NSAuditor AI EE 0.32.7 is live on npm, alongside CE 0.2.32 and agent-skill 0.2.30. It ships two kinds of honesty in one release, and it is matrix-neutral: no new framework, no new plugin, and no coverage number moves.
One scan should mean one thing everywhere
A security finding should mean the same thing in every framework it touches. Until this release, the network-scan analysis agents routed their findings to SOC 2 only. So a host serving cleartext or exposing SMB failed the SOC 2 report and read perfectly clean in the HIPAA, NIST CSF, ISO 27001, CIS v8, PCI DSS, and GDPR Article 32 reports built from the same scan. That is exactly the false-clean a multi-framework tool exists to prevent.
We drove the real agents over their full emission set and measured where findings landed: 32 finding-cells reached zero controls in a framework that already mapped the agent. A cleartext service failed SOC 2 CC6.7 and vanished from the HIPAA §164.312(e)(1) report — a Required transmission-security standard — off an identical scan.
Forty-eight rules, each adjudicated
We did not bulk-copy the SOC 2 mappings across. Every cell was adjudicated under the matching auditor lens — HHS-OCR Required-vs-Addressable, NIST CSF Subcategories, ISO/IEC 17021-1 Statement of Applicability, CIS Implementation Groups, EDPB Article 32 proportionality, and QSA cardholder scope. 48 rules were added and 4 wrong-control rules removed; 24 cells were deliberately left unrouted, each with a written reason. A new guard drives the real agents and fails the build if any emission reaches zero controls in a framework that maps its source, so this class can’t silently regress.
One boundary, stated plainly: 16 of the 48 new rules are inert today because no scanner producer yet emits the TLS-quality fields they key on. 33 fire now; the rest wait for next cycle’s producer contract. We would rather name that than let a rule count imply coverage that isn’t live.
We cut the capability claims we couldn’t back
Preparing this release, we audited every advertised Pro/Enterprise capability against the code. Six were marketed with no shipping implementation: a “Verification Engine” whose modules were throw new Error('Not implemented') placeholders, plus “branded reports,” “usage metering,” per-scan “Docker isolation,” a “ZDE policy engine,” and an “Enterprise CTEM datastore” that named no distinct engine. 0.32.7 withdraws all six — across the tier map, the marketing, and the licensing service that mints real customer licenses, verified by decoding a freshly-minted key.
Nothing real was removed: the code-enforced Zero-Data-Exfiltration read-only-credential guarantee, Pro-tier unlimited scan-history retention, and the operator suppression workflow all ship and stay claimed. What isn’t built yet is now an explicit Planned capabilities roadmap, and the stub files no longer ship.
Validated where it counts
These detections live on the network-scan path, not the cloud-scan path. The release is validated by the unit suite (9025 pass / 0 fail, mutation-checked) plus a live network scan, and the capability removal by decoding a real minted license. All seven coverage matrices are unchanged. More at the NSAuditor AI Enterprise page.




