What Did That Scan Actually Examine? NSAuditor AI Enterprise 0.43.0 Puts the Answer on the Face of the Report

Ask a security team what their last cloud scan covered and you will usually get a list of accounts. Ask an auditor the same question and they want something narrower: which providers were actually examined, which controls were actually evidenced, and where the boundary of the evidence sits. NSAuditor AI Enterprise 0.43.0, released by Nsasoft US LLC on 2 September 2026, answers that question on the face of the report. The release principle is three words long: silence is not a pass.

Three things you now see, and why each one matters

1. The provider that was not scanned is named, with a reason

A scan across AWS, Azure and GCP produces a provider summary. In 0.43.0 a cloud whose scanner did not run — a missing dependency, an absent credential, a plugin outside the requested scope — is reported as NOT audited, with the reason, and its findings are absent rather than empty. The audited-provider list names only clouds that were scanned; compliance verdicts keep failing closed over any surface that was not. The two causes are labelled distinctly, plugin skipped versus scanner error, because one is fixed by widening scope and the other by fixing an environment.

2. Evidence gaps read like evidence, not like a terminal

When a control could not be evidenced, its gap sentence now states the cause. Remediation instructions for the operator live on the operator channel instead of in the prose an assessor reads. For teams running air-gapped or restricted environments this is the difference between a report that reads cleanly and one that tells an assessor to run a public-registry install the environment does not permit.

3. The air-gap carrier is the build that was tested

The restricted offline carrier is pinned to the dependency versions the test suite runs against. Consecutive builds are byte-identical, verified in an isolated container with the network interface down and zero outbound attempts recorded. Vulnerability data travels separately through feed bundle and feed import over the NVD files you downloaded yourself; that bundle is integrity-checked, not authenticated.

Smaller changes with the same intent

The “Why this violates” rationale line is cleaner across four framework files in Markdown, HTML and JSON. A GDPR Article 32 assessment — Security of Processing infrastructure substrate only, not GDPR compliance — fails closed when an Azure scan refuses. And the frozen interface record, docs/contract-v1.md §1.3, documents the envelope liveness keys the compliance engine’s fail-close reads, so integrators can see the contract rather than infer it.

What is unchanged, deliberately

Eight frameworks from one agentless, read-only scan: SOC 2, HIPAA §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 (infrastructure substrate only) and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation. 29 Enterprise auditors — 28 cloud auditors plus one Zero Trust posture check — and 56 plugins overall. All eight coverage matrices are unchanged: 0.43.0 adds no coverage claims; it makes the existing ones impossible to misread. Zero Data Exfiltration — the scan runs entirely inside your infrastructure, with every outbound path enumerated and opt-in.

Enterprise 0.43.0 pairs with Community Edition 0.2.50 and the agent-skill package 0.2.48, requires Community Edition 0.2.49 or newer, and is the 103rd consecutive paired release. Product details and a full sample scan: nsauditor.com/ai/enterprise/.