NSASOFT.US ← Partner Program
— PARTNER PROGRAM · OEM

OEM & Embedded Licensing

Put the NSAuditor AI evidence engine inside your product. Your platform gains deep cloud-configuration evidence across AWS, Azure, and GCP — and because every scan runs inside your end customer's infrastructure, it adds none of their cloud data to your SaaS footprint.

Zero
Customer cloud data added to your platform — the engine executes in the end customer's infrastructure and writes to their storage
3
Clouds — AWS, Azure, and GCP, read-only by design
8
Evidence packs from one scan — SOC 2 · HIPAA · NIST CSF 2.0 · PCI DSS · ISO 27001 · CIS v8 · GDPR Art. 32 · NIST SP 800-171

Why embed instead of build

🔒

Evidence without the data

Every conventional way to add cloud evidence to a platform pulls the customer's cloud configuration into your SaaS — more sensitive data to host, secure, and answer for. The embedded engine inverts that: it runs where the customer's infrastructure is, and what reaches your platform is whatever you and your customer decide — possibly nothing at all.

🧭

Depth without the roadmap

One scan, eight evidence packs — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation) — produced by a fleet of cloud auditors across AWS, Azure, and GCP, with findings mapped per control. Behind it: framework mappings maintained against the frameworks' own revision cycles, partition-aware multi-region cloud coverage, breadth-first IAM graph traversal for transitive shadow-admin and effective-decrypt paths, and evidence gaps that fail closed instead of passing silently. Years of evidence engineering, one integration.

🧾

Evidence integrity built in

SHA-256 chain-of-custody sidecars and a cover-page Scope Attestation ship with every evidence pack. Suppressions carry an approval workflow, and reports verify a suppression signature for approvers whose registry entry carries key material. RFC 3161 trusted timestamping is opt-in with no default, ever — the request is an outbound call to the authority you name. Provenance your customers' assessors can check, not just read.

🤝

Your customer stays yours

Your brand, your UI, your workflows, your tier-1 support. Nsasoft backs your named technical contacts with tier-2/3 escalation and defined response targets. We never expect — or accept — direct contact from your end customers.

How the program works

1

Embed & distribute

You incorporate the Enterprise Edition engine into your product and distribute it to your end customers as a component — delivery form and territory set per Order Form. Development, testing, and demo use is included.

2

Direct end-user licence

Before operating the embedded component, each of your end customers accepts short pass-through terms directly from Nsasoft — covering authorized-target scanning obligations and scan-data ownership. You distribute the component; you never have to sublicense it.

3

Simple commercials

An annual platform licence plus a per-unit volume fee on the unit you already bill on — end customers, cloud accounts, or environments — certified in a quarterly deployment report. No per-seat tax on your growth. Releases during the term are included.

White-label — available as a separately elected module

The standard program ships with attribution — “Technical evidence engine powered by NSAuditor AI” — in your product and its documentation. Partners who need the engine presented fully under their own brand can elect the white-label module on their Order Form: a separate election, with its own terms and fee.

One thing does not change with the election, and it is a feature rather than a caveat: inside a signed evidence pack — the chain-of-custody envelope and the artifacts it enumerates, signed with the operator-held key — the integrity metadata always names the producing engine. Evidence whose origin could be rewritten would be evidence an auditor has no reason to trust; the surviving attribution is precisely what makes the pack worth handing over.

Data protection, stated plainly

Nsasoft never receives scan data. The embedded engine executes within the operating party's infrastructure and writes its output to that party's storage — Nsasoft has no technical capability to collect, access, or process it, and is not a data processor or business associate for it. Whether scan output ever reaches your platform is an architecture decision between you and your customer. The only information Nsasoft handles under the program is licence and commercial metadata: partner and end-customer identifiers, entitlement records, and deployment reports.

What the program is not

Not a hosting arrangement

The standard grant licenses embedding and distribution — not operating the engine as a hosted or managed service on end customers' behalf. Running scans centrally on customers' infrastructure would undo the zero-data-footprint architecture the program exists to preserve.

Not a fork of the open-source edition

The Community Edition remains freely available under the MIT license. The OEM program licenses the commercial Enterprise Edition engine — the cloud auditors, the compliance mapping, and the evidence-integrity tier.

Not the end-user EULA

The program runs under a standalone OEM Master Agreement with per-deal Order Forms. The EULA governs direct end-user subscriptions and does not govern OEM relationships.

Who it fits

The program is built for platforms whose customers need cloud configuration evidence, but whose evidence collection today rides on third-party integrations, questionnaires, or screenshots:

Compliance automation platforms

GRC and compliance-automation products that orchestrate evidence workflow and want deep cloud evidence of their own.

Audit & assurance platforms

Engagement platforms serving CPA and audit firms, where client infrastructure data concentration is a liability the embedded model avoids.

MSSP & MSP platforms

Service-provider platforms adding compliance evidence to a managed security offering across a multi-tenant book of business.

Talk to us

Tell us about your platform

We are onboarding early OEM partners by direct conversation. Write to partners@nsasoft.us with the details below and we'll come back with the program structure and a technical walkthrough.

  • Your platform — what it does, who your customers are
  • How you collect cloud evidence today — integrations, questionnaires, screenshots, or an in-house scanner
  • Clouds and frameworks your customers need covered
  • The unit you bill on — end customers, cloud accounts, environments
  • Whether white-label matters to your product
✉  Start the conversation
Reselling to your clients instead of embedding? See the Reseller Partner Program.
Program status. The OEM program is onboarding design partners under a standalone OEM Master Agreement executed per deal; agreement terms are subject to final legal review and nothing on this page constitutes an offer. Commercial terms are discussed directly — we publish the model, not the price list. One current limit, stated plainly: the shipped GRC push connectors are single-workspace and operator-configured — there is no partner-hosted multi-tenant pipeline today. Building and scoping one is exactly the kind of work an OEM agreement funds.

Want the product detail first? See NSAuditor AI Enterprise and the compliance documentation.