Find real vulnerabilities. Keep every byte.
NSAuditor AI by Nsasoft US LLC is an open-source AI-powered network security scanner with zero data exfiltration. 56 plugins (27 Community + 29 Enterprise), offline CVE matching, multi-cloud auditing across AWS, Azure, and GCP, and air-gapped operation. Runs entirely on your infrastructure — your scan data, findings, and reports never touch our servers.
Zero data exfiltration, verifiable
Run strace -e trace=connect or tcpdump while scanning: you will see the targets you specified, your own cloud provider’s APIs during a cloud scan, DNS lookups, multicast discovery on your local segment (mDNS, LLMNR, SSDP, WS-Discovery), NIST’s public NVD API for CVE matching (none with NSAUDITOR_OFFLINE_ONLY=1 and a local NVD store), and any service you opt into, such as your own AI provider — and nothing sent to Nsasoft. No analytics SDK, no error reporting service, no “anonymized telemetry”. License validation is offline JWT.
How it works
- Install in 30 seconds —
npm install -g nsauditor-ai. macOS, Linux, Windows. No SaaS account.
- Scan from your terminal —
NSA_ALLOW_ALL_HOSTS=1 nsauditor-ai scan --host 10.0.0.0/24 (a private range needs NSA_ALLOW_ALL_HOSTS=1: the SSRF guard refuses RFC 1918 and loopback targets by default). Community’s 27 plugins run against every host in the range (Enterprise’s cloud auditors run on --host aws, azure or gcp). CVE matching + risk-scored prioritization on Pro.
- Ship the report —
nsauditor-ai report --from <dir> --format executive (<dir> is the scan’s --out directory, out by default) turns a finished scan into a self-contained, print-ready HTML report you can send (Pro and Enterprise); --format jira writes a Jira-importer CSV instead (its column mapping is completed inside Jira’s own importer), and the scan itself writes JSON, plus SARIF with --output-format sarif. Scan again after the fixes and nsauditor-ai report --from <dir> --format executive --since prior answers the client’s next question — did we actually get better? — with what is new, what is resolved and what changed severity in the same report (Pro and Enterprise). When the report can see that a finding was not measured the same way twice — a host that was not scanned; a plugin that did not run, errored or timed out; an evidence gap; a narrower scope; a TCP port the port scanner saw open that stopped answering — it files the finding as not-comparable, with the reason on the row, instead of calling it resolved. That port check reads only TCP ports, so a UDP-only finding that disappears can still read as resolved. Beside the comparison the report states that framework-enumeration movement is not evaluated in this release, and the baseline’s integrity state (a baseline scanned before 1.1.0 carries no integrity digest); when either run holds analysis-agent findings, it adds that their scope comes from the license tier. Known limit: two scans of one host that finish in the same second into the same output directory share one evidence directory, and the later run’s files replace the earlier run’s; this release refuses the overwritten run at report time, the overwriting scan does not yet warn, and a fix is planned for the next release.
Multi-framework compliance from one scan
SOC 2 (AICPA TSC 2017) · HIPAA §164.312 · NIST CSF 2.0 · PCI DSS v4.0.1 · ISO/IEC 27001:2022 · CIS Controls v8 · GDPR Article 32 · NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation — not a certification). One --compliance flag, eight auditor-ready evidence packs. An S3 audit-trail gap is reported only when both trails are missing — a CloudTrail data-event trail that already covers the bucket satisfies it, judged per selector, with org trails and prefix-scoped selectors refused rather than assumed.
Pricing
- Community — Free forever, MIT-licensed. 27 plugins. npm install -g nsauditor-ai
- Pro — $39/mo billed annually ($470/yr), or $49/mo billed monthly. CVE matching, exploit-first triage (CISA KEV + FIRST EPSS), risk-scored prioritization, the
report command’s self-contained executive HTML (print to PDF from your browser), and delta reports of what changed since the last scan.
- Enterprise — From $2,000/yr. 29 EE plugins (28 cloud auditors across AWS · GCP · Azure, plus a Zero Trust posture assessment that scores a network-host scan), octa-framework compliance, air-gapped operation, unlimited scan-history retention with delta detection, dedicated support.
For developers
- Getting started — new Enterprise customers: install, activate, configure cloud credentials, run your first audit, and scope it with --aws-region.
- Documentation — quick start, architecture, plugin SDK, compliance evidence, MCP integration, air-gapped operation.
- GitHub — MIT-licensed core. Read it, fork it, ship it.
- MCP integration — run NSAuditor AI as an MCP server. Hook it into Claude Code, Cursor, or any MCP-aware client.
About Nsasoft US LLC
Nsasoft US LLC builds NSAuditor AI — a local-first, AI-powered network and cloud security scanner with Zero Data Exfiltration, so no customer data is collected, transmitted or stored by Nsasoft. Used by MSPs, MSSPs, and compliance consultancies to power client assessments, and by mid-market teams in healthcare, finance, government, and critical infrastructure that need continuous evidence for SOC 2, HIPAA, PCI DSS, ISO 27001, and NIST CSF. Headquartered at 732 S 6th St, Suite R, Las Vegas, NV 89101. Contact: support@nsasoft.us · sales@nsasoft.us · +1-702-625-0401.
This page requires JavaScript for the full interactive experience.
Direct links: NSAuditor AI,
Pricing,
Docs,
GitHub,
SOC 2,
Partner Programs.