Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32, mapped from a single pass across AWS, Azure and GCP. 55 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 28 EE cloud plugins: AWS S3, GCP, Azure, Zero Trust, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 (Security of Processing) — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Defined-vs-Customized Approach discipline per Appendix E. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
The dependency-advisory check a release has to clear was auditing the maintainer's development tree while calling itself the production closure. Those are not the same software — a development tree carries every build tool, test harness and type definition a customer never receives. It now packs the tarball, installs it into an empty directory the way a customer does, and audits that.
The development tree carries 25 advisories, 8 of them high severity. What a customer actually installs carries 6, none of them high. Across 26 advisory packages the two lists share 5 — and not one shared advisory is high severity. Every high the old gate reported was development-only. It was not reporting a smaller number than the truth; it was reporting a different subject.
A gate that cannot reach an advisory database returns an empty result, and an empty result looks exactly like a clean one. That is the most dangerous shape an instrument can take, so it is no longer permitted: the run must prove a database actually answered before any verdict is reported at all. An unmeasurable run says so, rather than passing.
28 cloud plugins, 55 in total, seven frameworks — all unchanged. The SOC 2 matrix is now enumerated in full at 10 covered · 4 partial · 37 out of scope = 51, the complete AICPA TSC universe at this granularity. That is enumeration completeness, not a coverage change: no control changed status and no routing moved. The other six matrices are unchanged — HIPAA 7/3/45 · NIST CSF 13/10/83 · PCI DSS 19/9/39 · ISO 27001 17/14/62 · CIS v8 17/23/113 · GDPR Art. 32 4/5/2.
Checked against the packages as published, not the source tree: all 28 enterprise plugins load active, and a three-cloud scan produced a 76-file evidence pack per cloud. The SOC 2 Type II write-up also now states which of its mechanisms are reachable from a shipped entry point and which are built but not reachable — so the documentation describes what an operator can actually run.
0.32.9 (29 July 2026): internal engineering identifiers were stripped out of the evidence pack — 686 unexplained internal-marker occurrences → 0 across 105 files, with a positive control in the same run (3,572 benign matches still detected). And a cloud that could not be scanned stopped reading clean: every in-scope control of such a cloud now carries a fail-closed evidence gap. Two migration notes still apply when coming from 0.32.8 or earlier — the evidence-gap finding title changed, so suppression rules matching the old text stop matching (findings resurface rather than hide, but silently); and re-scan rather than re-process scans captured before 0.32.9. 0.32.8 (28 July 2026): capability-claim honesty pass, part 2 — 27 advertised claims across the three published packages were verified against the code and withdrawn: arm64 images, offline installation tarballs, monthly NVD feed bundles, an air-gapped install script, a feed-import CLI command with no implementation, and the Community Edition's absolute "works without internet access" claim. Both releases were matrix-neutral.