Listing Thumbnail

    NSAuditor AI Enterprise Edition

     Info
    Deployed on AWS
    NSAuditor AI Enterprise turns one read-only cloud scan into eight auditor-ready evidence packs mapped to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Each framework's manifest can be signed with your operator-held Ed25519 key and verified offline. It audits AWS, Azure, and GCP entirely inside your infrastructure with Zero Data Exfiltration: no telemetry, no SaaS backend, air-gapped operation - credentials, findings, and config never leave your network.

    Overview

    Play video

    NSAuditor AI Enterprise Edition is a self-hosted, multi-cloud security and compliance auditor that converts a single read-only scan into auditor-ready compliance evidence. In one pass it maps findings to eight frameworks at once: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation. Every evidence pack carries a cover-page scope attestation and SHA-256 chain-of-custody sidecars, so auditors can independently verify report integrity.

    The evidence-integrity chain is cryptographic and operator-controlled at every layer. compliance sign-pack signs one framework's chain-of-custody manifest and the artifacts it enumerates with an operator-held Ed25519 key - an authorship proof relative to your key custody, never a vendor attestation - and compliance verify-pack verifies it offline, recomputing every artifact hash the manifest lists; the same verification is reproducible with openssl alone. Suppression approvals can be signed with an operator-held Ed25519 key, and a report verifies those signatures only for approvers whose identity-registry entry carries key material. Opt-in RFC 3161 trusted timestamps bind report hashes to a Time-Stamp Authority you name - an outbound call to that authority only, with no default TSA.

    Built for Zero Data Exfiltration, NSAuditor runs entirely inside your own infrastructure using read-only APIs and offline licensing. There are no cloud uploads, no telemetry, and no SaaS backend, which means no BAA or DPA is required and your cloud credentials, findings, and configuration never leave your network. For isolated enclaves, offline CVE data travels on your terms: feed bundle packages the NVD feeds you downloaded on a connected host - optionally with your own CISA KEV and FIRST EPSS files - and feed import loads them on the isolated host. No feed or exploit data ships with the product.

    Under the hood, NSAuditor performs deep auditing across AWS, Azure, and GCP with 56 plugins, including transitive security-group reachability, IAM shadow-admin chains, KMS key custody, and backup and snapshot exposure. Offline CVE matching is joined with exploit intelligence: CISA KEV known-exploited flags and FIRST EPSS exploitation probabilities drive prioritization, from data you supply. Compliance evidence can be pushed to Vanta, Drata, or Secureframe. Delivered as a container for deployment in your own VPC, ECS, EKS, or on-premises environment, it integrates with existing pipelines so compliance evidence generation becomes a repeatable, automated step rather than a manual scramble before each audit.

    Highlights

    • One scan, eight frameworks: auditor-ready evidence packs with SHA-256 chain-of-custody for SOC 2, HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS Controls v8, GDPR Article 32, and NIST SP 800-171 Rev 2 evidence substrate for CMMC Level 2 preparation - each framework's manifest signable with an operator-held Ed25519 key and verifiable offline.
    • Zero Data Exfiltration by architecture: runs entirely inside your infrastructure with read-only APIs and offline licensing. No cloud uploads, no telemetry, no BAA or DPA required.
    • Deep multi-cloud auditing across AWS, Azure, and GCP with 56 plugins; offline CVE matching joined with CISA KEV and FIRST EPSS exploit intelligence from data you supply; compliance evidence push to Vanta, Drata, or Secureframe.

    Details

    Delivery method

    Supported services

    Delivery option
    NSAuditor AI Enterprise 0.44.0 (container)
    NSAuditor AI Enterprise 0.43.0 (container)
    NSAuditor AI Enterprise 0.42.0 (container)

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    NSAuditor AI Enterprise Edition

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Enterprise Base
    Enterprise tier, up to 5 seats
    $2,000.00
    Enterprise Growth
    Enterprise tier, up to 25 seats
    $5,000.00
    Enterprise Scale
    Enterprise tier, unlimited seats (1000)
    $10,000.00

    AI Insights

     Info

    Dimensions summary

    You pick one of three Enterprise tiers based on how many seats you need. A seat is one installation on one machine, node, or CI runner. Enterprise Base covers up to 5 seats. Enterprise Growth covers up to 25 seats. Enterprise Scale covers unlimited seats (listed as 1000). All three tiers include the same Enterprise feature set; the tiers differ only by seat capacity and the level of support you receive. Billing is contract-based and runs to your AWS account, with consolidated billing and Private Offers for custom terms.

    Top-of-mind questions for buyers

    One seat is one installation of the software on one machine. That includes a laptop, server, container image, or CI runner. It is counted per installation, not per named user. If one engineer installs it on a laptop and a build server, that counts as two seats.
    Nothing breaks at runtime. Seat enforcement is contractual, not technical, so there are no lockouts or remote check-ins. The license status command shows your seat number. If you outgrow your tier, you move to a tier with more capacity; usage is reconciled and prorated at renewal.
    All three tiers include the same Enterprise feature set. Enterprise Base adds email support and an onboarding call. Enterprise Growth adds a dedicated support channel and priority response. Enterprise Scale adds a dedicated support engineer, a 4-hour critical response window, and custom plugin development.
    www.nsauditor.com+1
    Helpful?

    Vendor refund policy

    Refunds are governed by the EULA and the applicable AWS Marketplace order terms. Except as required by AWS Marketplace policies, all fees are non-refundable. Contact support@nsauditor.com  for cancellation or refund requests.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    NSAuditor AI Enterprise 0.44.0 (container)

    Supported services: Learn more 
    • Amazon ECS
    • Amazon EKS
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    EE 0.44.0 / CE 0.2.51 - the scan you can send, over a report that states what it could not read.

    A scanner that finds things is only half a deliverable. The other half is the document you hand a client, and until now that document had to be assembled by hand. Three changes close that gap.

    1. THE REPORT YOU SEND. 'nsauditor-ai report --from --format executive' turns a completed run into one self-contained, print-ready HTML file. It opens with no external network reference of any kind - no font, no script, no analytics beacon - so it renders identically on an air-gapped laptop and in a browser online. '--brand <brand.json>' puts your own company, preparer and contact on the cover page. '--format jira' writes a Jira-importer CSV instead; the column-to-field mapping is performed by Jira's own importer and has not been verified against a live Jira instance.

    2. THE REPORT STATES WHAT IT COULD NOT READ. A scan record keeps findings in more than one place, and a report that reads only one of them can render a clean page over a populated record. 0.44.0 reads every container a finding lives in - each plugin's findings, dictionary-shaped results, zero-trust dimensions, per-port TLS issues, and the CVE/KEV/EPSS-enriched finding queue - and then runs a container census over what remains. Anything finding-shaped sitting somewhere the report does not open is named and counted on the page itself, and in a warning to the operator. Silence is disclosed, never rendered.

    3. AN AUDIT-TRAIL GAP NOW MEANS BOTH AUDIT TRAILS ARE MISSING. An S3 bucket with server access logging switched off is no longer reported as an audit-trail gap when a CloudTrail data-event trail already covers that bucket. Coverage is judged per selector against the trail's own configuration; organization trails, prefix-scoped selectors and wildcard-shaped values are refused rather than assumed, and a bucket whose coverage cannot be established keeps its finding. The result is fewer findings, and the ones that remain are real.

    Also in this release: a compliance report whose suppressed finding carried a signature that failed its check could previously still render the Approver Identity band with green markers - identity resolution was labelled as though it answered record authenticity. Those are now separate lines that each name their own population and cannot disagree silently.

    Eight compliance frameworks from one read-only scan across a catalogue of 56 plugins in total (27 Community + 29 Enterprise). Every coverage matrix is unchanged this cycle. Requires Community Edition 0.2.49 or newer.

    Additional details

    Usage instructions

    1. LICENSE KEY (once, after subscribing). Register at https://www.nsauditor.com/ai/marketplace/register/  with your email, this subscription's 12-digit AWS account ID and Agreement ID ('agmt-...', AWS Console -> Manage subscriptions). Your ES256-signed key (JWT) arrives by email. Support: support@nsauditor.com .

    2. PULL (bash). IMG=709825985650.dkr.ecr.us-east-1.amazonaws.com/nsasoft-us/nsasoft/nsauditor-ai-enterprise:0.44.0 aws ecr get-login-password --region us-east-1 | docker login -u AWS --password-stdin ${IMG%%/*} docker pull $IMG

    3. RUN with your key in NSAUDITOR_LICENSE_KEY: docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> $IMG --help

    NEW IN 0.44.0: the finished scan becomes the report you send. 'nsauditor-ai report --from <run-dir> --format executive' renders a completed run as one self-contained, print-ready HTML file that opens with no external network reference of any kind - add --brand <brand.json> for a cover page in your own name. '--format jira' writes a Jira-importer CSV instead; the column-to-field mapping is done in Jira's own importer and has not been verified against a live Jira instance. The report also states what it could NOT read: a container census walks the scan record and names, on the page, any finding-shaped record sitting somewhere the report does not open. Also in 0.44.0: an S3 bucket's server access logging being off is no longer reported as an audit-trail gap when a CloudTrail data-event trail already covers that bucket - coverage is judged per selector, and organization trails and prefix-scoped selectors are refused rather than assumed.

    1. CLOUD SCAN (read-only credentials; the scanner refuses a writable role): docker run --rm -e NSAUDITOR_LICENSE_KEY=<key> -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_REGION
      -v "$PWD/out:/out" $IMG --host aws --plugins all --compliance soc2,hipaa,pci --out /out

    2. EVIDENCE. Each run writes JSON, Markdown and HTML into --out, plus the compliance pack for every framework you name. Eight frameworks map from one read-only scan: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 (infrastructure substrate only) and NIST SP 800-171 Rev 2 (evidence substrate for CMMC Level 2 preparation - not a certification, and this product does not assess or grant one).

    3. NETWORK SCAN: replace --host aws with a host or CIDR. ECS and EKS are the supported runtimes.

    Support

    Vendor support

    Support: support@nsauditor.com  | +1-702-625-0401 | https://www.nsauditor.com/support.html 

    Enterprise Base: Email support plus an onboarding call, across the full Enterprise feature set and cloud scanners.

    Enterprise Growth: Dedicated Slack / email channel with priority response (SLA per contract) and custom compliance-mapping help.

    Enterprise Scale: A dedicated support engineer and a custom SLA (4-hour critical, 24-hour standard) plus custom plugin development.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.