NSAuditor AI Enterprise turns one read-only cloud scan into seven auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. Each framework's manifest can be signed with your operator-held Ed25519 key and verified offline. It audits AWS, Azure, and GCP entirely inside your infrastructure with Zero Data Exfiltration: no telemetry, no SaaS backend, air-gapped operation - credentials, findings, and config never leave your network.
NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to seven frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.
The evidence-integrity chain is cryptographic and operator-controlled at every layer. compliance sign-pack signs one framework's chain-of-custody manifest and the artifacts it enumerates with an operator-held Ed25519 key - an authorship proof relative to your key custody, never a vendor attestation - and compliance verify-pack verifies it offline, recomputing every artifact hash the manifest lists; the same verification is reproducible with openssl alone. Suppression approvals can be signed with an operator-held Ed25519 key, and a report verifies those signatures only for approvers whose identity-registry entry carries key material. Opt-in RFC 3161 trusted timestamps bind report hashes to a Time-Stamp Authority you name - an outbound call to that authority only, with no default TSA.
Built for Zero Data Exfiltration, NSAuditor runs entirely inside your own infrastructure using read-only APIs and offline licensing. There are no cloud uploads, no telemetry, and no SaaS backend, which means no BAA or DPA is required and your cloud credentials, findings, and configuration never leave your network. For isolated enclaves, offline CVE data travels on your terms: feed bundle packages the NVD feeds you downloaded on a connected host - optionally with your own CISA KEV and FIRST EPSS files - and feed import loads them on the isolated host. No feed or exploit data ships with the product.
Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 55 plugins, including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. Offline CVE matching is joined with exploit intelligence: CISA KEV known-exploited flags and FIRST EPSS exploitation probabilities drive prioritization, from data you supply. Compliance evidence can be pushed to Vanta, Drata, or Secureframe. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.
Highlights
One scan, seven frameworks: auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32 - each framework's manifest signable with an operator-held Ed25519 key and verifiable offline.
Zero Data Exfiltration by architecture: runs entirely inside your infrastructure with read-only APIs and offline licensing. No cloud uploads, no telemetry, no BAA or DPA required.
Deep multi-cloud auditing across AWS, Azure, and GCP with 55 plugins; offline CVE matching joined with CISA KEV and FIRST EPSS exploit intelligence from data you supply; compliance evidence push to Vanta, Drata, or Secureframe.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.
Top-of-mind questions for buyers
What counts as one seat for billing across the three tiers?
One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
What happens if my team grows past the seat count in my tier?
Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
How do the three tiers differ beyond seat capacity?
All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
www.nsauditor.com+1
Helpful?
Vendor refund policy
Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com for cancellation or refund requests.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
EE 0.39.0 / CE 0.2.44.
NEW - COVERAGE-BOUNDARY DECLARATIONS ON EVERY CLOUD PROVIDER. A deferredScope declaration is the only channel by which a report reader learns that a surface was never examined. All nine shipped declarations came from AWS plugins while the seven GCP and Azure plugins declared nothing - so an AWS reader was told what was excluded by design and a GCP or Azure reader was told nothing. Seven declarations were added (plugins 1021, 1022, 1024, 1025, 1220, 1221, 1222), between 8 and 12 boundaries each, emitted on the audited path including over an empty estate and never on a precondition-failure path where no audit ran. They are ordered by materiality, because Community Edition abridges the declaration to 420 characters in its scan badge.
A declaration is NOT a finding and NOT an evidence gap: it routes to ZERO controls by design, re-measured across 49 declaration-by-framework combinations returning zero control violations beside a live negative control that correctly routed to three SOC 2 controls. An empty or short declaration list is NOT a claim of full coverage.
Every boundary was verified against the implementing code rather than a keyword search, which corrected four of them before shipping - the absence of a word is a hypothesis about vocabulary, not a capability boundary. An overstated boundary is an underclaim, and nothing ever complains about that direction.
Requires nsauditor-ai >= 0.2.43 - the floor is UNCHANGED this cycle.
Additional details
Usage instructions
REGISTER FOR YOUR LICENSE KEY (one time, after subscribing).
Open https://www.nsauditor.com/ai/marketplace/register/ and enter your email, the 12-digit AWS account ID holding this subscription, and your Agreement ID (starts 'agmt-': AWS Console -> AWS Marketplace -> Manage subscriptions -> NSAuditor AI Enterprise). Your ES256-signed license key (JWT) is emailed there. Support: support@nsauditor.com.
RUN, passing your key via NSAUDITOR_LICENSE_KEY (or mount a config volume and license install <key> once):
docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> 709825985650.dkr.ecr.us-east-1.amazonaws.com/nsasoft-us/nsasoft/nsauditor-ai-enterprise:0.39.0 --help
NEW IN 0.39.0 - READ BEFORE TREATING A SHORT FINDING LIST AS A CLEAN ONE. Every cloud plugin now declares the surfaces it does NOT evaluate, as a deferredScope declaration on the finding record; A declaration is NOT a finding and NOT an evidence gap: it routes to zero controls by design, stating only what was never assessed. An empty or short list is NOT a claim of full coverage - not every plugin declares its boundaries.
SUPPRESSION APPROVALS are CLI subcommands: compliance keygen (refuses to overwrite - regenerating a key voids every signature it produced), compliance suppress (signs its approval when NSAUDITOR_SIGNING_KEY names a local Ed25519 key; a report verifies it ONLY for approvers whose registry entry carries key material), plus review / renew. A MISSING verdict means NOT CHECKED, not FAILED. compliance sign-pack / verify-pack sign one framework's manifest and the artifacts it enumerates with an operator-held key - authorship relative to your key custody, never a vendor attestation; offline verify re-hashes every listed artifact.
AIR-GAPPED USE. No feed or exploit data ships with this image. Connected host: feed bundle --from <nvd-dir> --kev <catalog> --epss <scores> --out bundle.json.gz carries the NVD feeds YOU downloaded plus your own CISA KEV and EPSS files; move the image (docker save) and bundle across. Isolated host: feed import --file bundle.json.gz --cache-dir <store> --extras-dir <dir> imports your own carried data. The archive is INTEGRITY-CHECKED, NOT AUTHENTICATED: a carried SHA-256 detects alteration in transit but cannot establish authorship. Requires CE >= 0.2.43; amd64 only.
Cloud credentials are supplied read-only at runtime (-e AWS_* / mounted profiles). One image serves every tier, differing only by key. License validation is fully local (ES256, embedded key, no callback). NSAUDITOR_OFFLINE_ONLY=1 makes the scan path fully offline; a configured egress path under it is refused at startup (exit 2), never skipped. Every other outbound path is opt-in and off by default; the full register is in the image's docs (architecture 14.1.1).
RFC 3161 timestamping is opt-in: set NSAUDITOR_TSA_URL, outbound to that authority only, no default TSA ever. Exercised end to end from inside THIS image version against a live TSA, verified with the image's own openssl beside a one-byte-tampered control that failed.
WHERE SENSITIVE DATA IS STORED (Zero Data Exfiltration).
All scan data - credentials, findings, configuration and reports - stays inside YOUR environment (the container and any volumes you mount). The product sends no telemetry and has no SaaS backend; no customer data is collected, transmitted or stored by Nsasoft US LLC. By default the only outbound connections are your cloud provider's control plane (the scan itself), NVD CVE lookups and SES DNS lookups during AWS scans. The only data we receive is the billing metadata above (AWS account ID, Agreement ID, registration email), used solely to verify the subscription is yours and issue your license.
Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.
Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.
Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.