AI-Powered Network Security Audits Without Data Exposure.
NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and your security data never leaves your environment.
With 55 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 7 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, and GDPR Article 32.
Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.
One scan. Technical security assessment. Seven compliance frameworks. Verifiable evidence. Zero data exfiltration.
An open-core scanner with risk-scored findings, threat intelligence, and hepta-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.
Risk-Scored Prioritization
Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.
Findings are mapped to MITRE ATT&CK techniques with kill-chain context, so you can show your CISO what an attacker would actually do — not just CVE noise.
A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.
NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for seven frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, and GDPR Article 32 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.
Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full hepta-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).
Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.
EE 0.39.0 — every cloud provider now declares what it does not evaluate
Enterprise Edition 0.39.0, published 19 August 2026 alongside Community Edition 0.2.44 and the agent-skill package 0.2.42 — the 97th consecutive trio. A scanner that reports only what it found leaves the reader to guess whether silence means “clean” or “never looked”. NSAuditor answers that with deferredScope, a declaration of the surfaces a plugin does not examine — and until this release, all nine of those declarations sat on AWS plugins while the seven GCP and Azure plugins declared nothing. AWS disclosing is precisely what made the others’ silence read as completeness. Seven new declarations close that asymmetry, across plugins 1021, 1022, 1024, 1025, 1220, 1221 and 1222 — between 8 and 12 boundaries each, ordered by materiality because Community Edition abridges the declaration to 420 characters in its scan badge, so the boundaries that invalidate a cross-cutting conclusion lead and per-resource depth trails.
The precision matters more than the count. Every boundary was verified against the implementing code rather than a keyword search, and that changed four of them — because the absence of a word is a hypothesis about vocabulary, not a capability boundary. serviceTag appears nowhere in the fleet, yet plugin 1221 handles the Internet and AzureCloud service tags with their own severity calibration; publishing that as “deferred” would have denied a capability that ships. Three more were corrected the same way before shipping. An overstated boundary is an underclaim, which is the expensive direction, because nothing ever complains about it. Two of the seven boundary texts were promoted out of places no report reader could reach — one from a code comment, one from a data field the summariser never reads.
What this release does not change: a deferredScope declaration routes to zero controls by design — re-measured across 49 declaration-by-framework combinations at zero control violations, beside a live negative control that correctly routed to three SOC 2 controls. It is a statement of what was never assessed, never a finding and never a gap. Plugin catalog unchanged at 28; all seven coverage matrices unchanged. The Community Edition floor is unchanged at 0.2.43 or newer. Community Edition 0.2.44 rides this trio for a separate reason worth naming: the model-facing description that tells an AI assistant how to read these results was being truncated by at least one MCP client, and a truncated description that keeps its routing mechanics while losing its honesty rules fails silently. It now leads with the reading rules, so anything a client clips is mechanics — and mechanics failing is loud.
Full release history: the Enterprise page and the package changelogs on npm.