• Platform
    Platform
    Nucleus Platform
    Scale and automate your vulnerability and exposure management program
    Vulnerability Intelligence Platform
    Access centralized and enriched vulnerability intelligence
    Nucleus Insights Intelligence Feed
    AI-powered, expert-validated threat and vulnerability intelligence
    Integrations
    Discover our ecosystem of 200+ connectors
    Capabilities
    AI Engine for Exposure Management
    Close exposure gaps and track the threat landscape
    Asset Management
    Unify asset data to automate your vulnerability and exposure management
    Vulnerability Discovery
    Surface new exploitable vulnerabilities before traditional scanners
    Risk Prioritization
    Prioritize with asset context and threat intelligence
    Vulnerability Intelligence
    Enrich vulnerability findings with real-world threat intelligence
    Vulnerability Remediation
    Automate workflows to prioritize and mitigate critical exposures
    Risk Analytics and Reporting
    Transform unified exposure data into live dashboards and automated reports
    Compliance Frameworks
    Align with compliance framework controls and requirements
  • Solutions
    Public Sector
    Federal Government
    Vulnerability and exposure management for government agencies
    State, Local, and Education (SLED)
    Centralize security and simplify compliance for state and local government
    Use Cases
    Exposure Management
    Scale and automate your exposure management program
    Risk-Based Vulnerability Management
    Address vulnerabilities with risk-based context and prioritization
    Application Security
    Shift left application security with production risk context
    Cloud Vulnerability and Exposure Management
    Conquer critical exposures across hybrid clouds
    Featured Report
    Exploitability Intelligence Gap White Paper
    Original CVE Research: The Exploitability Intelligence Gap

    Nucleus experts researched every new KEV addition between October 2025 – March 2026 and captured their observations in this exclusive report.

    GET THE REPORT
  • Partners
    Partner Program
    Program Overview
    Learn more about our growing partner program
    MSSPs
    Explore opportunities for MSSP partnerships
    Marketplaces
    Find Nucleus on leading industry marketplaces
    Partner Resources
    Partner Directory
    Explore our ecosystem of partners
    Become a Partner
    Submit your request to join our partner program
    Deal Registration
    Easily register deals with Nucleus
    Partner Portal
    Log in to our dedicated Partner Portal
    Partner Case Study
    TRUESEC
    Case Study: TRUESEC MSSP Story

    Leading European MSSP TRUESEC unified customer data, automated remediation workflows, and scaled its services in partnership with Nucleus.

    LEARN MORE
  • Resources
    Resources
    Resource Library
    Discover customer stories, reports, research, and more
    Customer Stories
    See how our customers are using Nucleus
    Blog
    Stay informed with the Nucleus Node blog
    Webinars
    Learn from industry experts and Nucleus leaders
    Events
    Meet with us virtually and in-person
    Featured Resources

    The Exploitability Intelligence Gap

    New CVE research by Nucleus Security gathered in an exclusive company white paper.

    LEARN MORE

    Gartner Exposure Assessment Platform Magic Quadrant

    Nucleus Security recognized as a Challenger by Gartner.

    LEARN MORE
    Featured Stories

    Payments Giant Automates Exposure Management

    READ MORE

    Tier 1 Airline Slashes Critical Vulnerabilities with Nucleus

    READ MORE
    Featured Articles

    Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

    READ MORE

    FBI Winter SHIELD’s Cybersecurity Controls Are Worth a Second Look

    READ MORE
    Featured Webinars

    From Directive to Deadline: Operating BOD 26-04 Webinar

    OPEN WEBINAR

    Claude Mythos: AI-Driven Vulnerability Discovery Webinar

    OPEN WEBINAR
    Featured Events

    Triangle InfoSecCon

    LEARN MORE

    CAMP IT Chicago

    LEARN MORE
  • Company
    About
    About Nucleus
    Learn more about who we are as a company
    Careers
    Explore our current openings and join the team
    News
    Read the latest news and articles
    Contact
    Contact Us
    Reach out to the Nucleus team
    Watch a Demo on Demand
    Watch our on-demand video demo
    Schedule Custom Demo
    Request a customized demo suited to your business' needs
    Pricing
    Get a quote based on your unique requirements
    Featured Content
    Omdia Tech Validation Report
    Omdia Technical Validation

    Omdia’s Technical Validation, commissioned by Nucleus, details how Nucleus helps organizations build successful vulnerability and exposure management programs.

    LEARN MORE
Watch A Demo

Security at Nucleus

Last updated: July 2026

Security Approach

At Nucleus Security, strong and accurate security is foundational to everything we do. Our founders built their careers in vulnerability management for large, data-sensitive organizations, and that discipline is embedded across our company. We understand how much our customers trust us with their data, and we are committed to transparency about the controls we use to protect our platform and infrastructure.

At the center of our program, we run NucleusΒ using our own platform to manage vulnerability workflows and analysis. That gives us continuous, first-hand confidence in the security posture of our organization and every customer instance.

Certifications & Authorizations

We maintain independent, third-party-attested certifications for the Nucleus platform, and we host on cloud infrastructure that carries its own extensive compliance portfolio.

Nucleus Platform

  • SOC 2 Type IIΒ We maintain an annual SOC 2 Type II attestation covering the security of the Nucleus, NucelusGov, and VIP platforms. Reports are available to customers and prospects under NDA via our trust portal.
  • FedRAMP Moderate AuthorizedΒ NucleusGov, our platform for government, isΒ FedRAMP Moderate AuthorizedΒ and listed on the FedRAMP Marketplace (ID: FR2134455708). We also hold multiple direct agency Authorizations to Operate (ATOs) beyond the FedRAMP authorization. Federal agencies can request access to our FedRAMP package viaΒ max.govΒ to complete their ATO process.

Our Cloud Provider

Our production environment is hosted within a cloud boundary that maintains a broad set of certifications, including (but not limited to) ISO 27001, AICPA SOC 1 & SOC 2, PCI DSS, C5, and IRAP. These apply to physical and environmental security controls as well. We work with many cloud providers and we work with you to select the appropriate hosting region so you can meet local compliance requirements.

Application Security

We use a full suite of secure software-development activities and controls. Our developers follow secure coding practices mandated in our Development Style Guide, which guides secure implementation from the start of the development lifecycle through production release.

  • All code is tested regularly with multipleΒ SAST, SCA, and DASTΒ tools, and we consolidate findings within Nucleus to leverage the strengths of each tool.
  • Every application is scanned prior to any new production release.
  • A dedicated team owns remediation of any issues discovered, tracking finding status through the Nucleus platform.
  • We conduct regular, scheduled third-party penetration tests and audits including continuous phishing simulations to validate our defenses against sophisticated attacks.

Infrastructure & Data Protection

We layer multiple controls to protect customer data:

  • Encryption at restΒ using industry best practices, for both production data and backups.
  • Encryption in transitΒ withΒ TLS 1.2+ enforcedΒ on all connections.
  • Multi-factor authentication (MFA) required on all employee accounts, with single sign-on (SSO).
  • Tenant data isolationΒ customer data is tagged and segregated by organization so only authorized users can access it, and isolation is validated annually by a third-party penetration tester. Strict separation between production, government, and dev/test enivornments.
  • Centralized logging and alertingΒ across the environment.
  • Hardened, locked-down instancesΒ with controls specifically designed to minimize attack surface.

Vulnerability Management

We practice what we sell. We conduct routine vulnerability scanning of our network and infrastructure using a variety of security tools, consolidating all findings within Nucleus. A dedicated team owns remediation and tracks status through the platform. We also participate inΒ monthly continuous monitoring (ConMon)Β reviews with our government agency customers.

Trust Center Request Documentation

We are happy to share deeper detail with customers and prospects via our trust portal (https://trust.nucleussec.com):

  • SOC 2 Type II reportΒ available under NDA
  • Penetration test attestationΒ available under NDA
  • FedRAMP packageΒ available to agencies viaΒ max.govΒ upon request

Report a security issue:Β If you believe you’ve found a vulnerability or have a security concern, please contact us atΒ [email protected]. We appreciate responsible disclosure and will respond promptly.

Contents
FedRAMP Logo, Nucleus Security FedRAMP Moderate Authorized
  • Platform
    • Platform Overview
    • Nucleus Vulnerability Intelligence Platform (VIP)
    • Nucleus Insights
    • Integrations
    • AI Engine for Exposure Management
    • Asset Management
    • Vulnerability Discovery
    • Risk Prioritization
    • Vulnerability Intelligence
    • Vulnerability Remediation
    • Nucleus Risk Reporting & Analytics
    • Compliance Frameworks
  • Solutions
    • Exposure Management
    • Risk Based Vulnerability Management (RBVM)
    • Application Security
    • Cloud Vulnerability & Exposure Management
    • Federal
    • State / Local / Education
  • Partners
    • Nucleus Partner Program
    • Managed Security Service Providers
    • Partner Portal
    • Partner Directory
    • Marketplaces
    • Deal registration
    • Become a Partner
  • Resources
    • Resource Library
    • Blog
    • Webinars
    • Events
  • Company
    • About
    • Pricing
    • Careers
    • News
    • Support
    • Contact
  • Learn More
    • AI in Vulnerability Management
    • Exposure Management Explained
    • Effective Vulnerability Management Solutions
    • TheΒ EssentialΒ Guide to Exposure Assessment Platforms

Β© 2026 Nucleus Security. All rights reserved

  • Privacy Policy
  • Vulnerability Disclosure Program

From Directive to Deadline: Operating BOD 26-04 | Register for the Oct. 27 WebinarΒ β†’