Frequently Asked Questions

Product Information

What is Nucleus and what does it do?

Nucleus is a unified vulnerability management platform that aggregates vulnerability data from existing security tools, centralizes analysis, triage, and remediation, and automates workflows. It prioritizes risks using real-world intelligence and helps organizations align with compliance frameworks. The platform is designed for enterprises and government agencies seeking to streamline vulnerability discovery and remediation. Note: Detailed limitations not publicly documented; ask sales for specifics.

What products and services does Nucleus offer?

Nucleus offers the Vulnerability Intelligence Platform (VIP), which aggregates vulnerability data, prioritizes risks, and automates remediation workflows. Additional tools include Nucleus Insights (an AI-powered intelligence feed) and the MCP Server for advanced data interaction. Nucleus also provides tailored solutions for exposure management, risk-based vulnerability management, application security, and cloud vulnerability & exposure management, as well as sector-specific offerings for federal government and SLED (State/Local/Education). Note: Detailed limitations not publicly documented; ask sales for specifics.

Features & Capabilities

What are the key features and capabilities of the Nucleus platform?

Nucleus provides vulnerability aggregation from multiple tools, risk-based prioritization using asset context and threat intelligence, automation of remediation workflows (including ticketing and ownership assignment), compliance framework automation (NIST, FedRAMP, CISA), POA&M automation for public sector, cloud and application security integration, asset management, and AI-powered threat intelligence enrichment. Note: Best fit for organizations needing centralized vulnerability management; teams requiring highly specialized or niche integrations may want to confirm compatibility.

What new features were introduced in the Q2 2025 product update?

The Q2 2025 update introduced Custom Dashboards for tailored visibility, the Fixes Page for prioritizing fixes by risk reduction, enhanced reporting with SLA tracking by fix group, and expanded API and automation capabilities including the Rule Accuracy Tester, Bulk Asset Metadata API, and improved developer onboarding with Live API Docs. Note: Some advanced features may require additional configuration or API familiarity.

Does Nucleus offer integrations with other security tools?

Yes, Nucleus integrates with over 200 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), and SecurityScorecard and Censys (ASM). For a full list, visit the Nucleus integrations page. Note: Integration depth may vary by tool; confirm specific requirements with Nucleus support.

Does Nucleus provide an API for custom integrations and reporting?

Yes, Nucleus offers an API that enables users to interact with the Nucleus Database for custom dashboards, real-time reporting, and integration with SIEM, SOAR, and other security tools. The API supports building dashboards in PowerBI or Tableau and provides real-time updates. API documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise for setup and maintenance.

Performance & Implementation

How quickly can Nucleus be implemented and how easy is it to start?

Nucleus can be onboarded in hours instead of weeks, thanks to over 200 out-of-the-box integrations, prebuilt connectors, and reusable templates. The platform features an intuitive interface and automation, with step-by-step guides, video tutorials, and a dedicated support portal. Customer Success Managers and a responsive technical support team assist with implementation and ongoing support. Note: Actual onboarding time may vary based on environment complexity and integration needs.

What performance improvements does Nucleus offer?

Nucleus has enhanced platform speed and resiliency, enabling efficient processing of vulnerability data. Automation and integration with over 200 tools support quick onboarding and reduced operational strain. Customizable dashboards and reports allow real-time tracking of performance metrics. Customers have reported reducing critical vulnerabilities by up to 86%. Note: Performance may depend on data volume and integration complexity.

Security & Compliance

What security and compliance certifications does Nucleus have?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, meeting rigorous security requirements for cloud services used by the U.S. Federal Government. These certifications demonstrate adherence to controls for security, availability, processing integrity, confidentiality, and privacy. Note: For organizations requiring additional certifications, contact Nucleus for the latest compliance status.

How does Nucleus protect customer data and support compliance?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect customer data. The platform automates compliance framework controls for standards like NIST, FedRAMP, and CISA, and supports PCI DSS Requirement 6. Under its Master Service Agreement, Nucleus warrants compliance with applicable laws and regulations, including breach notification laws. Note: For detailed compliance mappings, consult Nucleus documentation or support.

Use Cases & Benefits

What problems does Nucleus solve for organizations?

Nucleus addresses challenges such as scattered vulnerability data, ineffective risk prioritization, manual and error-prone remediation workflows, complex compliance requirements, inefficient POA&M management, exposure management across hybrid cloud environments, and integrating production risk context into application security. Note: Organizations with highly unique or legacy systems should verify compatibility with Nucleus integrations.

What business impact can customers expect from using Nucleus?

Customers can expect improved operational efficiency through automation, enhanced security outcomes via risk-based prioritization, cost savings, simplified compliance, centralized visibility, and proven ROI. For example, some customers have reduced critical vulnerabilities by up to 86%, and service providers like Orange Cyberdefense report 85% of their customers use Nucleus weekly to reduce exposure. Note: Results may vary based on organizational maturity and implementation scope.

Who is the target audience for Nucleus?

Nucleus is designed for security analysts, development and IT teams, CISOs and security leadership, and GRC/compliance teams. It is used by organizations in regulated industries (healthcare, finance, government), large enterprises, MSSPs, and public sector entities (federal, state, local, education). Note: Smaller organizations with limited security resources may want to assess fit based on their scale and needs.

What industries are represented in Nucleus customer case studies?

Industries include banking and financial services (e.g., Bank of Hope), airlines (Tier-1 airline), healthcare (global health organization), cybersecurity services (Orange Cyberdefense), education (UCSB), energy and utilities (NRECA), retail and consumer goods (large retailer), public sector (US State Agency), and technology (workforce management enterprises). For more, see the Customer Stories page. Note: Industry-specific requirements may affect implementation details.

Can you share specific customer success stories using Nucleus?

Yes. Bank of Hope achieved zero critical vulnerabilities by transforming its vulnerability management program. A Tier-1 airline reduced 86% of critical vulnerabilities. A healthcare enterprise replaced Kenna with Nucleus, reducing its backlog from 4,000 to nine critical threats. Orange Cyberdefense streamlined vulnerability management and drove higher customer engagement. For more, see the Customer Stories page. Note: Outcomes depend on customer engagement and implementation scope.

Support & Technical Documentation

What technical documentation and support resources are available for Nucleus?

Nucleus provides comprehensive API documentation (api-docs.nucleussec.com), setup guides for the FlexConnect Framework, a help and support portal (help.nucleussec.com), and quickstart onboarding guides. Standard product support is included at no extra cost, with access to a dedicated support portal and responsive technical support. Note: Some advanced documentation may require registration or support contact.

What feedback have customers given about the ease of use of Nucleus?

Customers have described Nucleus as easy to use, with a smooth onboarding process and intuitive automation. For example, a Manager of Security Architecture in Healthcare said, "After purchasing, they offered one of the best onboarding/implementations I’ve worked with, and the product is easy to use." A SOC Operations Manager in IT Services noted, "The automation is very easy to navigate and provides immediate value." Note: User experience may vary based on organizational processes and user familiarity.

Enterprise-Grade Automation, Communication, and Risk: Nucleus Q2 Updates

Rob Gibson
August 13, 2025
Product Updates
Nucleus Q2 Product Update

This release raises the bar for enterprise-grade vulnerability and exposure management. We’re delivering on the promise of smarter, faster risk reduction powered by automation, enriched data, and operational depth. From fix-level SLA tracking to scalable API workflows and stakeholder-ready reporting, every enhancement is designed to help teams do more with less, and prove it. 

Here’s a breakdown of some of the major product updates from Q2 2025. 

Custom Dashboards: Visibility That Adapts to You 

Security leaders need to track key performance metrics including: SLA adherence, team performance, ticketing gaps, and risk trends. With the GA release of Custom Dashboards, you can build and share tailored views across teams and roles. It’s powerful, integrated intelligence designed to improve communication, collaboration, and security outcomes. 

  • Dashboards for every level. Build executive dashboards with visibility into vulnerability discovery and remediation trends, SLA adherence, MTTR, and more — automatically filtered by business unit, team, or user with built-in access control. 
  • Cross-team performance at a glance. Compare teams by MTTR, open risk exposure, SLA compliance, risk scores and more — enabling security leaders to drive measurable outcomes. 
  • Ticketing intelligence. Visualize the lifecycle of remediation with charts showing tickets by stage and over time. Surface vulnerabilities without assigned tickets. 
  • Admin control and sharing flexibility. Admins can now set default dashboards per role, while users can create and share private or team-wide views. 
  • Built for speed and scale. Dashboards remain responsive, up-to-date, and accurate, even across massive datasets.
Custom Dashboard Trends
Identify vulnerability trends by severity, SLA compliance, and more.
Custom Dashboard
Tailor your Nucleus dashboards to target the details most important to you.

Fixes Page: Prioritize Fixes That Reduce the Most Risk 

Remediation requires more than one strategy. Fixing critical issues reduces immediate risk, but can leave behind long-tail vulnerabilities that grow your security debt.  

The Fixes Page helps teams work smarter. It groups vulnerabilities by shared fix and ranks them by the percentage of total risk each fix reduces. The result is a clear, prioritized list of upgrades that align with IT processes and deliver meaningful risk reduction in the most efficient manner possible, maximizing risk-reduction for effort. 

  • Prioritize by impact, not noise. Get a ranked list of fixes showing the percent of total risk each fix eliminates — making it easy to choose the most effective actions first. 
  • Consolidate effort to burn down risk. Group vulnerabilities by shared fix (e.g., “openssl-1.0”) to streamline patch planning, reduce duplicate work, and align to real-world patch cycles. 
  • Track SLA performance by fix. Monitor SLA adherence based on fix-level remediation, not just CVEs — reflecting how teams actually remediate in practice. 
  • Shift from urgent to strategic. Break out of reactive triage. Identify the biggest opportunities to reduce long-tail risk and burn down security debt over time.
Nucleus Fixes Page
Identify risk and the number of asset vulnerabilities that can be remediated by a given action.

Reporting Enhancements: Communicate and Track Progress 

Reporting isn’t just about data, it’s about delivering the right insights to the right audience. This quarter’s updates help teams automate, customize, and scale how they share vulnerability management performance. These enhancements help security teams stay accountable, demonstrate progress, and communicate outcomes more effectively. 

  • Track SLA performance of group fixes. Measure SLA compliance based on fix-version groupings, aligning reporting with how remediation is actually executed — not just CVE-level snapshots. 
  • Provide consistent, actionable metrics for leadership. MTTR, MTTD, and other key indicators are now available across dashboards and reports, supporting clear, confident decision-making. 

API & Automation: Build Once. Scale Everywhere. 

As vulnerability and exposure management programs mature, so does the need to automate more, with control. This quarter, we introduced new capabilities to help teams trust their automation, enrich data pipelines, and orchestrate at scale — all without increasing noise or complexity. 

Here’s how customers are putting these updates to work: 

  • Test automation before going live. Validate rule logic against real findings with the new Rule Accuracy Tester before deploying, avoiding ticket floods and false positives. 
  • Bulk enrich assets with context. Use the new Bulk Asset Metadata API to update metadata and trigger processing at scale — ensuring ownership, tags, and business context are always accurate. 
  • Automate tenant and project provisioning. MSSPs and large enterprises can now programmatically spin up projects via API to accelerate onboarding and standardize operations. 
  • Faster developer onboarding. Swagger-powered Live API Docs now include inline copy, sample payloads, and syntax highlighting to streamline custom integrations. 
  • Precision filters for GRC and analytics. Enhanced findings API filters make it easy to power internal dashboards, risk registers, or acceptance workflows based on granular attributes. 

Looking Ahead 

These releases mark critical progress on our mission to unify and automate exposure management. But we’re not stopping here. Expect continued improvements to dashboards, deeper remediation intelligence, and AI-infused insights in the coming months. 

Want a walkthrough of the new capabilities? Schedule a demo.

Rob Gibson
Rob is the VP of Product for Nucleus, responsible for implementing the company's product strategy and managing the teams involved in developing our innovative vulnerability and exposure management platform.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.