About AuditKit
One scanner that replaces $200K in compliance consulting across ten frameworks, three clouds and Microsoft 365.
What AuditKit Does
AuditKit is a multi-cloud compliance scanner. It connects to your AWS, Azure and GCP environments - and imports Microsoft 365 findings from ScubaGear - runs 675 controls, and tells you exactly what's passing, what's failing, how to fix each issue, and what evidence your auditors will ask for.
Most compliance tools stop at detection. AuditKit goes further: every failed check includes the specific CLI command to fix it, a step-by-step screenshot guide for manual evidence collection, and direct links to the relevant cloud console page.
The Community Edition covers SOC2, PCI-DSS v4.0.1, CMMC, HIPAA, NIST 800-53, NIST CSF 2.0, CIS Benchmarks, ISO 27001, FedRAMP, and GDPR with full cross-framework mappings. It reports all 110 CMMC practices, each failing check with its fix and the screen to photograph. AuditKit turns those findings into the assessor's artifact: evidence package generation, deeper automated coverage, multi-account scanning, continuous monitoring, drift detection, and a Desktop GUI.
By the Numbers
Frameworks
SOC2, PCI-DSS v4.0.1, CMMC (L1 + L2), HIPAA, NIST 800-53, NIST CSF 2.0, CIS Benchmarks, ISO 27001, FedRAMP, GDPR
Providers
AWS (228 controls), Azure (277), GCP (168), Microsoft 365 (29+ via ScubaGear import)
Output Formats
PDF, HTML (interactive), JSON, CSV, terminal. Plus evidence packages and screenshot guides.
How It Works
AuditKit uses read-only API calls to inspect your cloud configuration. It never modifies your infrastructure. The scanner runs locally on your machine, connects to your cloud provider using your existing credentials, evaluates each compliance control, and generates a report.
Each scan result maps to one or more compliance framework controls. A single check, like verifying S3 bucket encryption, simultaneously satisfies SOC2 CC6.3, PCI-DSS 3.5.1, HIPAA 164.312(a)(2)(iv) and, through the crosswalk, NIST 800-53 and ISO 27001. This cross-framework mapping eliminates duplicate work when you need multiple certifications.
All scanning happens locally. No data leaves your machine. No cloud account, no SaaS dashboard, no telemetry. The tool is a single Go binary that runs wherever you have credentials.
Built by Guardian Nexus
AuditKit is built and maintained by Guardian Nexus, a team of engineers who have been through the compliance process firsthand. The tool exists because we spent too much time and money on consultants who ran automated scans and charged five figures for the output.
The Community Edition is open source under the Apache 2.0 license. AuditKit supports the continued development of both editions and adds the advanced features that defense contractors and enterprise teams need for CMMC Level 2 and large-scale compliance programs.
Get Started
Install AuditKit and run your first compliance scan in under 5 minutes.