AI-Driven Network Defense

AI-Powered Network Security Audits Without Data Exposure.

NSAuditor AI is an open-core, AI-powered network security audit platform that runs agentless, read-only, and entirely on your infrastructure. Nothing is installed across your estate, credentials are read-only by design, and every outbound path is opt-in and off by default.

With 56 plugins for networks and AWS, Azure, and GCP, one scan delivers risk-scored security findings, exploit-first prioritization using CISA KEV and FIRST EPSS, MITRE ATT&CK mapping, and auditor-ready evidence mapped to 8 compliance frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2.

Evidence packs include SHA-256 chain-of-custody manifests and opt-in RFC 3161 trusted timestamps. Operator-held Ed25519 signatures can be verified offline. NSAuditor AI supports air-gapped environments and reports evidence gaps explicitly—never claiming an unassessed surface is secure.

One scan. Technical security assessment. Eight compliance frameworks. Verifiable evidence. Zero data exfiltration.

56 Scanner Plugins 8 Frameworks SOC 2 · HIPAA · NIST · PCI DSS · ISO 27001 · CIS v8 · GDPR Art. 32 · NIST SP 800-171 Zero Data Exfiltration MIT Open Core
nsauditor-ai — scan
$ nsauditor-ai scan --host 10.0.0.0/24 --plugins all --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171
Initializing AI core... [OK]
Scanning 254 hosts · 56 plugins (parallel: 10)…
Critical Vulnerability Found CVE-2024-3321
Mapping to MITRE ATT&CK · SOC 2 CC6.1 · HIPAA §164.312(a) · NIST CSF PR.AC-1 · PCI DSS Req 8.4.1 · ISO 27001 A.8.5 · CIS Safeguard 6.5
Initial Access
Lateral Movement
Engineered for precision

What NSAuditor AI ships

An open-core scanner with risk-scored findings, threat intelligence, and octa-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.

Risk-Scored Prioritization

Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.

Learn more →

Octa-Framework Compliance

One scan produces eight auditor-ready evidence packs: SOC 2 (AICPA TSC 2017), HIPAA §164.312 Technical Safeguards, NIST CSF 2.0, PCI DSS v4.0.1 (sub-requirement-level for QSA RoC; every citation derived from the standard itself), ISO/IEC 27001:2022 (per-Annex-A-code with Statement of Applicability discipline), and CIS Critical Security Controls v8 (per-Safeguard with the Implementation Group cumulative discipline — IG1 cyber-insurance baseline / IG2 / IG3; no-certification-body attestation via CSAT / CIS-CAT Pro), and GDPR Article 32 (Security of Processing — infrastructure substrate for Art. 32 only, not GDPR compliance; 4/5/2 across 11 sub-measure units), and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation — all 110 Rev 2 requirements enumerated; 2/49/59). SHA-256 chain-of-custody sidecars you can verify offline, and opt-in outbound push to Vanta, Drata or Secureframe. Zero BAA required.

View Enterprise compliance →
How it works

From your network to auditor-ready evidence

One local scan flows through risk scoring, threat mapping, and the compliance engine — ending in a hash-chained evidence pack your auditor can verify.

The fundamentals

What is a network security audit?

A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.

NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for eight frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.

Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full octa-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).

New to auditing? Read our step-by-step guide: How to Conduct a Network Security Audit — Checklist & Best Practices.

Three editions

Free, Pro, and Enterprise

Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.

Community
Free · MIT
27 Community plugins · forever free · no signup
  • Full scanner plugin set
  • AI analysis (your API keys)
  • CTEM watch mode
  • JSON · HTML · SARIF · CSV
  • MCP server for AI agents
npm install -g nsauditor-ai
Enterprise
$2k+/yr · 3 tiers
29 EE plugins — 28 cloud auditors · octa-framework compliance · air-gapped
  • 56 plugins (27 CE + 29 EE — 28 cloud auditors across AWS · GCP · Azure, plus a zero-trust posture check scored from a network-host scan)
  • Octa-framework compliance — one scan, eight evidence packs
  • SOC 2 (AICPA TSC 2017) — 10/4/37
  • HIPAA §164.312 — 7/3/45 · Zero BAA
  • NIST CSF 2.0 — 13/10/83 subcategories
  • PCI DSS v4.0.1 — 19/9/44 across 72 enumerated sub-requirements, identifiers derived from the standard
  • ISO/IEC 27001:2022 — 17/14/62 Annex A controls
  • CIS Controls v8 — 17/23/113 Safeguards
  • GDPR Article 32 — 4/5/2 across 11 sub-measure units
  • NIST SP 800-171 Rev 2 — 2/49/59 across 110 requirements
  • Zero Data Exfiltration · Air-gapped operation
  • Vanta / Drata / Secureframe GRC connectors (opt-in)
Enterprise tiers →
Latest release

Every PCI DSS citation, derived from the standard itself

Enterprise Edition 0.46.0 is the current release, published 9 September 2026 alongside Community Edition 0.2.53 and the agent-skill package 0.2.51. A citation your QSA reads is one the standard backs. Every PCI DSS v4.0.1 sub-requirement identifier, every Customized Approach eligibility answer and every objective the product cites is now read from the PCI SSC publication into a derived, self-validating artifact that the mapping file points at — one source, no second copy to drift. Eligibility comes from where the standard states it, each requirement’s own Customized Approach Objective cell, and every one of the 28 mapped controls is Customized-eligible.

Guarded so it stays that way. Each Customized Approach Objective says, per control, whether it is the requirement cell’s own wording or NSAuditor’s paraphrase, and the report labels it from that flag; a build guard fails on any cited identifier the standard does not contain, and every objective flagged verbatim is checked against the document in both directions. The PCI DSS matrix is enumerated at 19 covered / 9 partial / 44 out of scope across 72 sub-requirements — covered and partial unchanged, no control changed status — and the other seven matrices are unchanged.

29 Enterprise auditors, 56 plugins overall, all eight frameworks. The Community Edition floor is unchanged at 0.2.49 or newer — install Community Edition first. Previously — EE 0.45.0 (7 September 2026): evidence that says only what it can prove — report time anchored by RFC 3161 trusted timestamping, opt-in via NSAUDITOR_TSA_URL, from the Time-Stamp Authority you choose rather than the scanner’s host, a scope attestation that states in the artifact that this scanner does not measure its own clock, and the NTP clock-attestation probe WITHDRAWN as of EE 0.45.0. Previously — EE 0.44.0 (4 September 2026): the scan you can send — nsauditor-ai report --from <run> --format executive turned a finished run into a self-contained, print-ready HTML report that states what it could not read, and an S3 audit-trail gap began to mean both trails are missing. See the Enterprise plugin catalog →

Full release history: the Enterprise page and the package changelogs on npm.