NSAuditor AI Enterprise turns one read-only cloud scan into eight auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Each framework's manifest can be signed with your operator-held Ed25519 key and verified offline. It audits AWS, Azure, and GCP from inside your infrastructure with Zero Data Exfiltration: no scan data or evidence is sent to Nsasoft, there is no telemetry and no SaaS backend, and the one default path that carries scan content (the CVE lookup to NIST's NVD) can be switched off for air-gapped operation.
NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to eight frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.
The evidence-integrity chain is cryptographic and operator-controlled at every layer. compliance sign-pack signs one framework's chain-of-custody manifest and the artifacts it enumerates with an operator-held Ed25519 key - an authorship proof relative to your key custody, never a vendor attestation - and compliance verify-pack verifies it offline, recomputing every artifact hash the manifest lists; the same verification is reproducible with openssl alone. Suppression approvals can be signed with an operator-held Ed25519 key, and a report verifies those signatures only for approvers whose identity-registry entry carries key material. Opt-in RFC 3161 trusted timestamps bind report hashes to a Time-Stamp Authority you name - an outbound call to that authority only, with no default TSA.
Built for Zero Data Exfiltration, NSAuditor runs inside your own infrastructure using read-only APIs and offline licensing. No scan data or evidence artifact is sent to Nsasoft, there is no telemetry and no SaaS backend, and your cloud credentials go only to your own cloud providers, so no BAA or DPA with Nsasoft is needed. Every outbound path is listed in a published register; of those on by default, the one that carries scan content is the CVE lookup, which sends each identified service's vendor, product and version to NIST's NVD unless you set NSAUDITOR_OFFLINE_ONLY=1 with a local NVD store. For isolated enclaves, offline CVE data travels on your terms: feed bundle packages the NVD feeds you downloaded on a connected host - optionally with your own CISA KEV and FIRST EPSS files - and feed import loads them on the isolated host. No feed or exploit data ships with the product.
Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 28 cloud plugins (56 in total), including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. CVE matching - against NVD, or offline from feeds you import - is joined with exploit intelligence: CISA KEV known-exploited flags and FIRST EPSS exploitation probabilities drive prioritization, from data you supply. Compliance evidence can be pushed to Vanta, Drata, or Secureframe. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.
Highlights
One scan, eight frameworks: auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation - each framework's manifest signable with an operator-held Ed25519 key and verifiable offline.
Zero Data Exfiltration: runs inside your infrastructure with read-only APIs and offline licensing. No scan data is sent to Nsasoft, no telemetry, and every outbound path is listed in a published register.
Deep multi-cloud auditing across AWS, Azure, and GCP with 28 cloud plugins (56 in total); CVE matching joined with CISA KEV and FIRST EPSS exploit intelligence from data you supply; compliance evidence push to Vanta, Drata, or Secureframe.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.
Top-of-mind questions for buyers
What counts as one seat for billing across the three tiers?
One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
What happens if my team grows past the seat count in my tier?
Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
How do the three tiers differ beyond seat capacity?
All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
www.nsauditor.com+1
Helpful?
Vendor refund policy
Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com for cancellation or refund requests.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
EE 1.2.0 / CE 0.2.56 - six more cases checked before a finding is called fixed.
For Pro and Enterprise delta reports (nsauditor-ai report --since): a vanished UDP finding is filed NOT-COMPARABLE unless the other scan recorded that port as closed or answering; measured on a real router run against a twin missing its 22 UDP rows, all 22 are filed not comparable, each with its reason. After a failed CVE lookup, that service's earlier CVE rows are not counted as fixed in the delta or MTTR. An analysis agent that failed, timed out or returned no finding list leaves a [COVERAGE GAP] AGENT NOT RUN record: the delta files that agent's rows NOT-COMPARABLE, MTTR withholds them, and 78 generated routing rules route the gap to the controls that agent's findings fail, in every framework that maps that agent. An Enterprise package that failed to load is named on stderr and recorded on the scan's conclusion, and that host's analysis-agent and CVE rows are filed NOT-COMPARABLE. A CVE the vulnerability data stopped attributing while the same program and version still answer is filed NOT-COMPARABLE (vulnerability-data-changed), with the row calling the absence a change in the vulnerability data it was matched against, not a remediation.
For Enterprise compliance reports: with SLA tracking on (--compliance-history or --sla-policy) and a prior compliance scan of the same host in the history, a control that failed on a prior finding stays FAILED, backed by an evidence-gap record counted among "Evidence gaps (not findings)", when this scan did not re-measure that finding's port, region or producer.
Also: a CVE newly attributed to an unchanged service stays NEW, with a note that the service is unchanged and the vulnerability data is not; two scans of one host whose plugin runs finish in the same second get separate output directories. Plugin count is unchanged at 29 and all eight coverage matrices are unchanged. Paired with CE 0.2.56 and agent-skill 0.2.54; the Community peer floor rises to CE >= 0.2.56.
Additional details
Usage instructions
LICENSE KEY (once, after subscribing).
Register at https://www.nsauditor.com/ai/marketplace/register/ with your email, this subscription's 12-digit AWS account ID and Agreement ID ('agmt-...', AWS Console -> Manage subscriptions). Your ES256-signed key (JWT) arrives by email. Support: support@nsauditor.com.
RUN with your key in NSAUDITOR_LICENSE_KEY:
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> $IMG --help
WHAT CHANGED SINCE THE LAST SCAN (Pro and Enterprise). Write both scans to the same --out directory with the same --plugins set, then compare them:
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> -v "$PWD/out:/out" $IMG report --from /out --format executive --since prior
The report lists what is new, what is resolved and what changed severity, and files a finding the run recorded it could not measure as NOT-COMPARABLE with the reason on the row. Run records written since EE 1.1.0 are chained with SHA-256, and a baseline altered after it was written refuses the comparison.
NEW IN 1.2.0: six more cases checked. A vanished UDP finding is filed NOT-COMPARABLE unless the other scan recorded that port as closed or answering. After a failed CVE lookup, that service's earlier CVE rows are not counted as fixed in the delta or MTTR. An analysis agent that did not run leaves a [COVERAGE GAP] AGENT NOT RUN record, and its rows are filed NOT-COMPARABLE. An Enterprise package that failed to load is named on stderr, and that host's analysis-agent and CVE rows are filed NOT-COMPARABLE. A CVE the vulnerability data stopped attributing while the same program and version still answer is filed NOT-COMPARABLE (vulnerability-data-changed). With SLA tracking on (--compliance-history <dir> or --sla-policy <file>) and a prior compliance scan of the same host, a control that failed on a prior finding stays FAILED when this scan did not re-measure that finding's port, region or producer. Plugin count is unchanged at 29 and all eight coverage matrices are unchanged. Paired with CE 0.2.56 and agent-skill 0.2.54; the Community peer floor rises to CE >= 0.2.56.
CLOUD SCAN (read-only credentials; the scanner refuses a writable role):
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_REGION
-v "$PWD/out:/out" $IMG --host aws --plugins all --compliance soc2,hipaa,pci --out /out
EVIDENCE. Each run writes JSON, Markdown and HTML into --out, plus the compliance pack for every framework you name. Eight frameworks map from one read-only scan: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 (infrastructure substrate only) and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation - not a certification, and this product does not assess or grant one).
TIME AND INTEGRITY, both opt-in and both yours to verify. Set NSAUDITOR_TSA_URL and each artifact ships a .tsr sidecar holding the Time-Stamp Response from the Time-Stamp Authority you name - outbound to that authority only, never a default, and refused outright under an offline-only posture. A chain-of-custody envelope names exactly the artifacts it covers and re-hashes each one at verification; files it does not enumerate are outside it, which the tool prints rather than leaving you to assume.
NETWORK SCAN: replace --host aws with a host or CIDR. ECS and EKS are the supported runtimes.
Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.
Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.
Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Extract named entities from English text, including your own custom types at inference with no retraining. Runs inside your AWS account on CPU, so no text is sent to a third-party API. 18 default entity types.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.