Frequently Asked Questions

Product Overview & Use Cases

What is Nucleus and how does it help organizations manage vulnerabilities?

Nucleus is a unified vulnerability management platform that aggregates data from existing security tools, automates workflows, and prioritizes risks using real-world intelligence. It creates a centralized command center for vulnerability analysis, triage, and remediation, helping organizations streamline operations and improve security outcomes. Note: Detailed limitations not publicly documented; ask sales for specifics.

Who can benefit from using Nucleus?

Nucleus is designed for Security Analysts, Development and IT Teams, CISOs and Security Leadership, GRC and Compliance Teams, large enterprises, organizations in regulated industries (healthcare, finance, government), Managed Security Service Providers (MSSPs), and public sector entities including federal government and SLED (State, Local, and Education). Note: Best fit for organizations with complex infrastructures; smaller teams with limited integration needs may want to consider alternatives.

What problems does Nucleus solve for higher education institutions?

Nucleus addresses challenges such as manual vulnerability management, lack of automation, fragmented data across multiple tools, and inefficient remediation processes. In a case study, a large U.S. private university with 2,000+ employees and 10,000+ students saved countless staff hours and budget by automating VM processes, integrating with their complex security stack, and eliminating manual spreadsheets. Note: Some institutions may require custom integrations not supported out-of-the-box; check the integrations page for specifics.

Features & Capabilities

What are the key features of the Nucleus platform?

Nucleus offers vulnerability aggregation, risk-based prioritization, automation of remediation workflows, compliance framework support, POA&M automation, cloud and application security integration, asset management, and threat intelligence enrichment. The platform integrates with over 160 tools, provides customizable dashboards, and enables real-time reporting. Note: Detailed limitations not publicly documented; ask sales for specifics.

Does Nucleus support integrations with other security tools?

Yes, Nucleus integrates with over 160 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), SecurityScorecard and Censys (ASM). For a complete list, visit the integrations page. Note: Some integrations may require additional configuration; check documentation for details.

Does Nucleus offer an API for custom integrations and reporting?

Yes, Nucleus provides an API that allows users to interact with the Nucleus Database for custom dashboards, real-time reporting, and integration with third-party tools such as SIEM and SOAR. API documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise; consult documentation for implementation guidance.

Implementation & Support

How long does it take to implement Nucleus, and how easy is it to start?

Nucleus integrates with over 200 tools out of the box, enabling onboarding in hours instead of weeks. Prebuilt connectors and reusable templates simplify deployment. Customers have access to step-by-step guides, video tutorials, and a dedicated support portal. Customer Success Managers and a responsive technical support team assist with implementation and troubleshooting. Note: Implementation time may vary based on organizational complexity and integration requirements.

What technical documentation and support resources are available?

Nucleus provides API documentation (api-docs.nucleussec.com), FlexConnect Framework setup guides (help.nucleussec.com/docs/flexconnect-framework), a comprehensive help and support portal (help.nucleussec.com), and quickstart onboarding guides (help.nucleussec.com/docs/quickstart). Standard product support is included at no additional cost. Note: Some advanced features may require additional technical expertise.

Pricing & Value

How does Nucleus pricing compare to other vulnerability management solutions?

In a higher education case study, Nucleus was selected after a seven-month evaluation of 15 vendors for its competitive pricing and transparency. The university reported that Nucleus saved more on budget than competitors while offering more product features important to their needs. Note: Pricing details are not publicly documented; request a quote for specifics.

What business impact can customers expect from using Nucleus?

Customers can expect improved operational efficiency, enhanced security outcomes, cost savings, compliance support, centralized visibility, and proven ROI. For example, a Tier-1 airline reduced critical vulnerabilities by 86%, and Orange Cyberdefense reported 85% of its customers using Nucleus weekly to reduce exposure to threats. Note: Results may vary based on organizational size and implementation scope.

Security & Compliance

What security and compliance certifications does Nucleus hold?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, ensuring adherence to rigorous security requirements for cloud services used by the U.S. Federal Government. The platform also supports compliance with frameworks like NIST, FedRAMP, CISA, and PCI DSS Requirement 6. Note: Some certifications may be required for specific industries; verify applicability for your organization.

How does Nucleus protect customer data?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect the security, confidentiality, and integrity of customer data. The platform prevents unauthorized access, use, modification, or disclosure and warrants compliance with all applicable laws and regulations under its Master Service Agreement. Note: For detailed data protection policies, consult the legal documentation or contact support.

Customer Proof & Success Stories

Can you share specific case studies or success stories of customers using Nucleus?

Yes. Notable examples include Bank of Hope achieving zero critical vulnerabilities, a Tier-1 airline reducing critical vulnerabilities by 86%, a healthcare enterprise replacing Kenna and reducing its backlog from 4,000 vulnerabilities to nine critical threats, Orange Cyberdefense streamlining vulnerability management, UCSB transforming risk management, NRECA achieving centralized risk visibility, and a global health enterprise scaling risk reduction across hybrid cloud environments. For more, visit Customer Stories. Note: Outcomes depend on organizational context and implementation.

What feedback have customers provided regarding ease of use?

Customers report that Nucleus is easy to use, with intuitive automation and a smooth onboarding process. For example, a Manager of Security Architecture and Threat Management in Healthcare and Biotech described the onboarding as "one of the best" and the product as "easy to use." A SOC Operations Manager in IT Services noted the automation provides immediate value. Note: User experience may vary based on team size and technical expertise.

Performance & Metrics

What performance improvements can organizations expect from Nucleus?

Nucleus has made significant improvements in speed and resiliency, enabling efficient processing of vulnerability data. Customers have reported measurable outcomes, such as reducing critical vulnerabilities by up to 86%. Enhanced reporting and customizable dashboards allow users to track performance metrics and reveal trends in real-time. Note: Performance may depend on infrastructure complexity and integration scope.

Industry Coverage

Which industries are represented in Nucleus case studies?

Industries include banking and financial services (Bank of Hope), airlines (Tier-1 airline), healthcare (healthcare enterprise, global health organization), cybersecurity services (Orange Cyberdefense), education (UCSB), energy and utilities (NRECA), retail and consumer goods (large retailer), public sector (US State Agency), and technology (workforce management enterprises). Note: Industry-specific requirements may affect implementation; consult sales for tailored solutions.

CUSTOMER STORY

Large University Saves Countless Staff Hours and Budget Using Nucleus

Higher Education Case Study

Customer Profile

  • Large U.S. Private University
  • 2,000+ Employees
  • 10,000+ Students
  • Seeking a tool to automate VM processes and work more efficiently.
  • Interview: Vulnerability Analyst

Executive Summary

  • A large private University System in the U.S. with 2,000+ employees and 10,000 students, was seeking a tool to automate VM processes and work more efficiently.
  • The tool needed to integrate with a complex security stack with many embedded solutions, while eliminating manual processes and spreadsheets.
  • Following 7 months of vendor evaluations across 15 tools, the University concluded that Nucleus best met the criteria, ‘playing nicely’ with all integrations, offering superior asset flexibility, and at a more reasonable cost than other contenders.
  • The decision to onboard Nucleus saved the University countless man-hours and budget dollars, surpassing expectations by partnering closely with stakeholders to build the program they needed in the context of their security ecosystem.

The Challenge

“Our biggest challenge prior to adopting Nucleus was the sheer volume of manual work and complete lack of automation.”

Like many organizations, the University security team struggled to effectively manage their vulnerability data, leaning heavily on scanners while manually compiling results into a spreadsheet before working to remediate. This process was labor-intensive, taking several hours to compile each scan and format data into a manageable workbook. To compound the issue, the analysts had no easy way to port notes from previous workbooks over to the fresh scan results, often relying on memory alone.

“We knew there had to be a better, more efficient method of compiling data, tracking, and remediating vulnerabilities.”

Evaluation and Evolution

“There was maybe one other platform that deserved consideration. But, they were so unrealistically expensive, even for an enterprise of our size to pay, it made no sense.”

Determined to find a tool that could offer effective automation and save precious man-hours, the security team set out on a comprehensive vendor review, compiling a list of 15 solutions across both established and newer-to-market vendors. Across seven months, the team dove deep into the capabilities of each, heavily weighting four key components:

  • Integrations
  • Flexibility
  • Price
  • Customer Service

Integrations. A key tenet to their search, the University was already invested in several scanning and security solutions that they wanted to maintain. They quickly learned many of the prospective vendors offered scanning capabilities of their own, which the University would be forced to adopt instead.

“Nucleus was one of the few solutions we looked at that ‘played well’ with everyone and was not going to force us to use one product over another.”

Flexibility. Another key point for Nucleus: flexibility with assets. The University wanted to leverage data from their entire suite of tools, while having plasticity to shape prioritization based on their unique business context.

“With Nucleus, we were able to adjust risk scores of assets, change criticality of vulnerabilities, and keep notes on our individual assets in a form other than a tag. We needed that.”

Pricing. While functionality was paramount to pricing, the University remained budget conscious. Finding that prices varied wildly from vendor to vendor, they were pleasantly surprised with the transparency and affordability of Nucleus, without sacrificing functionality.

“Being a higher educational institution, budget is always a concern. Nucleus was competitive in its pricing, saving us more on budget than its competitors, while offering more product features that were important to us.”

Customer Service. As a final key component to the evaluation, the University valued collaboration and wanted a partnership to help evolve their vulnerability management program, recognizing that ‘cookie-cutter’ wasn’t going to be the right approach.

“Customer service is a big focus for us, and Nucleus has exceeded our expectations. From the early stages of product demo, they were clear in what their product could and could not do and letting us know what was on their roadmap. Many companies will promise you the world to get you in the door and leave you hanging after. The team at Nucleus continue to this day to follow up to see how things are going and to address any issues.”

The Results

Nucleus is now the central source of data for “everything” at the enterprise’s security operations, and has expanded in scope and adoption into other business units. By having a complete picture of their assets in one shared platform, developers can better prioritize their work while also giving product managers insight and focus to optimize the security posture of their product.

“We set out to give power to the developers to visualize their data. We really wanted to remove the smoke and mirrors and put the security data directly in their hands without a middleman. Nucleus helped transform everyone into one large team, where everyone feels accountable for security.”

Nucleus helped shift the culture by bringing vast sets of data from disparate tools into a central hub and giving users that information across function. Using the Nucleus platform for unified vulnerability management enabled the enterprise to get vital security information out from behind the curtain of the security team and into the hands and desktops of the developer team. Developers now take direct responsibility for security in their area and can act on the information in their lane.

“Nucleus cares and wants to build with you as a customer. I wish I would’ve found them sooner!”

Want to See Nucleus in Action?

Watch our demo on-demand.