NSAuditor AI Enterprise turns one read-only cloud scan into eight auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Each framework's manifest can be signed with your operator-held Ed25519 key and verified offline. It audits AWS, Azure, and GCP from inside your infrastructure with Zero Data Exfiltration: no scan data or evidence is sent to Nsasoft, there is no telemetry and no SaaS backend, and the one default path that carries scan content (the CVE lookup to NIST's NVD) can be switched off for air-gapped operation.
NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to eight frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.
The evidence-integrity chain is cryptographic and operator-controlled at every layer. compliance sign-pack signs one framework's chain-of-custody manifest and the artifacts it enumerates with an operator-held Ed25519 key - an authorship proof relative to your key custody, never a vendor attestation - and compliance verify-pack verifies it offline, recomputing every artifact hash the manifest lists; the same verification is reproducible with openssl alone. Suppression approvals can be signed with an operator-held Ed25519 key, and a report verifies those signatures only for approvers whose identity-registry entry carries key material. Opt-in RFC 3161 trusted timestamps bind report hashes to a Time-Stamp Authority you name - an outbound call to that authority only, with no default TSA.
Built for Zero Data Exfiltration, NSAuditor runs inside your own infrastructure using read-only APIs and offline licensing. No scan data or evidence artifact is sent to Nsasoft, there is no telemetry and no SaaS backend, and your cloud credentials go only to your own cloud providers, so no BAA or DPA with Nsasoft is needed. Every outbound path is listed in a published register; of those on by default, the one that carries scan content is the CVE lookup, which sends each identified service's vendor, product and version to NIST's NVD unless you set NSAUDITOR_OFFLINE_ONLY=1 with a local NVD store. For isolated enclaves, offline CVE data travels on your terms: feed bundle packages the NVD feeds you downloaded on a connected host - optionally with your own CISA KEV and FIRST EPSS files - and feed import loads them on the isolated host. No feed or exploit data ships with the product.
Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 28 cloud plugins (56 in total), including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. CVE matching - against NVD, or offline from feeds you import - is joined with exploit intelligence: CISA KEV known-exploited flags and FIRST EPSS exploitation probabilities drive prioritization, from data you supply. Compliance evidence can be pushed to Vanta, Drata, or Secureframe. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.
Highlights
One scan, eight frameworks: auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation - each framework's manifest signable with an operator-held Ed25519 key and verifiable offline.
Zero Data Exfiltration: runs inside your infrastructure with read-only APIs and offline licensing. No scan data is sent to Nsasoft, no telemetry, and every outbound path is listed in a published register.
Deep multi-cloud auditing across AWS, Azure, and GCP with 28 cloud plugins (56 in total); CVE matching joined with CISA KEV and FIRST EPSS exploit intelligence from data you supply; compliance evidence push to Vanta, Drata, or Secureframe.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.
Top-of-mind questions for buyers
What counts as one seat for billing across the three tiers?
One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
What happens if my team grows past the seat count in my tier?
Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
How do the three tiers differ beyond seat capacity?
All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
www.nsauditor.com+1
Helpful?
Vendor refund policy
Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com for cancellation or refund requests.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
EE 1.3.0 / CE 0.2.57 - SLA age that no longer resets on every scan, and three more cases checked before a finding is called fixed.
For Enterprise compliance reports: since EE 0.32.4, outside SOC 2, a finding whose stored text a compliance pack had rewritten was counted as closed on each later scan and found again as new, so in the HIPAA, NIST CSF, PCI DSS, ISO 27001, CIS, GDPR and NIST SP 800-171 packs its age never reached an SLA threshold. A finding is now keyed on its prose with every framework's ids removed, on both sides, so a history written by any earlier release reads correctly with no pack regenerated. With SLA tracking on (--compliance-history or --sla-policy) and a prior compliance scan of the same host, the controls behind a failed CVE lookup now stay FAILED, backed by a [COVERAGE GAP] LOOKUP NOT MEASURED record; and the CVE mapper's record of a lookup that itself failed fails, as an evidence gap, the 14 controls its CVE rows map to in seven frameworks.
For Pro and Enterprise delta reports (nsauditor-ai report --since): in a scan made with 1.3.0 that includes the port scanner (003), a plugin an analysis agent reads that was left out records an input gap, so the delta files that agent's earlier rows NOT-COMPARABLE and MTTR withholds them; with the SSH probe left out, the CVE mapper's and the service agent's earlier rows on a port 22 that answered unidentified are filed NOT-COMPARABLE. Each new, resolved and changed row's Basis cell says what was checked for that row.
Also: the egress register lists 18 outbound paths, up from 16 (a redirect the scanned web server returns, and a UPnP device's description URL); a failed GuardDuty listing is an evidence gap rather than a HIGH finding that GuardDuty is not enabled; the Missing-HSTS check fires on port 443 where the HTTPS response was received; a non-default SNMP community string and the cookie values the HTTP probe records no longer reach the scan's artifacts. Plugin count is unchanged at 29 and all eight coverage matrices are unchanged. Paired with CE 0.2.57 and agent-skill 0.2.55; the Community peer floor rises to CE >= 0.2.57. Rescan with this image before comparing across the upgrade.
Additional details
Usage instructions
LICENSE KEY (once, after subscribing).
Register at https://www.nsauditor.com/ai/marketplace/register/ with your email, this subscription's 12-digit AWS account ID and Agreement ID ('agmt-...', AWS Console -> Manage subscriptions). Your ES256-signed key (JWT) arrives by email. Support: support@nsauditor.com.
RUN with your key in NSAUDITOR_LICENSE_KEY:
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> $IMG --help
WHAT CHANGED SINCE THE LAST SCAN (Pro and Enterprise). Write both scans with this image to the same --out directory with the same --plugins set, including the port scanner (003), then compare them:
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> -v "$PWD/out:/out" $IMG report --from /out --format executive --since prior
The report lists what is new, what is resolved and what changed severity, and files a finding the run recorded it could not measure as NOT-COMPARABLE with the reason on the row. Run records written since EE 1.1.0 are chained with SHA-256, and a baseline altered after it was written refuses the comparison.
NEW IN 1.3.0: SLA age that no longer resets on every scan. Outside SOC 2, a finding whose stored text a compliance pack had rewritten was counted as closed on each later scan and found again as new; a finding is now keyed on its prose with every framework's ids removed, so a history written by any earlier release reads correctly with no pack regenerated. Three more cases checked before a finding is called fixed: with SLA tracking on (--compliance-history <dir> or --sla-policy <file>), the controls behind a failed CVE lookup stay FAILED, backed by a [COVERAGE GAP] LOOKUP NOT MEASURED record; in a scan that includes the port scanner (003), a plugin an analysis agent reads that was left out records an input gap, and that agent's earlier rows are filed NOT-COMPARABLE; and with the SSH probe left out, the CVE mapper's and the service agent's earlier rows on a port 22 that answered unidentified are filed NOT-COMPARABLE. Each new, resolved and changed row's Basis cell says what was checked for that row. Plugin count is unchanged at 29 and all eight coverage matrices are unchanged. Paired with CE 0.2.57 and agent-skill 0.2.55; the Community peer floor rises to CE >= 0.2.57.
CLOUD SCAN (read-only credentials; the scanner refuses a writable role):
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_REGION
-v "$PWD/out:/out" $IMG --host aws --plugins all --compliance soc2,hipaa,pci --out /out
EVIDENCE. Each run writes JSON, Markdown and HTML into --out, plus the compliance pack for every framework you name. Eight frameworks map from one read-only scan: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 (infrastructure substrate only) and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation - not a certification, and this product does not assess or grant one).
TIME AND INTEGRITY, both opt-in and both yours to verify. Set NSAUDITOR_TSA_URL and each artifact ships a .tsr sidecar holding the Time-Stamp Response from the Time-Stamp Authority you name - outbound to that authority only, never a default, and refused outright under an offline-only posture. A chain-of-custody envelope names exactly the artifacts it covers and re-hashes each one at verification; files it does not enumerate are outside it, which the tool prints rather than leaving you to assume.
NETWORK SCAN: replace --host aws with a host or CIDR. ECS and EKS are the supported runtimes.
Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.
Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.
Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Extract named entities from English text, including your own custom types at inference with no retraining. Runs inside your AWS account on CPU, so no text is sent to a third-party API. 18 default entity types.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.