For an MSP or a security consultant, the hard meeting is rarely the first assessment. It is the second one, when the client asks what their money bought: did we actually get better since the last scan? NSAuditor AI Enterprise 1.1.0 and Community Edition 0.2.55, released on 28 September 2026, add delta and trend reports to the Pro and Enterprise editions, so the answer arrives as a report the client can read and keep.
The meeting every MSP knows
The client says the firewall change fixed it. The engineer says the second scan never reached that host. Two spreadsheets come out, and an hour later nobody is sure which findings were remediated and which were simply not looked at. NSAuditor AI Pro ends that meeting early, with a report that shows exactly what moved and why.
New, resolved, changed, and what could not be compared
One command compares two scan runs: nsauditor-ai report --from <dir> --format executive --since <runId|prior>. Point --from at the folder your scans write to with --out, and prior picks the run before the one you report on. You get what is new, what is resolved and what changed severity, rendered into the self-contained HTML report you hand the client.
The value is in what it refuses to do. When the report can see that a finding was not measured the same way twice, it does not mark it resolved. It files that finding under NOT-COMPARABLE, with the reason on the row: a host that was not scanned; a plugin that did not run, errored or timed out; an AccessDenied evidence gap; a port that stopped answering between the scans; or, on Enterprise cloud scans, a narrower scope such as fewer AWS regions or a different Azure subscription or GCP project.
That changes the client conversation. Every not-comparable row names its reason, which turns a dispute into a to-do list: scan the missing host, restore the permission, match the scope. Your resolved column becomes something you can stand behind in front of the client’s board.
Refusals protect your credibility
Some comparisons would mislead, so the report does not produce them. Two runs at different licence tiers are refused outright, and so are two runs that straddle a release where a reported number changed meaning. You never have to walk back a number in front of a client.
A “before” you can defend
A before-and-after is only as good as the “before”. From the first scan run on 1.1.0, each run’s record and each host’s findings files are sealed with SHA-256 digests and chained to the previous run. Both runs are verified before the comparison, and if a findings file was altered, the report names it and refuses to compare. When a client or an assessor asks how you know the baseline is the baseline, you have an answer.
Built for the way a practice works
- Client-ready HTML, with the reason on every not-comparable row.
- Read-only credentials. Nothing in the client environment is changed.
- Zero Data Exfiltration. Client scan data never goes to Nsasoft, and the product has no telemetry.
- Pricing that fits a practice. Pro is from $39 a month billed annually ($49 month to month). Enterprise, for AWS, Azure and GCP estates and eight compliance frameworks, is from $2,000 a year and is also on AWS Marketplace.
- Quick upgrade.
npm i -g nsauditor-ai@0.2.55 @nsasoft/nsauditor-ai-ee@1.1.0
Show the client the movement
Any tool can diff two scans. The hard part is refusing to call something fixed when the scanner only stopped looking. NSAuditor AI puts what it can see was not measured the same way twice on its own list, each row with its reason, so the report you put in front of a client is one you can defend.
See what changed since the last scan with Pro, for consultants and MSPs, at nsauditor.com/ai/pro/, and Enterprise at nsauditor.com/ai/enterprise/.




