AuditKit Community Edition
Free, open-source multi-cloud compliance scanner. Apache 2.0.
SOC2
PCI-DSS
CMMC L1 + L2 (all 110)
HIPAA
CIS Benchmarks
NIST 800-53
NIST CSF 2.0
ISO 27001
FedRAMP
GDPR
Installation
# Download a prebuilt binary from the Releases page
# https://github.com/guardian-nexus/AuditKit-Community-Edition/releases
tar xzf auditkit-linux-amd64.tar.gz
mv auditkit-linux-amd64 auditkit && chmod +x auditkit
# Or build from source
git clone https://github.com/guardian-nexus/AuditKit-Community-Edition.git
cd AuditKit-Community-Edition/scanner && go build ./cmd/auditkit
# Run your first scan
./auditkit scan -framework soc2 -format pdf -output report.pdf
Requires Go 1.24+ and read-only cloud credentials. See the documentation for cloud-specific setup guides.
See It In Action
$ auditkit scan -provider aws -framework soc2 -verbose
# Scanning 38 SOC2 criteria across AWS...
✗ FAIL | CC6.6 | MFA Not Enforced
Evidence: 3 IAM users without MFA: admin-user, deploy-bot, john.doe
Remediation: aws iam enable-mfa-device --user-name admin-user
Screenshot: IAM → Users → Security credentials → Show MFA enabled
Console URL: https://console.aws.amazon.com/iam/home#/users
✓ PASS | CC7.1 | CloudTrail Logging Enabled
Evidence: CloudTrail enabled in all regions, logs encrypted
Frameworks: SOC2 (CC7.1), PCI-DSS (10.2.1), HIPAA (164.312(b))
# Automated Check Score: 27.4% (23/84 passed)
# All 189 controls reported: 84 checked automatically (scored above), the rest with evidence-collection guidance
# PDF report: compliance-report.pdf
Every failed check includes the specific CLI command to fix it, a step-by-step screenshot guide for manual evidence collection, and a direct link to the relevant cloud console page.
Resources
- GitHub Repository: source code, issues, discussions
- Documentation: getting started, CLI reference, framework guides, cloud setup
- Quick Start Guide: first scan in 5 minutes
Need the assessor's evidence package, deeper automated coverage, or continuous monitoring? AuditKit turns your findings into the artifact a C3PAO asks for - and adds multi-account scanning, drift detection, and more.