AI-Powered Network Security Audits Without Data Exposure.
NSAuditor AI is an open-core, AI-powered network security audit platform — the modern successor to our classic network security auditor for Windows. Run a full network security audit with risk-scored findings, exploit-first triage (CVE findings joined to the CISA KEV catalog and FIRST EPSS scores at scan time, so a known-exploited MEDIUM outranks an unexploited CRITICAL), MITRE ATT&CK mapping, and seven-framework compliance evidence — SOC 2 (AICPA TSC), HIPAA §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 — running entirely on your infrastructure. Your data never touches our servers.
An open-core scanner with risk-scored findings, threat intelligence, and hepta-framework compliance evidence — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Critical Security Controls v8, and GDPR Article 32 — built so your audit trail holds up to a CPA-firm review, a QSA RoC walkthrough, an ISO Stage 2 assessment, a CIS-CAT self-attestation, and a GDPR Article 32 review.
Risk-Scored Prioritization
Every finding carries a composite risk score — severity × exploitability × impact × exposure — so the queue sorts worst-first, and an operator suppression workflow tracks accepted-risk and false-positive dispositions with expiry.
Findings are mapped to MITRE ATT&CK techniques with kill-chain context, so you can show your CISO what an attacker would actually do — not just CVE noise.
A network security audit is a systematic review of your network — hosts, ports, services, configurations, and cloud accounts — to find vulnerabilities, misconfigurations, and compliance gaps before an attacker does.
NSAuditor AI runs that audit locally: it discovers live hosts and services, fingerprints them with safe, non-destructive probes, matches those versions against CVE data offline, maps each finding to MITRE ATT&CK, and generates auditor-ready evidence for seven frameworks — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, and GDPR Article 32 — from a single scan. Unlike SaaS scanners, every step runs on your own infrastructure, so a complete network security audit happens with zero data exfiltration.
Need cloud coverage? NSAuditor AI Enterprise extends the audit across AWS, GCP, and Azure with the full hepta-framework compliance engine, air-gapped operation, and continuous monitoring (CTEM).
Start with the MIT-licensed Community Edition. Upgrade only when you need CVE matching and risk-scored prioritization, compliance evidence, or cloud scanners.
EE 0.36.0 — the compliance report now verifies the signatures it renders
Enterprise Edition 0.36.0, published 13 August 2026 alongside Community Edition 0.2.41 and the agent-skill package 0.2.39 — the 94th consecutive trio. A compliance report lists the exceptions an approver accepted, and each carries an approval record; until now the report verified the approver’s identity against a registry but never the signature on the record itself. It checks it now: a registry entry may carry the approver’s public key beside its fingerprint, the two must agree or the registry is refused at load, and each suppression signature is verified for approvers whose registry entry carries key material. The verdict names the exact bytes it checked, and two questions are answered rather than one — whether the suppression should stand, and whether the bytes came from the key they name — which diverge on a key revoked after it signed, turning signing-after-revocation into a cryptographic finding.
What it deliberately does not say: a missing verdict means NOT CHECKED, never failed. Every identity registry in the field today carries fingerprints only, so the common case is that verification is unavailable until approvers supply key material — reporting those as failures would accuse an organisation’s own approvers of forgery for not having migrated. The report says “signed — not checked by this report”, and a new advisory names how many registered approvers are still awaiting key material and exactly what to paste. Requires Community Edition 0.2.40 or newer — unchanged this cycle. Plugin catalog unchanged at 28; all seven coverage matrices unchanged.
Full release history: the Enterprise page and the package changelogs on npm.