Frequently Asked Questions

Product Overview & Use Cases

What is Nucleus and how does it help with vulnerability management?

Nucleus is a unified vulnerability management platform that aggregates data from your existing security tools, creating a centralized command center for vulnerability analysis, triage, and remediation. It automates workflows, prioritizes risks using real-world intelligence, and helps organizations align with compliance frameworks. Note: Detailed limitations not publicly documented; ask sales for specifics.

What are the main use cases supported by Nucleus?

Nucleus supports use cases including Exposure Management, Risk-Based Vulnerability Management (RBVM), Application Security (with production risk context), Cloud Vulnerability & Exposure Management, and POA&M compliance for federal and SLED organizations. Note: Best fit for organizations needing centralized vulnerability management; teams seeking niche application security features may want to evaluate alternatives.

Features & Capabilities

What features does Nucleus offer for vulnerability prioritization?

Nucleus uses asset context and real-world threat intelligence—including CISA KEV, Mandiant, and CVSS—to prioritize vulnerabilities. It supports Stakeholder-Specific Vulnerability Categorization (SSVC) and automates remediation workflows with integrations to ServiceNow, Jira, and other ticketing systems. Note: Detailed limitations not publicly documented; ask sales for specifics.

How does Nucleus automate vulnerability remediation?

Nucleus automates remediation workflows by integrating with ticketing systems like ServiceNow and Jira, assigning ownership, and tracking progress. It enables organizations to prioritize remediation based on CISA KEV and other threat intelligence sources. Note: Automation may require configuration for complex environments; consult technical documentation for specifics.

What integrations are available with Nucleus?

Nucleus integrates with over 160 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), SecurityScorecard and Censys (ASM). For a complete list, visit Nucleus Integrations. Note: Some integrations may require additional setup or licensing.

Does Nucleus offer an API for custom integrations and reporting?

Yes, Nucleus provides an API for interacting with the Nucleus Database, enabling custom dashboards and reports in tools like PowerBI or Tableau, integration with SIEM/SOAR, and real-time updates. API documentation is available at Nucleus API Docs. Note: API usage may require technical expertise and proper authentication.

Performance & Implementation

How quickly can Nucleus be implemented?

Nucleus integrates with over 200 tools out of the box, enabling onboarding in hours instead of weeks. Prebuilt connectors and reusable templates further reduce deployment time. Note: Implementation speed may vary based on environment complexity and integration requirements.

What improvements have been made to Nucleus's performance?

Nucleus has enhanced platform speed and resiliency, enabling efficient processing of vulnerability data and minimizing interruptions. Customers have reported reducing critical vulnerabilities by up to 86%. Note: Performance may depend on infrastructure and data volume.

How easy is it to use Nucleus?

Customers report that Nucleus is easy to use, with an intuitive interface and straightforward automation. Onboarding is supported by step-by-step guides, video tutorials, and a dedicated support portal. Note: Ease of use may depend on user familiarity with vulnerability management concepts.

Security & Compliance

What security and compliance certifications does Nucleus hold?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, meeting rigorous security requirements for cloud services used by the U.S. Federal Government. Note: Certifications may not cover all regulatory frameworks; verify with your compliance team.

How does Nucleus support compliance with CISA BOD 22-01?

Nucleus tracks CISA KEV vulnerabilities to ensure federal compliance with CISA Binding Operational Directive 22-01, automating reporting and remediation workflows. Note: Compliance support is tailored for federal and public sector organizations; private sector requirements may differ.

What data security measures does Nucleus implement?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect customer data, including prevention of unauthorized access, use, modification, or disclosure. Note: For detailed technical controls, consult the Master Service Agreement or contact support.

Customer Proof & Success Stories

Can you share specific case studies or customer success stories?

Yes. Examples include Bank of Hope achieving zero critical vulnerabilities, a Tier-1 airline reducing critical vulnerabilities by 86%, and Orange Cyberdefense driving higher customer engagement (85% weekly usage). For more, see Customer Stories. Note: Results may vary based on organization size and implementation.

What industries are represented in Nucleus's case studies?

Industries include banking and financial services, airlines, healthcare, cybersecurity services, education, energy and utilities, retail and consumer goods, public sector, and technology. Note: Industry-specific features may vary; consult sales for tailored solutions.

Technical Documentation & Support

Where can I find technical documentation for Nucleus?

Technical documentation is available at API Docs, FlexConnect Framework Docs, and Support Portal. Quickstart guides are at Quickstart. Note: Documentation may require registration or authentication for full access.

What support resources are available for Nucleus customers?

Standard product support is included at no additional cost, with access to a dedicated support portal and responsive technical support. Customer Success Managers assist with implementation and troubleshooting. Note: Support levels may vary by contract; verify with your account manager.

Target Audience & Customer List

Who is the target audience for Nucleus?

Roles include Security Analysts, Development and IT Teams, CISOs and Security Leadership, GRC and Compliance Teams. Companies include regulated industries (healthcare, finance, government), large enterprises, MSSPs, and public sector entities. Note: Smaller organizations may require tailored onboarding; consult sales for fit.

Who are some of Nucleus's customers?

Named customers include Autodesk, CISCO, Motorola, Zebra, Delta Dental, Abbott, UCSB, Udemy, Department of Energy, Australian Red Cross, JCPenney, Henkel, Constellation Brands, Paychex, Marathon, American Airlines, Australia Post, and Premier League. For more, visit Nucleus Platform. Note: Customer list may change; verify for latest updates.

CISA KEV CATALOG VULNERABILITIES

Identify, Prioritize, and Remediate

CISA KEV

Vulnerability Remediation with a Plan

Approach vulnerabilities in your environment with business context and intelligence about active exploits in the wild.

IDENTIFY

Identify CISA Known Exploited Vulnerabilities in Seconds

Identify which assets in your environment have known exploited vulnerabilities. Cross-reference CISA KEV with Mandiant threat intelligence, CVSS, and more.

CISA KEV BOD

PRIORITIZE

Prioritize Remediation Based on CISA KEV

Use the CISA KEV catalog to prioritize remediation while automating workflows with integrations to ServiceNow, Jira, and other ticketing systems.

CISA KEV Finding

COMPLY

Meet CISA BOD 22-01 Federal Remediation Requirements

Track CISA KEV vulnerabilities to ensure federal compliance with CISA Binding Operational Directive 22-01.

CISA KEV BOD 22-01

Watch a Demo Today

Learn more about the Nucleus Unified Vulnerability Management platform right away.
Watch our in-depth, on-demand demo to see us in action.