 6, none high. Across 26 advisory packages the two lists share 5, and **not one shared advisory is high severity** — all eight highs were development-only. The old gate was not reporting a smaller number than the truth, it was reporting a different subject. Also in this release: the **SOC 2 matrix is now enumerated in full** at 10 covered + 4 partial + 37 out of scope = 51, the complete AICPA TSC universe at this granularity — **enumeration completeness, not a coverage change**, since no control changed status and no routing moved, and the other six matrices are unchanged; and the SOC 2 Type II documentation now states which of its mechanisms are reachable from a shipped entry point and which are built but not reachable. **Matrix-neutral and count-neutral** — 28 enterprise plugins (27 of them cloud auditors), 55 in total, seven frameworks, all unchanged. Verified against the published bytes rather than the source tree: all 28 enterprise plugins load active, and a three-cloud scan produced a 76-file evidence pack per cloud. Prior: EE 0.32.9 (2026-07-29) — two headline changes, both verifiable. (1) **Internal-provenance strip** — a compliance report is a document a customer hands their auditor, and ours carried internal engineering identifiers (roadmap ids, internal release stamps, the name of an internal audit review) in finding titles, the attestation cover page and the chain-of-custody record. Measured on a rebuilt three-cloud evidence pack: 686 unexplained internal-marker occurrences → 0 across 105 files, with a positive control in the same run (3,572 benign matches still detected) so the zero is a measurement rather than an absence of looking. (2) **A false-clean closure** — when a cloud plugin could not start (optional SDK absent, credentials unusable) it refused to report, and that refusal evaporated one layer up: the compliance report came out byte-identical to one where the scanner ran and found nothing, with ten controls reading PASS, no violation and no warning. The dangerous shape is ordinary: AWS and GCP scan for real, Azure's SDK is absent, and the combined pack reads as a clean three-cloud audit. Every in-scope control of a cloud that could not be scanned now carries a fail-closed evidence gap. Also: an archived scan re-processed by the new build warns instead of failing clean; four report surfaces that contradicted each other on trusted timestamping — which was still on the roadmap at that release, and became opt-in via `NSAUDITOR_TSA_URL` in EE 0.33.0 — now say the same verifiable thing; CE `--out