Listing Thumbnail

    NSAuditor AI Enterprise Edition

     Info
    Deployed on AWS
    NSAuditor AI Enterprise turns one read-only cloud scan into seven auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. It audits AWS, Azure, and GCP entirely inside your infrastructure with Zero Data Exfiltration: no telemetry, no SaaS backend, and air-gapped operation, so cloud credentials, findings, and config never leave your network.

    Overview

    Open image

    NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to seven frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.

    Built for Zero Data Exfiltration, NSAuditor runs entirely inside your own infrastructure using read-only APIs and offline licensing. There are no cloud uploads, no telemetry, and no SaaS backend, which means no BAA or DPA is required and your cloud credentials, findings, and configuration never leave your network. This makes it a fit for air-gapped and highly regulated environments across financial services, healthcare, and government.

    Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 55 plugins, including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.

    Highlights

    • One scan, seven frameworks: generate auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, and GDPR Article 32.
    • Zero Data Exfiltration by architecture: runs entirely inside your infrastructure with read-only APIs and offline licensing. No cloud uploads, no telemetry, no BAA or DPA required.
    • Deep multi-cloud auditing across AWS, Azure, and GCP with 55 plugins, including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure.

    Details

    Delivery method

    Supported services

    Delivery option
    NSAuditor AI Enterprise 0.36.0 (container)
    NSAuditor AI Enterprise 0.35.0 (container)
    Container image (Docker / Kubernetes / air-gap capable)

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    NSAuditor AI Enterprise Edition

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Enterprise Base
    Enterprise tier, up to 5 seats
    $2,000.00
    Enterprise Growth
    Enterprise tier, up to 25 seats
    $5,000.00
    Enterprise Scale
    Enterprise tier, unlimited seats (1000)
    $10,000.00

    AI Insights

     Info

    Dimensions summary

    You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.

    Top-of-mind questions for buyers

    One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
    Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
    All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
    www.nsauditor.com+1
    Helpful?

    Vendor refund policy

    Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com  for cancellation or refund requests.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    NSAuditor AI Enterprise 0.36.0 (container)

    Supported services: Learn more 
    • Amazon ECS
    • Amazon EKS
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    Every compliance report now verifies the suppression signatures it renders, for approvers whose registry entry carries key material. A registry entry may hold the approver's public key beside its fingerprint, and the fingerprint must equal the one computed from that material or the registry is refused at load. Each verdict names the exact signature bytes it checked, so it cannot be aliased onto another record sharing an id. Two axes, not one: whether a suppression should stand, and whether those bytes came from the key they name. They differ on exactly the revoked case, which is what makes signing-after-revocation a cryptographic finding rather than a statement about an operator-editable string. A missing verdict means NOT CHECKED and renders as "signed - not checked by this report"; only a failed check renders as failed. Also fixed, and it is why this release is worth installing: a signed approval could not reach a scan. Suppressions were resolved from the per-scan output folder, which is created during the run, so the file had to sit in a directory that did not exist yet and no operator placement could be read. They now resolve from NSAUDITOR_SUPPRESSIONS (absolute honoured verbatim, relative against your working directory), then the per-scan folder if a file is genuinely there, then the --out base where compliance suppress writes. The documented quickstart works as written. The identity phase no longer degrades on an engine fault; that framework's report fails loudly instead of rendering a degraded section that told the auditor to restore a registry that was fine. Bundles Community Edition 0.2.41. Plugin catalog unchanged at 28; all seven coverage matrices unchanged (SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO 27001:2022, CIS Controls v8, GDPR Art. 32).

    Additional details

    Usage instructions

    1. REGISTER FOR YOUR LICENSE KEY (one time, after subscribing). Open https://www.nsauditor.com/ai/marketplace/register/  and enter: (a) your email, (b) the 12-digit AWS account ID holding this subscription, (c) your Agreement ID. WHERE TO FIND IT: starts with 'agmt-'. AWS Console -> AWS Marketplace -> Manage subscriptions -> NSAuditor AI Enterprise. It is checked against the agreement AWS reports for that account. Your ES256-signed license key (JWT) is emailed to that address. Or POST the same fields directly: curl -X POST https://api.licgw.com/v1/marketplace/register  -H "Content-Type: application/json" -d '{"email":"you@company.com ","awsAccountId":"123456789012","agreementId":"agmt-xxxxxxxx"}' Support: support@nsauditor.com .

    2. PULL THE IMAGE. aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin 709825985650.dkr.ecr.us-east-1.amazonaws.com docker pull 709825985650.dkr.ecr.us-east-1.amazonaws.com/nsasoft-us/nsasoft/nsauditor-ai-enterprise:0.36.0

    3. RUN WITH YOUR LICENSE. Pass it via NSAUDITOR_LICENSE_KEY (or mount a config volume and run license install <key> once): docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> 709825985650.dkr.ecr.us-east-1.amazonaws.com/nsasoft-us/nsasoft/nsauditor-ai-enterprise:0.36.0 --help Suppression approvals are subcommands: compliance keygen (keypair; refuses to overwrite, since regenerating a key voids every signature it produced), compliance suppress (signs the approval it writes when NSAUDITOR_SIGNING_KEY names a local Ed25519 key, and a report checks that signature only for approvers whose registry entry carries key material), review / renew (renew warns it invalidates an existing signature). CLI-only. NEW IN 0.36.0: every compliance report cryptographically verifies each suppression signature it renders, for approvers whose registry entry carries key material. An entry may hold the approver's public key beside its fingerprint; the two must agree or the registry is refused at load. The verdict separates whether a suppression should stand from whether its bytes came from the key they name, diverging on a key revoked after it signed. A MISSING verdict means NOT CHECKED, never FAILED: an entry with only a fingerprint has nothing to check against, so the report reads "signed - not checked by this report". Cloud credentials are supplied read-only at runtime (-e AWS_* / mounted profiles). One image serves every tier; base / growth / scale differ only by the license key. Air-gapped operation: license validation is fully local (ES256, embedded key, no callback). Set NSAUDITOR_OFFLINE_ONLY=1 to serve CVE lookups locally and make the scan path fully offline; a configured egress path under it is refused at startup (exit 2), never skipped. Every other outbound path is opt-in and off by default (AI enrichment, GRC push, timestamping, KMS signing, NTP probe, monitoring webhook); the full register is in the image's docs (architecture 14.1.1). Opt-in RFC 3161 trusted timestamping, not yet exercised against a live Time-Stamp Authority from inside this exact image version: set NSAUDITOR_TSA_URL to the TSA you choose, outbound there only, no default TSA.

    4. WHERE SENSITIVE INFORMATION IS STORED (Zero Data Exfiltration). All scan data - credentials, findings, configuration, and generated reports - stays inside YOUR environment (the container and any volumes you mount). The product sends no telemetry and has no SaaS backend, and no customer data is collected, transmitted, or stored by Nsasoft US LLC. Outbound connections are limited to the register above: by default your cloud provider's control plane (the scan itself), NVD CVE lookups (servable locally with NSAUDITOR_OFFLINE_ONLY=1) and SES DNS lookups during AWS scans; all else is opt-in and off by default. The only data we receive is the billing/fulfillment metadata above (AWS account ID, Agreement ID, registration email), processed solely to verify the subscription is yours and issue your license.

    Support

    Vendor support

    Support: support@nsauditor.com  | +1-702-625-0401 | https://www.nsauditor.com/support.html 

    Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.

    Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.

    Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.