NSAuditor AI Enterprise 0.35.0 — Suppression Approvals Get a Command Line

LAS VEGAS, NV — 12 August 2026. Nsasoft US LLC has released NSAuditor AI Enterprise Edition 0.35.0 alongside Community Edition 0.2.40 and agent-skill 0.2.38 — the 93rd consecutive paired release. It gives the suppression-approval workflow an entry point an operator can reach.

The question that ends audits badly

Your auditor doesn’t ask what you fixed. They ask what you accepted.

Every team suppresses findings, and most of those decisions are correct: a false positive, a compensating control, a risk the business consciously owns. What is usually missing is a durable record — who accepted it, on what grounds, when, and until when. A ticket comment is not that record, and neither is a spreadsheet row nobody revisits.

What ships

Four commands: compliance suppress, compliance review, compliance renew and compliance keygen.

  • suppress records the decision with an owner, a rationale, a date and an expiry.
  • review lists what is about to lapse — so an accepted risk resurfaces on your schedule, not in someone else’s findings report three days before fieldwork.
  • renew extends a decision, and states plainly what that does to the record.
  • keygen creates the approval keypair, writes the private half 0600, and prints an identity-registry entry ready to paste. It refuses to overwrite an existing signing key — regenerating one would make every signature that key already produced unverifiable, and nothing would report it until an assessor met the mismatch on an archived approval that was correct when written.

Every accepted risk now has a name, a date and an expiry.

Ed25519 suppression signing is reachable and not yet provencompliance suppress signs the approval it writes when NSAUDITOR_SIGNING_KEY names a local signing key, and its verification gate has not yet run against the published bytes of this release. That distinction is published rather than rounded up. The always-on evidence-integrity layer remains the SHA-256 chain of custody, which verifies offline.

Unchanged in this release

Plugin catalog unchanged at 28 Enterprise plugins — 27 cloud auditors across AWS, Azure and GCP plus one Zero Trust posture assessment scored from a network-host scan, 55 in total with Community Edition’s 27. All seven compliance coverage matrices unchanged: SOC 2, HIPAA §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32 infrastructure substrate. RFC 3161 trusted timestamping remains opt-in via NSAUDITOR_TSA_URL, with no default ever.

Availability

npm install -g nsauditor-ai@latest @nsasoft/nsauditor-ai-ee@latest nsauditor-ai-agent-skill@latest

Enterprise 0.35.0 requires Community Edition 0.2.40 or newer — the approval commands live in the Community Edition and forward to Enterprise, so an older Community install cannot reach them. Community Edition is free and MIT-licensed on npm as nsauditor-ai; Enterprise is private and licensed per seat.

Everything runs on the operator’s own machine: agentless, read-only scanning, with reports written to the customer’s own directory.

More: https://www.nsauditor.com/ai/enterprise/