Why embed instead of build
Evidence without the data
Every conventional way to add cloud evidence to a platform pulls the customer's cloud configuration into your SaaS — more sensitive data to host, secure, and answer for. The embedded engine inverts that: it runs where the customer's infrastructure is, and what reaches your platform is whatever you and your customer decide — possibly nothing at all.
Depth without the roadmap
One scan, eight evidence packs — SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation) — produced by a fleet of cloud auditors across AWS, Azure, and GCP, with findings mapped per control. Behind it: framework mappings maintained against the frameworks' own revision cycles, partition-aware multi-region cloud coverage, breadth-first IAM graph traversal for transitive shadow-admin and effective-decrypt paths, and evidence gaps that fail closed instead of passing silently. Years of evidence engineering, one integration.
Evidence integrity built in
SHA-256 chain-of-custody sidecars and a cover-page Scope Attestation ship with every evidence pack. Suppressions carry an approval workflow, and reports verify a suppression signature for approvers whose registry entry carries key material. RFC 3161 trusted timestamping is opt-in with no default, ever — the request is an outbound call to the authority you name. Provenance your customers' assessors can check, not just read.
Your customer stays yours
Your brand, your UI, your workflows, your tier-1 support. Nsasoft backs your named technical contacts with tier-2/3 escalation and defined response targets. We never expect — or accept — direct contact from your end customers.
How the program works
Embed & distribute
You incorporate the Enterprise Edition engine into your product and distribute it to your end customers as a component — delivery form and territory set per Order Form. Development, testing, and demo use is included.
Direct end-user licence
Before operating the embedded component, each of your end customers accepts short pass-through terms directly from Nsasoft — covering authorized-target scanning obligations and scan-data ownership. You distribute the component; you never have to sublicense it.
Simple commercials
An annual platform licence plus a per-unit volume fee on the unit you already bill on — end customers, cloud accounts, or environments — certified in a quarterly deployment report. No per-seat tax on your growth. Releases during the term are included.
White-label — available as a separately elected module
The standard program ships with attribution — “Technical evidence engine powered by NSAuditor AI” — in your product and its documentation. Partners who need the engine presented fully under their own brand can elect the white-label module on their Order Form: a separate election, with its own terms and fee.
One thing does not change with the election, and it is a feature rather than a caveat: inside a signed evidence pack — the chain-of-custody envelope and the artifacts it enumerates, signed with the operator-held key — the integrity metadata always names the producing engine. Evidence whose origin could be rewritten would be evidence an auditor has no reason to trust; the surviving attribution is precisely what makes the pack worth handing over.
Data protection, stated plainly
Nsasoft never receives scan data. The embedded engine executes within the operating party's infrastructure and writes its output to that party's storage — Nsasoft has no technical capability to collect, access, or process it, and is not a data processor or business associate for it. Whether scan output ever reaches your platform is an architecture decision between you and your customer. The only information Nsasoft handles under the program is licence and commercial metadata: partner and end-customer identifiers, entitlement records, and deployment reports.
What the program is not
Not a hosting arrangement
The standard grant licenses embedding and distribution — not operating the engine as a hosted or managed service on end customers' behalf. Running scans centrally on customers' infrastructure would undo the zero-data-footprint architecture the program exists to preserve.
Not a fork of the open-source edition
The Community Edition remains freely available under the MIT license. The OEM program licenses the commercial Enterprise Edition engine — the cloud auditors, the compliance mapping, and the evidence-integrity tier.
Not the end-user EULA
The program runs under a standalone OEM Master Agreement with per-deal Order Forms. The EULA governs direct end-user subscriptions and does not govern OEM relationships.
Who it fits
The program is built for platforms whose customers need cloud configuration evidence, but whose evidence collection today rides on third-party integrations, questionnaires, or screenshots:
Compliance automation platforms
GRC and compliance-automation products that orchestrate evidence workflow and want deep cloud evidence of their own.
Audit & assurance platforms
Engagement platforms serving CPA and audit firms, where client infrastructure data concentration is a liability the embedded model avoids.
MSSP & MSP platforms
Service-provider platforms adding compliance evidence to a managed security offering across a multi-tenant book of business.
Talk to us
Tell us about your platform
We are onboarding early OEM partners by direct conversation. Write to partners@nsasoft.us with the details below and we'll come back with the program structure and a technical walkthrough.
- Your platform — what it does, who your customers are
- How you collect cloud evidence today — integrations, questionnaires, screenshots, or an in-house scanner
- Clouds and frameworks your customers need covered
- The unit you bill on — end customers, cloud accounts, environments
- Whether white-label matters to your product
Want the product detail first? See NSAuditor AI Enterprise and the compliance documentation.