NSAuditor AI Enterprise turns one read-only cloud scan into seven auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. Each framework's manifest can be signed with your operator-held Ed25519 key and verified offline. It audits AWS, Azure, and GCP entirely inside your infrastructure with Zero Data Exfiltration: no telemetry, no SaaS backend, air-gapped operation - credentials, findings, and config never leave your network.
NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to seven frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.
The evidence-integrity chain is cryptographic and operator-controlled at every layer. compliance sign-pack signs one framework's chain-of-custody manifest and the artifacts it enumerates with an operator-held Ed25519 key - an authorship proof relative to your key custody, never a vendor attestation - and compliance verify-pack verifies it offline, recomputing every artifact hash the manifest lists; the same verification is reproducible with openssl alone. Suppression approvals can be signed with an operator-held Ed25519 key, and a report verifies those signatures only for approvers whose identity-registry entry carries key material. Opt-in RFC 3161 trusted timestamps bind report hashes to a Time-Stamp Authority you name - an outbound call to that authority only, with no default TSA.
Built for Zero Data Exfiltration, NSAuditor runs entirely inside your own infrastructure using read-only APIs and offline licensing. There are no cloud uploads, no telemetry, and no SaaS backend, which means no BAA or DPA is required and your cloud credentials, findings, and configuration never leave your network. For isolated enclaves, offline CVE data travels on your terms: feed bundle packages the NVD feeds you downloaded on a connected host - optionally with your own CISA KEV and FIRST EPSS files - and feed import loads them on the isolated host. No feed or exploit data ships with the product.
Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 55 plugins, including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. Offline CVE matching is joined with exploit intelligence: CISA KEV known-exploited flags and FIRST EPSS exploitation probabilities drive prioritization, from data you supply. Compliance evidence can be pushed to Vanta, Drata, or Secureframe. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.
Highlights
One scan, seven frameworks: auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32 - each framework's manifest signable with an operator-held Ed25519 key and verifiable offline.
Zero Data Exfiltration by architecture: runs entirely inside your infrastructure with read-only APIs and offline licensing. No cloud uploads, no telemetry, no BAA or DPA required.
Deep multi-cloud auditing across AWS, Azure, and GCP with 55 plugins; offline CVE matching joined with CISA KEV and FIRST EPSS exploit intelligence from data you supply; compliance evidence push to Vanta, Drata, or Secureframe.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.
Top-of-mind questions for buyers
What counts as one seat for billing across the three tiers?
One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
What happens if my team grows past the seat count in my tier?
Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
How do the three tiers differ beyond seat capacity?
All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
www.nsauditor.com+1
Helpful?
Vendor refund policy
Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com for cancellation or refund requests.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
EE 0.40.1 / CE 0.2.45. This is the first Marketplace version carrying EE 0.40.0's cargo: 0.40.0 was never published as a delivery option, so both releases are described here.
NEW - AN EIGHTH FRAMEWORK: NIST SP 800-171 Rev 2, shipped as "NIST SP 800-171 evidence substrate for CMMC Level 2 preparation" and never as anything stronger. Not a claim of CMMC certification, compliance or readiness; not FedRAMP authorization; never a MET or NOT MET verdict on a requirement; never an SPRS score. A Level 2 certificate is issued to a contractor by a C3PAO, and FedRAMP authorizes cloud service offerings, which this product is not.
All 110 Rev 2 requirements are enumerated - 2 covered, 49 partial, 59 out of scope - rather than a declared subset, so there is no under-enumeration surface. That only 2 are covered is the headline rather than an apology: SP 800-171A decomposes the 110 requirements into 320 assessment objectives, one objective scored NOT MET fails its whole requirement, and almost every requirement retains an objective about a defined procedure, an identified set or an organization-defined parameter that configuration cannot evidence. Each mapped requirement records its assessment objectives and the subset this engine supplies EXAMINE-method material for, and partialBasis names which of three shortfalls applies, because "partial" otherwise hides three genuinely different situations.
Two numbers were deliberately NOT shipped: a per-requirement SPRS weight and a basic/derived label. Both were transcriptions this repository cannot re-derive from an authority it holds, and an adversarial review disputed specific values in each. A per-requirement weight is also the multiplicand of the deduction arithmetic, so publishing it hands a reader the implied score the doctrine forbids. Removed rather than guessed.
Rev 2 is pinned because CMMC assesses Rev 2 by rule; Rev 3's 97 requirements with organization-defined parameters are a different universe, and Rev 3 numbering in a Rev 2 citation is drift rather than currency. Which systems process CUI remains the operator's assertion - the scanner cannot see CUI, cannot distinguish FCI from CUI, and cannot define an enclave boundary. The SSP and the POA&M are the artifacts an assessment is conducted against, and stay operator-side.
Its requirement ids collide exactly with PCI DSS sub-requirement ids - 3.5.1 is real in both, the first time two shipped frameworks share a literal id string. Both abstain from the id-sanitizer's shape table with the reason declared, and every citation carries its qualifier.
CHANGED - A KEY YOU MAY NOT CONTROL IS NO LONGER REPORTED AS CUSTOMER KEY CUSTODY. Read this before upgrading, because it changes what your reports say. Four plugins decided encryption-key custody from the key identifier's shape alone, so an alias ARN in a different AWS account, or a CMEK naming a different GCP project, read exactly like your own and the scan emitted positive audit evidence asserting the key was under customer control. Fixed in RDS, SQS/SNS, DynamoDB and GCP Cloud Storage; the finding now names both the key's account or project and the resource's, so you can confirm the arrangement rather than take a colour on trust. A foreign scope is an evidence gap and never a violation: a central key account is a recommended architecture, so a rule that failed on it would raise false positives against the layout the cloud vendors themselves advise. What you will see change: buckets, tables, queues, topics and databases whose key lives in another account or project move from PASS to a LOW evidence gap. Same-scope keys are untouched. Azure storage accounts are not covered - a vault URI carries the vault name only, with no subscription or tenant id, so establishing custody needs a separate Key Vault lookup with a new permission and a new denied-call failure mode. Boarded rather than half-implemented, because a check that silently cannot fire reads like coverage.
No finding routes to a different control as a result of this change, across all eight frameworks: these emissions are matched on stable prefixes, and the one anchor that had pinned the old reason text (GCP) was widened so the same findings route identically.
0.40.1 - 27 PHANTOM PLUGIN IDS OUT OF CUSTOMER-FACING PROSE. Compliance reports shipped identifiers naming no plugin. EE plugin ids are 1000+ and every instance was the real plugin with its leading 1 missing, including the instruction "Run plugin 040 (aws-cloudtrail-auditor) in the same scan" - a published instruction an operator cannot follow, sitting inside a finding's own remediation text. 24 occurrences in framework data and 3 in plugin emission strings. Verified against real output in stages rather than by inspection: the same estate re-scanned with the build patched incrementally went 42 phantom ids to 8 to 0, and the 42-to-8 step is the one worth keeping, because a data-only patch read as finished while a fifth of the defect lived in plugin code. A guard now derives the valid id set from the plugins on disk, so a dropped digit and an invented id are caught alike.
Plugin catalog UNCHANGED at 28. All seven pre-existing coverage matrices UNCHANGED (SOC 2 10/4/37, HIPAA 7/3/45, NIST CSF 13/10/83, PCI DSS 19/9/39, ISO 27001 17/14/62, CIS v8 17/23/113, GDPR Art. 32 4/5/2); NIST SP 800-171 is introduced at 2/49/59.
Requires nsauditor-ai >= 0.2.45. The floor is RAISED this cycle and derived from the CE version that ships the eighth framework's stem, not from a sibling working tree: published CE 0.2.44 does not carry it, so 0.40.x paired with 0.2.44 rejects the framework name. This image bakes CE 0.2.45.
Additional details
Usage instructions
LICENSE KEY (once, after subscribing).
Register at https://www.nsauditor.com/ai/marketplace/register/ with your email, the 12-digit AWS account ID for this subscription, and your Agreement ID (starts 'agmt-', AWS Console -> Manage subscriptions). Your ES256-signed key (JWT) arrives by email. Support: support@nsauditor.com.
RUN with your key in NSAUDITOR_LICENSE_KEY:
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> $IMG --help
NEW IN 0.40.0 - AN EIGHTH FRAMEWORK, SCOPED EXACTLY AS: NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Deliberately not claimed, in these exact words: CMMC certified, compliant or ready; FedRAMP authorization; any MET or NOT MET verdict; any SPRS score. All 110 Rev 2 requirements are enumerated; only 2 are covered - covered requires EVERY SP 800-171A objective to be technical system state the scan reads directly. Rev 2 is PINNED, not Rev 3. WHICH SYSTEMS PROCESS CUI IS YOUR ASSERTION - a scan cannot see CUI or define an enclave boundary. Its ids collide with PCI DSS sub-requirement ids (3.5.1 is real in both), so every citation carries its qualifier.
ALSO NEW - THIS CHANGES YOUR REPORTS. RDS, SQS/SNS, DynamoDB and GCP Cloud Storage judged key custody from the key identifier's SHAPE alone, so a key in another account or project read as your own. Those move from PASS to a LOW evidence gap naming BOTH scopes: a foreign key scope is an EVIDENCE GAP, never a violation. Azure storage accounts are NOT covered by this check - a vault URI carries no subscription or tenant id.
Every cloud plugin declares surfaces it does NOT evaluate (deferredScope). A declaration is NOT a finding and NOT an evidence gap: it routes to zero controls by design. An empty or short list is NOT a claim of full coverage.
SUPPRESSION APPROVALS: compliance suppress signs when NSAUDITOR_SIGNING_KEY names a local Ed25519 key; a report verifies it ONLY for approvers whose registry entry carries key material. A MISSING verdict means NOT CHECKED, not FAILED. compliance sign-pack/verify-pack sign a framework's manifest with an operator-held key - authorship relative to your key custody, never a vendor attestation.
AIR-GAPPED USE. No feed or exploit data ships in this image. On a connected host, feed bundle --from <nvd-dir> --out bundle.json.gz carries NVD feeds YOU downloaded; move the image (docker save) and bundle across, then feed import --file bundle.json.gz --cache-dir <store> imports your own carried data. That archive is INTEGRITY-CHECKED, NOT AUTHENTICATED: a carried SHA-256 detects alteration, never authorship. amd64 only; this image pairs CE 0.2.45 with EE 0.40.1.
License validation is fully local (ES256, embedded key, no callback). NSAUDITOR_OFFLINE_ONLY=1 makes the scan path fully offline; a configured egress path under it is refused at startup (exit 2), never skipped. RFC 3161 timestamping is opt-in: set NSAUDITOR_TSA_URL, outbound to that authority only, no default TSA ever. Round-tripped from inside THIS image version against a live TSA, verified with the image's own openssl beside a tampered control that failed.
WHERE SENSITIVE DATA IS STORED (Zero Data Exfiltration).
Cloud credentials are read-only at runtime, and all scan data - credentials, findings, configuration, reports - stays in YOUR environment (the container and volumes you mount). No telemetry, no SaaS backend; Nsasoft US LLC collects, transmits or stores no customer data. By default the only outbound connections are your cloud provider's control plane, NVD CVE lookups and SES DNS lookups in AWS scans. The only data we receive is the billing metadata above (AWS account ID, Agreement ID, registration email), used solely to verify your subscription and issue the license.
Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.
Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.
Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.