NSAuditor AI Enterprise 0.32.10: Verified Instruments, Auditor-Ready Evidence

NSAuditor AI EE 0.32.10 is live: full 51-criterion SOC 2 enumeration, customer-closure dependency measurement, 28 cloud plugins, seven frameworks, Zero Data Exfiltration.

nsauditor-ai-enterprise-0-32-10-verified-instruments-auditor-ready-evidence

Every security tool tells you it is clean. Very few tell you what “clean” was measured against. Nsasoft US LLC has released NSAuditor AI Enterprise Edition 0.32.10 (with Community Edition 0.2.35 and agent-skill 0.2.33, published in lockstep) — a release built entirely around that question, and around a simple commitment: the instruments we point at your infrastructure are held to the same standard as the instruments we point at our own.

Why this matters to a security buyer

When an auditor asks where a number came from, “the tool said so” is not an answer. The value of a compliance evidence pack is entirely a function of whether its method is inspectable. NSAuditor AI Enterprise is built for that moment: one agentless, read-only pass across AWS, Azure and Google Cloud produces seven auditor-ready evidence packs, each artifact carrying a SHA-256 chain of custody so an assessor can verify independently that the report bytes are unchanged since the scan wrote them.

0.32.10 extends that discipline into the release pipeline itself.

1. The dependency gate now measures the package a customer installs

NSAuditor ships a release gate that checks its own third-party dependency closure for known advisories before any build reaches a customer. In 0.32.10 that gate builds its own subject rather than assuming one: it packs the release tarball, installs it plus the declared Community Edition peer into an empty directory exactly the way a customer would, and audits there.

The result on the shipped 0.32.10 bytes: zero critical and zero high-severity advisories in the customer install. That figure was re-derived from a real global install of the published packages, not transcribed from a previous run — and because the closure re-resolves from the registry on every run, the gate prints a package-for-package divergence block each time rather than asking anyone to trust a total.

This is the same principle NSAuditor applies to cloud posture: a number without its subject is not a measurement. Totals that agree are exactly what makes two different lists read as one.

2. A clean verdict now requires that something actually answered

The gate carries a pinned canary — a package with a permanently published advisory that must come back before the run will report anything at all. If the canary is silent, the run exits as untrustworthy: not clean, not dirty. It also names which advisory source answered and flags any non-public registry mirror, because proving a source is live is not the same as proving it is current.

Security teams will recognise the failure mode this closes. A zero from a source that answered nothing is silence, and silence must never render as safety. NSAuditor already applies this rule to scanning — a cloud plugin that cannot enumerate emits a fail-closed evidence gap into the auditor’s document instead of reading clean. Now the release pipeline obeys it too.

3. SOC 2 coverage, enumerated in full: 51 of 51

The SOC 2 coverage matrix is now enumerated across the complete AICPA Trust Services Criteria universe: 10 covered, 4 partial, 37 out of scope — 51 of 51, with every out-of-scope criterion carrying a written architectural reason.

This is enumeration completeness, not a coverage change: no control changed status and no routing changed. Four criteria had previously been neither claimed nor explicitly excluded. An auditor is entitled to the whole universe and the reasoning that places each criterion in it — not the flattering subset. Every framework file is now pinned against an independently held universe constant, so a future omission fails the build rather than shipping quietly.

The other six frameworks are unchanged in this release.

What NSAuditor AI Enterprise delivers

  • Seven frameworks from one read-only scan — SOC 2 (AICPA TSC), HIPAA §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, and GDPR Article 32 infrastructure substrate.
  • 28 enterprise cloud-audit plugins across AWS, Azure and GCP — IAM, storage, encryption, network perimeter, logging and workload services — 55 in total alongside the Community Edition plugin set.
  • Agentless and read-only — nothing to install in the estate under assessment; read-only credential enforcement is gated in CI, not asserted in a policy document.
  • SHA-256 chain of custody on every artifact in the evidence pack, plus a cover-page scope attestation.
  • Zero Data Exfiltration by architecture — no telemetry, no SaaS backend, no vendor-side copy of your evidence. Credentials, findings and reports stay inside your network. Offline licence validation means no phone-home.
  • Deploy anywhere — npm, your own VPC, ECS/EKS, Kubernetes, on-premises, or fully air-gapped. Opt-in push of findings to Vanta, Drata and Secureframe for teams already running a GRC platform.

Availability

NSAuditor AI Enterprise Edition 0.32.10 and Community Edition 0.2.35 are live now:

npm install -g nsauditor-ai @nsasoft/nsauditor-ai-ee

Enterprise licensing, the full capability matrix and a sample evidence pack: https://www.nsauditor.com/ai/enterprise/. The Enterprise listing is also available for procurement through existing AWS Marketplace commitments.

About Nsasoft US LLC — Nsasoft builds network and cloud security auditing software used by security teams, MSSPs and compliance practitioners. NSAuditor AI maps infrastructure findings to seven compliance frameworks entirely inside the customer’s own infrastructure.