# NSAuditor — Nsasoft US LLC **Category:** cloud compliance scanner / cloud security audit tooling — agentless, read-only, runs inside the customer's own infrastructure. NSAuditor AI produces the auditor-ready evidence pack; it does not certify compliance and is not a GRC platform. It complements Vanta, Drata and Secureframe rather than replacing them (opt-in scan-time push to all three, early-access). > Nsasoft US LLC publishes two product lines: (1) NSAuditor AI — an open-core, AI-powered network security scanner with multi-cloud octa-framework compliance evidence (SOC 2 + HIPAA §164.312 + NIST Cybersecurity Framework 2.0 + PCI DSS v4.0.1 + ISO/IEC 27001:2022 + CIS Critical Security Controls v8 + GDPR Article 32 infrastructure substrate + NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation) and zero data exfiltration; and (2) the classic NSAuditor Network Security Auditor desktop suite for Windows — long-standing tools for network auditing, product-key recovery, password recovery, network inventory, and bandwidth monitoring. Established 2004 · Las Vegas, NV. The two product lines target different audiences. NSAuditor AI is the active development focus — it's the CLI / CI-CD / cloud-scanning / compliance-evidence platform with both a free MIT-licensed Community Edition and a commercial Enterprise Edition. The classic NSAuditor desktop suite is the Windows-installer product line that's been continuously sold since 2004 — trusted by thousands of system administrators for in-house network audits, product-key recovery off retired PCs, password recovery, software inventory, and traffic monitoring. Nsasoft is not a data processor under any regulation. All NSAuditor products run entirely on customer infrastructure or workstations. License validation is offline. Customer scan data, findings, reports, ePHI, Cardholder Data, and credentials never touch Nsasoft servers — Zero BAA required under HIPAA §160.103 (NSAuditor AI is not a Business Associate). CHD is operator-attested CDE-isolated for PCI DSS scope. ISO 27001 ISMS scope is operator-controlled. ## NSAuditor AI — open-core AI security scanner (active product line) NSAuditor AI is the AI-powered, multi-cloud, evidence-pack-generating security scanner. It runs a complete network security audit across AWS, GCP, Azure, and on-prem networks and produces auditor-ready evidence for eight compliance frameworks from a single scan. Core capabilities: offline CVE matching, MITRE ATT&CK technique annotation on network findings, an operator-driven suppression workflow, unlimited scan-history retention (CTEM), and an MCP server so AI agents can drive scans conversationally. 56 plugins total (27 CE + 29 EE, of which 28 are cloud auditors; the 29th scores zero-trust posture from a network-host scan). Current release: EE 0.44.0 (2026-09-04) — THE SCAN YOU CAN SEND: `nsauditor-ai report --from --format executive` turns a finished scan into a self-contained, print-ready HTML report that opens with no external network reference, with optional cover-page branding via `--brand`; `--format jira` writes a Jira-importer CSV, whose field mapping is completed inside Jira and is not verified against a live Jira instance. Pro and Enterprise tiers. The report also states what it could NOT read: a container census names and counts any place holding finding-like records that the report does not read, so silence is disclosed on the page rather than rendered as nothing. And an audit-trail gap now means BOTH trails are missing — S3 server access logging being off is no longer reported as a gap when a CloudTrail data-event trail already covers that bucket; coverage is judged per selector, and organization trails and prefix-scoped selectors are REFUSED rather than assumed, so there are fewer false findings and the ones that remain are real. Plugin count unchanged at 29 Enterprise (56 overall); all eight coverage matrices UNCHANGED; floor CE >= 0.2.49, unchanged. Prior release: EE 0.43.0 (2026-09-02) — a cloud the scanner could not reach is reported as NOT audited, with the reason, rather than as clean. Prior release: EE 0.42.0 (2026-08-27) — SOVEREIGN-ESTATE CORRECTNESS: partition-correct AWS auditing (GovCloud / China / ISO / European Sovereign Cloud) and fail-closed Azure sovereign-cloud selection with an estate stamp. Prior release: EE 0.41.0 (2026-08-26) — THE 29TH PLUGIN: AMAZON DOCUMENTDB GETS ITS OWN AUDITOR. Plugin 1230 AWS DocumentDB Auditor owns the docdb engine on the shared RDS control plane (storage encryption + KMS custody, TLS via the tls cluster parameter, audit logging + CloudWatch export, backup retention, deletion protection, replica/AZ topology, manual-snapshot public/cross-account restorability); the RDS auditor now engine-filters DocumentDB and Neptune off the shared plane and declares a Neptune estate unaudited. Plugin count 28 to 29; all eight coverage matrices unchanged. On the RFC 3161 trusted-timestamp path — opt-in via NSAUDITOR_TSA_URL, with no default authority and an outbound call only to the authority the operator names — every timestamp token is now matched against the exact artifact digest it attests before anything is written to disk, so a .tsr sidecar in an evidence pack provably belongs to the artifact beside it, and one framework's chain-of-custody envelope records that check, per artifact, as an explicit boolean an auditor can read. The verification instruction printed on the compliance report cover page is now one that runs exactly as printed. Tokens encoded in BER — which CMS permits and which openssl ts -verify accepts — are accepted rather than discarded, so evidence from commercial timestamp authorities (DigiCert, GlobalSign, Sectigo) lands in the pack; a refusal now requires two independent readers to fail. A run configured for timestamping that obtained fewer timestamps than it attempted now says so once, naming the reason, so "zero .tsr files" is no longer indistinguishable from "timestamping was never configured". signed: true attests protocol status and what the token says it attests, never cryptography; openssl ts -verify against the authority's chain remains the only thing that adjudicates a token, and it is the command the product prints. All eight coverage matrices are re-derived identical, and the plugin catalog grows to 29 Enterprise auditors (56 overall). Paired at 0.42.0: Community Edition 0.2.49 + agent-skill 0.2.47; the Community Edition floor was RAISED at 0.42.0 to >= 0.2.49 and is UNCHANGED at EE 0.44.0 (current trio: EE 0.44.0 + CE 0.2.51 + agent-skill 0.2.49). RFC 3161 timestamping is opt-in via NSAUDITOR_TSA_URL and is never a default. THE HEADLINE OF THE 0.40 LINE IS THE EIGHTH FRAMEWORK, introduced at EE 0.40.0 (2026-08-20): NIST SP 800-171 Rev 2 is the eighth compliance framework, scoped as evidence substrate for CMMC Level 2 preparation — all 110 Rev 2 requirements enumerated with no declared subset, mapping claimed at SP 800-171A determination-statement level (69 of 172 determination statements across the 51 mapped requirements), and each partial naming which shortfall it is. It informs the System Security Plan and the POA&M and never produces them; it emits no MET / NOT MET determination and no SPRS score, and CUI scope remains the operator's assertion. Prior: EE 0.39.0 (2026-08-19) — THE COVERAGE-HONESTY RELEASE: every cloud provider now declares what it does NOT evaluate. Seven new `deferredScope` declarations ship across the GCP and Azure fleet (plugins 1021, 1022, 1024, 1025, 1220, 1221, 1222), 8 to 12 static boundaries each, emitted at run() scope on the audited path including over an empty estate and never where a precondition failed. ⚠️ All nine prior declarations sat on AWS plugins, and AWS DISCLOSING IS EXACTLY WHAT MADE THE OTHERS’ SILENCE READ AS COMPLETENESS. Every boundary was verified against the implementing code rather than a keyword search, which corrected four of them — grep-absence is a hypothesis about vocabulary, not a capability boundary, and an overstated boundary is an underclaim, the direction nothing complains about. A declaration is not a finding and not a gap: it routes to ZERO controls by design. Plugin catalog UNCHANGED at 28; all seven coverage matrices UNCHANGED. EE 0.39.0 REQUIRES CE >= 0.2.43 — floor UNCHANGED this cycle. Paired with Community Edition 0.2.44 and the agent-skill package 0.2.42; the 97th consecutive trio. Prior — EE 0.38.0 (2026-08-17), the signing release: an evidence pack can now be signed, and the verifier checks more than the signature. `compliance sign-pack` signs ONE framework's chain-of-custody envelope with an operator-held Ed25519 key at an approval station, so the scan fleet stays keyless by design and a compromised scanner cannot mint authorship. `compliance verify-pack` establishes authorship from that signature and then recomputes every artifact hash the envelope enumerates against the files on disk — a verifier that checked only the signature would authenticate artifact claims nothing had ever verified and report that as a pass. ⚠️ THE SCOPE TRAVELS WITH THE CLAIM: a verified pack signature proves that the holder of a key asserted authorship of ONE FRAMEWORK'S ENVELOPE AND THE ARTIFACTS THAT ENVELOPE ENUMERATES — not the output directory and not the pack — and because the key is operator-held it is relative to the customer's own key custody and is NEVER A VENDOR ATTESTATION; verify-pack prints that boundary on every run, successful ones included. Two trust anchors and the tool names the one it used: `--registry` resolves the approver through the customer's identity registry and checks revocation and validity AS AT THE MOMENT OF SIGNING, so a key whose authority has since lapsed does not retroactively invalidate what it signed while valid; `--public-key` verifies against a supplied key and discloses in its own output that identity, revocation and validity checks did not run. The exact signed bytes ship beside the signature, so an auditor reproduces the check with `shasum -a 256` and `openssl pkeyutl -verify` and no NSAuditor code in the path. Exit codes distinguish THREE states, not two — verified, a violation, and the run could not measure — so an unsigned pack, an unreadable manifest or an unsupplied key is never reported as a failed verification. EE 0.38.0 REQUIRES CE >= 0.2.43 — a RAISED floor this cycle, because both new commands are routed from Community Edition. Paired with Community Edition 0.2.43 and the agent-skill package 0.2.41; the 96th consecutive trio. Prior — EE 0.37.0 (16 August 2026): vulnerability data can now be carried onto a network that has no way to fetch it. `nsauditor-ai feed bundle` merges the NVD feed files an operator downloaded on a connected host into one portable archive; `feed import` reads it into the offline CVE store on the far side and names why it skipped records — withdrawn CVEs and entries with no CPE data are expected, and are not data loss. Optional `--kev` / `--epss` carry the operator's OWN CISA KEV and FIRST EPSS downloads inside the same archive, validated on the connected host where a bad file can still be replaced — no exploit data ships with this product. Each carried file records a SHA-256 that import verifies, so a file altered in transit is detected; the archive is integrity-checked, not authenticated, and import treats every field it reads as untrusted input. Air-gapped delivery now ships as a dependency-complete bundle with an install script and checksums — RESTRICTED distribution; the install script is verified on native aarch64 as well as amd64, so an arm64 enclave is covered. Only the published CONTAINER IMAGE is amd64 — a different delivery vehicle. EE 0.37.0 REQUIRES CE >= 0.2.42 — a RAISED floor this cycle, because the new feed commands are routed from Community Edition and an older CE would build an incomplete archive without saying so. Paired with Community Edition 0.2.42 and the agent-skill package 0.2.40; the 95th consecutive trio. Prior — EE 0.36.0 (13 August 2026), the verification release. A compliance report now cryptographically verifies each suppression signature it renders for an approver whose registry entry carries key material, and the verdict names the exact signature bytes it checked. A registry entry may carry the approver's public key beside its fingerprint, and the two must agree or the registry is refused at load. The verdict has two axes and they can disagree: `verified` asks whether a suppression should stand, while `cryptoValid` asks whether the bytes came from that key. They diverge on a key revoked after it signed, which is how signing after revocation becomes a cryptographic finding for an approver whose registry entry carries key material. ⚠️ A missing verdict means NOT CHECKED and never FAILED: a suppression whose approver entry carries no key material is rendered as signed and not checked by this report, and registries in the field are fingerprint-only today. An identity-phase engine fault now fails that framework's report loudly rather than rendering a degraded section that blames the operator. The plugin catalog is unchanged at 28 enterprise plugins and all seven coverage matrices are unchanged. EE 0.36.0 requires CE >= 0.2.40, because the approval commands live in Community Edition and forward to Enterprise. Prior: EE 0.35.0 (12 August 2026) — the suppression-approval workflow got its entry point: four CLI commands (compliance suppress, review, renew and keygen), with keygen creating an Ed25519 approval keypair whose public half is the key material a registry entry can carry. At that release no surface verified a produced signature. - [NSAuditor AI — Home / overview](https://www.nsauditor.com/ai/): What it is, how it works, terminal demo, three editions - [NSAuditor AI — Pro](https://www.nsauditor.com/ai/pro/): Pro tier features — offline CVE matching, MITRE ATT&CK technique annotation, risk scoring, exploit intelligence (CISA KEV + FIRST EPSS joined onto CVE matches; operator-populated stores, no feed data ships — the page carries the full setup commands), finding suppression, parallel analysis agents, and sendable reports — `report --from --format executive` writes a self-contained, print-ready HTML report, `--format jira` a Jira-importer CSV ($39/mo annual, $49/mo monthly) - [NSAuditor AI — Enterprise](https://www.nsauditor.com/ai/enterprise/): Enterprise capabilities + three tiers (Base $2k/yr, Growth $5k/yr, Scale $10k+/yr). 29 EE plugins. Octa-framework compliance. Sendable executive reports. Air-gapped operation - [NSAuditor AI — Pricing](https://www.nsauditor.com/ai/pricing/): Community / Pro / Enterprise comparison and FAQ - [Documentation hub](https://www.nsauditor.com/ai/docs/): Quick start, architecture, plugin reference, per-framework guides, MCP integration, plugin SDK - [SOC 2 compliance guide](https://www.nsauditor.com/ai/docs/soc2/): AICPA TSC 2017 mapping — 10 covered + 4 partial + 37 OOS - [HIPAA §164.312 Technical Safeguards guide](https://www.nsauditor.com/ai/docs/hipaa/): 7 covered + 3 partial + 45 OOS. Zero BAA architecture - [NIST Cybersecurity Framework 2.0 guide](https://www.nsauditor.com/ai/docs/nist/): 13 covered + 10 partial + 83 OOS across 106 of 107 Subcategories - [PCI DSS v4.0.1 guide](https://www.nsauditor.com/ai/docs/pci/): 19 covered + 9 partial + 39 OOS across 67 of ~250 sub-requirements (MVP-67) - [ISO/IEC 27001:2022 guide](https://www.nsauditor.com/ai/docs/iso/): 17 covered + 14 partial + 62 OOS across 93 Annex A controls. SoA discipline - [CIS Critical Security Controls v8 guide](https://www.nsauditor.com/ai/docs/cis/): 17 covered + 23 partial + 113 OOS across 153 Safeguards / 18 Controls. IG1/IG2/IG3 cumulative - [GDPR Article 32 guide](https://www.nsauditor.com/ai/docs/gdpr/): 4 covered + 5 partial + 2 OOS across 11 Art. 32 sub-measures. Infrastructure substrate ONLY — not GDPR compliance - [Getting started guide](https://www.nsauditor.com/ai/docs/getting-started/): Linear new-customer onboarding — purchase email to first audit report: install, activate license, configure cloud credentials, run a first audit, scope with `--aws-region`, set up the Pro exploit-intelligence stores (CISA KEV + FIRST EPSS download commands + the NSAUDITOR_EXPLOIT_KEV_STORE / NSAUDITOR_EXPLOIT_EPSS_STORE environment variables), and drive it from Claude Desktop via MCP - [Sample scan output (synthetic, no signup)](https://www.nsauditor.com/ai/docs/sample-scan/): End-to-end walk-through with synthetic Acme Corp findings - [NSAuditor AI — full LLM context (llms.txt)](https://www.nsauditor.com/ai/llms.txt): Deep technical details, plugin inventory, framework coverage matrices, version history - [NSAuditor AI — sitemap](https://www.nsauditor.com/ai/sitemap.xml): Structured URL list for the /ai/ subdirectory - [GitHub repository (CE, MIT)](https://github.com/nsasoft/nsauditor-ai): Open-source Community Edition source, plugin SDK, releases - [npm package (CE)](https://www.npmjs.com/package/nsauditor-ai): `npm install -g nsauditor-ai` ## Classic NSAuditor desktop suite — Windows tools (long-standing product line) The original Windows-installer product line that's been continuously sold since 2004. Network auditing, product-key recovery, password recovery, network inventory, and bandwidth monitoring. Single-user, multi-user, corporate, and academic licensing. - [All desktop downloads](https://www.nsauditor.com/downloads/): Trial downloads for the full desktop product line - [Network Security Auditor](https://www.nsauditor.com/network_security/network_security_auditor.html): The classic Nsauditor Network Security Auditor — the flagship Windows network security audit tool, with 45+ utilities for network scanning, auditing, monitoring, and vulnerability detection - [Network Security Software overview](https://www.nsauditor.com/network-security-software.html): Desktop network-security product family index - [Product Key Recovery suite](https://www.nsauditor.com/product-key-recovery-software.html): Recover Windows / Office / Adobe / game product keys from local or backup-image sources. Includes Product Key Explorer, Office / Adobe / Game variants, Backup Key Recovery - [Password Recovery suite](https://www.nsauditor.com/password_recovery_software.html): Recover stored Windows / browser / IM / email / FTP / dial-up passwords from local accounts. Includes Spotie, SpotIM, SpotFTP, Outlook / Chrome / GTalk / Paltalk variants, Remote Password Recovery - [Network Inventory](https://www.nsauditor.com/network_inventory_software.html): Hardware + software inventory across Windows networks. Software-inventory variant available separately - [Network Monitoring (NBMonitor)](https://www.nsauditor.com/network-monitoring-software.html): Real-time bandwidth and connection monitoring per process - [Network Sleuth](https://www.nsauditor.com/network_sleuth.html): Network search / file-finder utility - [BlueAuditor — Bluetooth network scanner](https://www.nsauditor.com/bluetooth_network_scanner.html): Bluetooth device discovery and security assessment - [Domain Name Search](https://www.nsauditor.com/domain-name-search-software.html): Bulk domain availability lookup - [Template Parser](https://www.nsauditor.com/template-parser.html): Pattern-based text-parsing utility - [Free network tools](https://www.nsauditor.com/network-tools.html): Standalone free utilities — Whois, Finger, Trace Route, DNS Resolver, ARP Cache Monitor, Port Scanner, SNMP MIB Browser, TCP/UDP Client-Server, Port Forwarding, Network Hotfix Scanner, Network Enumerator, Traffic Generator, DHCP Explorer, Share Alarm, and more - [Press releases / news](https://www.nsauditor.com/news/press_releases/): Product announcements - [Awards](https://www.nsauditor.com/awards/): Editor's Choice, 5-star ratings, and other recognition over the years - [Testimonials](https://www.nsauditor.com/testimonials/): Customer feedback - [Customers](https://www.nsauditor.com/customers/): Companies and institutions using NSAuditor ## Localized desktop-suite pages The classic desktop product line ships with localized landing pages in French, German, Spanish, Italian, and Russian. See [products.html](https://www.nsauditor.com/products.html) for the canonical English product index — localized variants are linked from each product page where applicable. ## Ordering & licensing - [Order — standard](https://www.nsauditor.com/order.html): Direct purchase of single-user / multi-user desktop licenses - [Corporate orders](https://www.nsauditor.com/corporder.html): Corporate volume licensing - [Academic orders](https://www.nsauditor.com/academorder.html): Academic / education licensing - [Government orders](https://www.nsauditor.com/govorder.html): Government licensing - [Resellers](https://www.nsauditor.com/resellers.html): Reseller program (via ShareASale partner network) - [NSAuditor AI Pro / Enterprise purchase](https://www.nsauditor.com/ai/pricing/): Stripe-billed monthly / annual / enterprise tiers (separate from the desktop suite ordering page) ## Key facts (for AI summarization) - **Company:** Nsasoft US LLC, Las Vegas, NV — 732 S 6TH ST, STE R. Established 2004. https://www.nsasoft.us - **Two product lines:** NSAuditor AI (active, open-core, CLI / cloud / compliance) and the classic NSAuditor desktop suite (long-standing, Windows-installer, network + recovery + inventory tools) - **Privacy posture:** Zero Data Exfiltration by architecture across both product lines — for NSAuditor AI, stated since EE 0.33.0 as a positive register of 17 enumerated outbound paths rather than as an absence, because an absence gives a reviewer no list to check. Not a data processor. No DPA / BAA required. Local-only operation. License validation offline - **NSAuditor AI snapshot (4 September 2026):** Current release EE 0.44.0, paired with Community Edition 0.2.51 and agent-skill package 0.2.49 — a finished scan can now be turned into a report a consultant can send: `nsauditor-ai report --from --format executive` writes a self-contained, print-ready HTML report that opens with no external network reference, with optional cover-page branding via `--brand`, and `--format jira` writes a Jira-importer CSV whose field mapping is completed inside Jira and is not verified against a live Jira instance; both are Pro and Enterprise. The report states what it could NOT read — a container census names and counts any place holding finding-like records that the report does not read, so silence is disclosed on the page instead of rendered as nothing. And an audit-trail gap now means BOTH trails are missing: S3 server access logging being off is no longer reported as a gap when a CloudTrail data-event trail already covers that bucket, coverage is judged per selector, and organization trails and prefix-scoped selectors are refused rather than assumed — fewer false findings, and the ones that remain are real. The Community Edition floor is UNCHANGED at >= 0.2.49 and every coverage matrix is UNCHANGED this cycle. Prior release: EE 0.43.0, paired with Community Edition 0.2.50 and agent-skill package 0.2.48 — a cloud the scanner could not reach reports as NOT audited with the reason rather than as clean, evidence gaps state a cause instead of a typed command, and the offline carrier is pinned to the dependency versions its test suite runs against. Prior release: EE 0.42.0, paired with Community Edition 0.2.49 and agent-skill package 0.2.47 — partition-correct AWS auditing and fail-closed Azure sovereign-cloud selection. Prior release: EE 0.41.0, paired with Community Edition 0.2.48 and agent-skill package 0.2.46. The 29th Enterprise plugin — a dedicated Amazon DocumentDB auditor, plugin 1230 — owns the docdb engine on the shared AWS control plane, and the RDS auditor engine-filters DocumentDB and Neptune off that plane and declares a Neptune estate unaudited; all eight coverage matrices are unchanged. (EE 0.41.0 requires CE >= 0.2.45 — the floor is RAISED at 0.40.0, because framework-name validation lives in Community Edition). NIST SP 800-171 Rev 2 is the eighth compliance framework, scoped as evidence substrate for CMMC Level 2 preparation. All 110 Rev 2 requirements are enumerated with no declared subset, and mapping is claimed at SP 800-171A determination-statement level — 69 of 172 determination statements across the 51 mapped requirements, with each partial naming which of three shortfalls it is. Rev 2 is pinned deliberately, because CMMC assesses Rev 2 by rule. It is not a CMMC certification, emits no MET/NOT MET determination and no SPRS score: it supplies examine-method substrate that informs your System Security Plan and POA&M, and leaves the determination with your assessor. ⚠️ NIST SP 800-171 requirement ids collide exactly with PCI DSS sub-requirement ids — always write "NIST SP 800-171 3.5.1", never a bare 3.5.1. Every cloud plugin now declares the surfaces it does NOT evaluate — introduced in EE 0.39.0 (2026-08-19): seven new `deferredScope` declarations across the GCP and Azure fleet close an asymmetry in which only AWS disclosed its coverage boundaries — and AWS disclosing is exactly what made the others’ silence read as completeness. A declaration is not a finding and not a gap: it routes to zero controls by design. A compliance report cryptographically verifies each suppression signature it renders for an approver whose registry entry carries key material, and a missing verdict means not checked rather than failed. 56 plugins (27 CE + 29 EE; 28 of the 29 are cloud auditors). Eight shipping compliance frameworks (SOC 2 · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO/IEC 27001:2022 · CIS Controls v8 · GDPR Art. 32 substrate · NIST SP 800-171 Rev 2 substrate for CMMC Level 2 preparation) — one scan produces eight evidence packs. Three editions: Community (free, MIT) / Pro ($39/mo annual) / Enterprise ($2k+/yr). Multi-cloud coverage: AWS + GCP + Azure + on-prem networks. Per-account and per-region scan scoping; runs from the CLI, in CI/CD, or via the MCP server. - **Prior release: EE 0.35.0 · CE 0.2.40 · agent-skill 0.2.38 (published 2026-08-12 — the 93rd consecutive trio):** The suppression-approval workflow got its entry point: four CLI commands, compliance suppress, review, renew and keygen. keygen created an Ed25519 approval keypair whose public half is the key material a registry entry can carry, wrote the private half 0600 and printed an identity-registry member to paste, and refused to overwrite an existing signing key. suppress signed the approval it wrote when NSAUDITOR_SIGNING_KEY named a local key file, and a malformed key failed at the command and wrote nothing. renew warned that renewing a signed approval invalidates its signature, because the expiry and the renewal record live inside the signed payload. At that release no surface verified a produced signature, and EE 0.36.0 is the release whose reports check those bytes, for approvers whose registry entry carries key material. No new environment variables shipped, and the plugin count and all seven coverage matrices were unchanged. Prior: EE 0.34.0 (2026-08-10 — the 92nd consecutive trio) — exploit intelligence, Pro tier. Severity ranks how bad a vulnerability would be *if* exploited; it says nothing about whether anyone is exploiting it. Every finding carrying a CVE is now joined by CVE ID, at scan time, against a local CISA KEV catalog and a local FIRST EPSS scores file, and banded — and the band names assert only what their sources support. **KNOWN_EXPLOITED** is KEV membership, meaning exploitation observed at some time; it is deliberately not called ACTIVE, because KEV entries are never removed and the register cannot support a present-tense claim. **ELEVATED** is EPSS >= 0.10, around the 88th-90th percentile; it is deliberately not called PROBABLE, which in plain English reads as better than even odds. **BASELINE** asserts nothing beyond 'not elevated'; it is deliberately not called UNLIKELY, because a low EPSS is not evidence of safety. The queue is then ordered KEV → EPSS → risk score → severity, so **a KEV-listed MEDIUM outranks an unexploited CRITICAL**, and the justification travels with the finding — the flag, the score with its percentile, the matched CVE ids and the store's as-of date — so the ordering is always dateable. Banding keys on the absolute EPSS score and never the percentile, because a percentile is a property of the CVE population rather than of the finding. **Both stores fail closed when stale** — 14 days for KEV, 10 for EPSS — and a stale store withdraws a negative rather than asserting one, so an out-of-date catalog never reports 'not exploited'. **No feed data ships**: both stores are operator-populated via NSAUDITOR_EXPLOIT_KEV_STORE / NSAUDITOR_EXPLOIT_EPSS_STORE, and the join runs entirely on the operator's own machine. It enriches and does not detect — it runs downstream of CVE matching and does not widen what the scanner finds — and **riskScore is untouched**, with exploitPriority added as a new axis beside it. A documentation correction rides along: the risk score had been described as 'severity × exploitability × impact × exposure' while no exploitability input existed; it computes CVSS weighted by verification status with a 15% uplift for findings carrying an initial-access technique, and that is what the documentation now says. **All seven coverage matrices are UNCHANGED and the plugin count is UNCHANGED at 28 enterprise plugins** — 27 cloud auditors plus one zero-trust posture check scored from a network-host scan, 55 in total. **EE 0.36.0 requires CE >= 0.2.40.** Earlier: EE 0.33.1 (2026-08-07) — auditor-verifiable proof stated in all seven framework reports: RFC 3161 trusted timestamping is opt-in via NSAUDITOR_TSA_URL, with no default ever, verified against a real public Time-Stamp Authority on 2026-08-07 through the published binaries, with `Verification: OK` on the report, the scope attestation and the chain of custody and `Verification: FAILED` after a single appended byte. **Ed25519 suppression signing, which a report checks only for approvers whose registry entry carries key material, was not reachable at that release; EE 0.35.0 made it reachable, and EE 0.36.0 verifies a rendered signature against the key material a registry entry carries** — the SHA-256 chain-of-custody sidecars, which verify offline, carry evidence integrity wherever a report shows no verdict. Prior: EE 0.32.11 (2026-08-05) — the dependency-advisory release gate had been auditing the maintainer's development tree while describing itself as the production closure. It now packs the tarball, installs it into an empty directory the way a customer does, and audits that instead — and it refuses to report clean until it has proved an advisory database actually answered, because a run that could not reach one returns an empty result indistinguishable from a clean one. **The two measurements barely overlap.** The development tree carries 25 advisories, 8 of them high severity; the closure a customer installs carries 6, none high. Across 26 advisory packages the two lists share 5, and **not one shared advisory is high severity** — all eight highs were development-only. The old gate was not reporting a smaller number than the truth, it was reporting a different subject. Also in this release: the **SOC 2 matrix is now enumerated in full** at 10 covered + 4 partial + 37 out of scope = 51, the complete AICPA TSC universe at this granularity — **enumeration completeness, not a coverage change**, since no control changed status and no routing moved, and the other six matrices are unchanged; and the SOC 2 Type II documentation now states which of its mechanisms are reachable from a shipped entry point and which are built but not reachable. **Matrix-neutral and count-neutral** — 28 enterprise plugins (27 of them cloud auditors), 55 in total, seven frameworks, all unchanged. Verified against the published bytes rather than the source tree: all 28 enterprise plugins load active, and a three-cloud scan produced a 76-file evidence pack per cloud. Prior: EE 0.32.9 (2026-07-29) — two headline changes, both verifiable. (1) **Internal-provenance strip** — a compliance report is a document a customer hands their auditor, and ours carried internal engineering identifiers (roadmap ids, internal release stamps, the name of an internal audit review) in finding titles, the attestation cover page and the chain-of-custody record. Measured on a rebuilt three-cloud evidence pack: 686 unexplained internal-marker occurrences → 0 across 105 files, with a positive control in the same run (3,572 benign matches still detected) so the zero is a measurement rather than an absence of looking. (2) **A false-clean closure** — when a cloud plugin could not start (optional SDK absent, credentials unusable) it refused to report, and that refusal evaporated one layer up: the compliance report came out byte-identical to one where the scanner ran and found nothing, with ten controls reading PASS, no violation and no warning. The dangerous shape is ordinary: AWS and GCP scan for real, Azure's SDK is absent, and the combined pack reads as a clean three-cloud audit. Every in-scope control of a cloud that could not be scanned now carries a fail-closed evidence gap. Also: an archived scan re-processed by the new build warns instead of failing clean; four report surfaces that contradicted each other on trusted timestamping — which was still on the roadmap at that release, and became opt-in via `NSAUDITOR_TSA_URL` in EE 0.33.0 — now say the same verifiable thing; CE `--out ` no longer writes to the parent directory when the directory name contains a dot, the MCP `scan_cloud` summary handles both spellings of the evidence-gap prefix, and `validate` no longer misreports where plugins came from. New instrument: a pack scanner that fails closed when its own positive control is empty. **Matrix-neutral** — 28 enterprise plugins (27 cloud auditors) and all seven coverage matrices are identical to 0.32.8. Prior: EE 0.32.8 (2026-07-28) — capability-claim honesty pass, part 2, also matrix-neutral. - **Two migration notes, both introduced in EE 0.32.9, for any upgrade that crosses that release:** (1) the evidence-gap finding TITLE changed, so suppression rules matching the old text stop matching — the safe direction (findings resurface rather than hide) but a silent one; (2) re-scan rather than re-processing scans captured before 0.32.9 — the engine now warns on them. - **NSAuditor AI integrations:** OpenAI / Claude / Ollama (customer API keys). MCP server with 5 CE tools + 9 Pro tools. Vanta + Drata + Secureframe GRC connectors — scan-time push, opt-in, early-access single-workspace; live tenant validation in progress. A linux/amd64 container image (delivery vehicle, not per-scan isolation). No arm64 image is published. An offline installation bundle IS published for air-gapped operation — dependency-complete, with an install script and checksums, under RESTRICTED distribution and amd64 ONLY - **Desktop suite snapshot:** Network Security Auditor + Product Key Recovery family (Product Key Explorer, Office / Adobe / Game / Backup variants) + Password Recovery family (Spotie / SpotIM / SpotFTP / Remote Password Recovery / Outlook / Chrome / GTalk / Paltalk) + Network Inventory + NBMonitor (bandwidth) + Network Sleuth (file search) + BlueAuditor (Bluetooth) - **Compliance frameworks supported by NSAuditor AI Enterprise:** SOC 2 (AICPA TSC 2017) · HIPAA Security Rule §164.312 · NIST Cybersecurity Framework 2.0 · PCI DSS v4.0.1 · ISO/IEC 27001:2022 · CIS Critical Security Controls v8 · GDPR Article 32 (infrastructure substrate only, NOT GDPR compliance) · NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation) — octa-framework one-scan workflow: `nsauditor-ai scan --host aws --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171` - **Air-gapped operation:** a linux/amd64 container image or npm host install, offline ES256 license verification (no phone-home), and offline CVE matching under `NSAUDITOR_OFFLINE_ONLY=1` — for payment-processing CDE-isolation and ISO 27001 ISMS-scope-controlled environments, and as the technical evidence layer that feeds a federal-contractor DFARS / CMMC programme; nSAuditor's air-gapped operation is compatible with the FedRAMP / DFARS / CMMC threat model where SaaS data flow is prohibited. - **AWS Marketplace:** NSAuditor AI Enterprise Edition is listed on AWS Marketplace by Nsasoft US LLC; purchase is via Private Offer. Search "nsauditor" on AWS Marketplace. ## Contact - **Sales / Enterprise:** enterprise@nsasoft.us - **Support:** support@nsasoft.us - **License issues:** license@nsasoft.us - **General contact:** https://www.nsauditor.com/contact.html - **Press / partners:** https://www.shareasale.com/shareasale.cfm?merchantID=54299 - **Company:** Nsasoft US LLC, Las Vegas, NV — https://www.nsasoft.us - **Source code:** https://github.com/nsasoft/nsauditor-ai