Your Cloud Scan Now Reports What It Did Not Check: Inside NSAuditor AI Enterprise 0.32.11
NSAuditor AI Enterprise 0.32.11 adds full-visibility cloud scan reporting, a dedicated scope channel and a compliance_matrix MCP tool across seven frameworks.
Ask any experienced assessor what separates a scan report they can rely on from one they cannot, and the answer is rarely about detection depth. It is about boundaries. A report that lists forty findings and says nothing about the estate it never touched leaves the reader to guess at the denominator — and guessing is exactly what an audit is supposed to eliminate.
NSAuditor AI Enterprise 0.32.11, released 5 August 2026 alongside Community Edition 0.2.36 and agent-skill 0.2.34, is built around that distinction. Multi-cloud scanning across AWS, Azure and GCP now reports the full picture in one place: what was found, what could not be verified, and what this release deliberately does not evaluate — three different statements, given three different labels.
Full-visibility severity reporting
The cloud scan summary now carries the complete severity spectrum, including the INFO tier, and rolls INFO records up by category rather than listing them flat. On a real AWS account, a single conclusion line now reads:
Cloud scan (AWS): 177 findings — 10 CRITICAL · 53 HIGH · 42 MEDIUM
· 10 LOW · 62 INFO · 8 evidence-gaps (unverified).
Sixty-two INFO records is not noise. It is context: configuration facts, posture observations and the scanner’s own statements about the edges of its coverage. Rolled up by category, that tier becomes a readable section of the report instead of a wall of rows — and it is now present on both surfaces, the assistant-facing MCP summary and the command-line evidence table.
A dedicated channel for scope
The sharper addition is a separate channel with its own badge:
[🔎 SCOPE NOT ASSESSED]
aws:s3-access-points — S3 access-point scan scope: standard access
points are evaluated; Multi-Region Access Points and Object Lambda
Access Points are not.
This is intentionally not the evidence-gap badge. “I attempted this and could not verify it on this run” and “this release does not evaluate this surface at all” are different claims with different remediation paths, and an assessor needs to tell them apart at a glance. On the same live AWS run, nine scope declarations were surfaced by name and quoted verbatim, sitting beside eight evidence gaps — distinct counts, distinct labels, one report.
For a compliance team, the practical effect is that the scope section of a pre-audit package writes itself. The tool states its own boundaries in the artifact, so nobody has to reconstruct them from memory in a control walkthrough.
The coverage matrix, on demand
0.32.11 adds a new MCP tool, compliance_matrix, which returns the shipped coverage matrix for any of the seven supported frameworks. For SOC 2 that is 10 covered, 4 partial and 37 out of scope across the full 51-criterion AICPA Trust Services Criteria universe — enumeration-complete, with the denominator stated rather than implied.
Two design choices matter here. The numbers are derived from the shipped framework data at call time, not written into a string somewhere that can drift from the engine. And the tool fails closed: if it cannot read that data, it declines to answer rather than returning an empty or partial matrix. In an era where buyers, auditors and AI assistants all ask coverage questions in natural language, having one authoritative machine-readable answer is a governance feature in its own right.
Deeper GCP firewall analysis
The Google Cloud firewall auditor gained three verdict improvements in this release. A rule whose direction field cannot be read is now reported per rule, by name, instead of being passed over. A scan with no resolvable project now returns an explicit not-reachable state rather than a successful empty result. And an explicit deny-all-ingress rule — a hardening control — is now read correctly as the control it is. Each new per-rule condition is anchored in all seven frameworks, so it appears wherever the customer is reporting.
Capabilities that describe themselves
Every licensed capability now ships a written description, printed by license --capabilities. Eighteen capabilities, eighteen sentences of plain English. It is a small change with an outsized effect on procurement conversations: a licence is now self-documenting, and there is no gap between the flag list and what the flags mean.
Verified on the bytes customers download
Every claim above was confirmed against the published packages, not a development branch: a global install of the real tarballs, the MCP validation battery re-run against those installed bytes, and a live three-cloud smoke run in which every measured framework matched the previous release’s baseline exactly — the predicted result for a release that improves presentation and verdict accuracy without changing detection routing.
What has not changed
All seven coverage matrices are unchanged, and the plugin count stays at 28 Enterprise cloud-audit plugins (55 including Community Edition). Zero Data Exfiltration remains the architecture: cloud credentials, findings and configuration never leave your network. No telemetry, no SaaS backend, no phone-home, and licence validation is local. Scanning is agentless and runs on read-only credentials.
Availability
Community Edition installs with npm install -g nsauditor-ai. Enterprise licensing, the full capability matrix and framework documentation are at nsauditor.com/ai/enterprise.
NSAuditor AI maps infrastructure findings to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32 — running entirely inside the customer’s network.



