Audit-ready compliance evidence from one read-only scan — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2, mapped from a single pass across AWS, Azure and GCP. 56 plugins, built on an open-source core. Runs entirely on your infrastructure — zero data exfiltration by architecture.
The cloud-audit + compliance engine shown above is NSAuditor AI Enterprise · Community Edition is free forever, MIT licensed
Runs entirely on your machine. No cloud. No telemetry. License validation is offline. We can't see your data because we never touch it.
Findings are risk-scored and ranked so you fix what matters first. Suppress accepted-risk or false-positive findings with the operator workflow — your triage decisions persist across scans.
OpenAI, Claude, or Ollama (fully local). Compliance reports, remediation guidance, risk prioritization. Your API keys, your data.
27 CE plugins: Ports, SSH, HTTP, TLS, DNS, SNMP, SMB, RPC, mDNS, UPnP, and more. 29 EE plugins, of which 28 are cloud auditors: AWS S3, GCP, Azure, IAM Deep Auditor, CloudTrail, API Gateway, DynamoDB, KMS, Lambda, Secrets+SSM, CodePipeline, IAM Decrypt-Path, S3 Lifecycle, AWS Backup, RDS, SES, VPC/PrivateLink, EC2 SG, ElastiCache, Inspector2/GuardDuty, plus dedicated Azure Storage / NSG perimeter / Key Vault deep auditors, and more. The 29th, Zero Trust Assessment, is not a cloud auditor — it scores zero-trust posture from a network-host scan and calls no cloud API.
SOC 2 (AICPA TSC 2017), HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32 (Security of Processing), and NIST SP 800-171 Rev 2 — all from one scan. Sub-requirement-level mapping for QSA RoC workflow. Customized Approach eligibility read from each requirement's own objective cell, identifiers derived from the standard. CHD Scope operator-attested. ISO 27001 Statement of Applicability discipline. CIS Implementation Group cumulative discipline (IG1 cyber-insurance baseline). GDPR Article 32 is an infrastructure substrate for Art. 32 only (4 covered + 5 partial + 2 OOS across 11 sub-measure units) — NOT GDPR compliance. Auditor-ready evidence packs with SHA-256 chain-of-custody. Zero BAA required.
The MCP server ships free in the Community Edition — drive NSAuditor from Claude Desktop, Claude Code, Cursor, or any MCP-aware agent. Add it to your claude_desktop_config.json (npx nsauditor-ai-mcp), then install the optional agent skill so the assistant knows NSAuditor's tools, schemas, and audit workflows — in Claude Desktop: Skills → Create skill → Upload a skill (upload SKILL.md). Then just ask: "audit my AWS account."
Every compliance product cites standards; EE 0.46.0 reads its PCI DSS v4.0.1 citations from the PCI SSC publication rather than from a summary of it. Sub-requirement identifiers, Customized Approach eligibility and the objective column are derived into a self-validating artifact that the mapping file points at — one source, no second copy to drift. Eligibility is read from where the standard states it, each requirement’s own Customized Approach Objective cell, and every one of the 28 mapped controls is Customized-eligible. Each objective says, per control, whether it is the requirement cell’s own wording or NSAuditor’s paraphrase, and the report labels it from that flag. A build guard fails on any cited identifier the standard does not contain, and every objective flagged verbatim is checked against the document in both directions — so a citation your QSA reads is one the standard backs. PCI DSS matrix enumerated at 19 covered / 9 partial / 44 out of scope across 72 sub-requirements (covered and partial unchanged, no control changed status); the other seven matrices unchanged; 29 Enterprise auditors (28 cloud auditors + one Zero Trust posture check), 56 plugins overall; floor unchanged at CE ≥ 0.2.49.
Every field on an evidence pack is backed by the code that produced it. Report time is anchored by RFC 3161 trusted timestamping, opt-in via NSAUDITOR_TSA_URL: each artifact’s .tsr sidecar takes its time from the Time-Stamp Authority you choose rather than from the scanner’s host, so a wrong host clock cannot corrupt a token and an assessor reads host skew from the token itself — with a signature behind it. The artifact names its own limits: the scope attestation’s ntp block is frozen at six keys with constant values and a note stating that this scanner does not measure its own clock, on an unchanged nsauditor.scope-attestation/v1 schema, so nothing an auditor’s tooling reads has moved and every sidecar already taken stays verifiable. Consistent with that standard, the NTP clock-attestation probe is WITHDRAWN as of EE 0.45.0 — it attested the scanner’s own host clock, never your estate — and the words that described it are guarded against reappearing on any published surface. The agent skill carries the same discipline into AI assistants, and the change shipped as a minor version so it is findable in the version series an auditor reads. Prior: EE 0.45.0 (2026-09-07) kept all eight coverage matrices unchanged and paired with CE 0.2.52 + agent-skill 0.2.50; floor CE ≥ 0.2.49 (current floor: CE 0.2.49).
A scan ends with a directory of artifacts; an engagement ends with something a client reads. nsauditor-ai report --from <run> --format executive turns a finished scan into one self-contained, print-ready HTML report — and the HTML opens with no external network reference of any kind, so it survives an email attachment, an offline laptop and a locked-down reviewer’s browser. --brand puts your own name on the cover page. --format jira writes a Jira-importer CSV instead, so a findings list becomes a backlog — the field mapping is done inside Jira, and that is not a live-instance integration we have verified. Pro and Enterprise tiers.
A report that quietly skips a container reads exactly like a report that had nothing to skip. Every report now carries a container census: where finding-like records sit in a place the report does not read, that place is named and counted on the page. Silence is disclosed, never rendered as absence. Second: S3 server access logging being off is no longer reported as a gap where a CloudTrail data-event trail already covers that bucket. Coverage is judged per selector, and organisation trails and prefix-scoped selectors are refused rather than assumed — the credit is never granted on an assumption, so there are fewer false findings and the ones that remain are real. That release kept all eight coverage matrices unchanged and required CE 0.2.49 or newer (current floor: CE 0.2.49).
0.43.0 (2 September 2026): silence is not a pass — a cloud provider whose scanner did not run is reported as NOT audited with the reason rather than as clean, its findings absent rather than empty; an evidence gap states what was not evidenced instead of quoting a typed install command at an assessor; and the restricted air-gap carrier is pinned to the dependency versions its own test suite runs against and builds reproducibly, byte-identical across consecutive builds with the network interface down. 0.42.0 (27 August 2026): sovereign and government estates audited as themselves — partition-correct AWS auditing across GovCloud, China, the intelligence-community partitions and the European Sovereign Cloud, fail-closed Azure sovereign-cloud selection with every scan stamping the estate it addressed, an SBOM of the installed package and a published FIPS posture (FIPS-approved algorithms; not itself a FIPS 140-validated module). 0.41.0: the 29th plugin, the 1230 AWS DocumentDB Auditor, seven dimensions, every unreadable dimension a named evidence gap. 0.40.0: the eighth compliance framework — NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation, all 110 Rev 2 requirements enumerated at the SP 800-171A determination-statement level. 0.40.3: the evidence chain checks itself — on the opt-in RFC 3161 path every timestamp token is matched against the exact artifact digest it attests before anything is written, and the verification instruction on the report cover page runs exactly as printed. 0.38.0: an evidence pack can be signed — compliance sign-pack signs one framework’s chain-of-custody envelope with an operator-held Ed25519 key, and compliance verify-pack establishes authorship and then recomputes every artifact hash against disk, because checking the signature alone would authenticate a manifest whose artifact claims nothing had verified. 0.37.0: vulnerability data you can carry onto a network that cannot fetch it — feed bundle merges the NVD files you downloaded, feed import ingests them on the isolated host. 0.36.0: a report stopped taking an approval record at its word and began checking the signature against the approver’s registered key material, with verified and cryptoValid kept as separate questions so a revoked key makes them disagree. 0.35.0: suppression approvals got a command line — an accepted risk carries an owner, a rationale, a date and an expiry. Full changelog →
report --from <run> → self-contained executive HTML, or a Jira-importer CSV