Frequently Asked Questions

Product Overview & Purpose

What is Nucleus and what does it do?

Nucleus is a unified vulnerability management platform that aggregates data from your existing security tools, creating a centralized command center for vulnerability analysis, triage, and remediation. It automates workflows, prioritizes risks using real-world intelligence, and helps organizations align with compliance frameworks. Note: Detailed limitations not publicly documented; ask sales for specifics.

Features & Capabilities

What are the key features of Nucleus?

Nucleus offers vulnerability aggregation, risk-based prioritization, automation of remediation workflows, compliance framework support, POA&M automation, cloud and application security integration, asset management, and threat intelligence enrichment. It processes over 8 billion findings daily and integrates with 200+ tools. Note: Best fit for organizations needing centralized vulnerability management; teams requiring highly specialized niche integrations may want to confirm compatibility.

How does Nucleus aggregate vulnerability data?

Nucleus unifies, normalizes, and operationalizes vulnerability data from all your security tools into a single platform. It uses advanced asset-matching technology to consolidate duplicate assets, maintain consistent asset IDs, and link identical container images across environments. Note: Asset deduplication may require initial configuration for optimal results.

Does Nucleus support workflow automation?

Yes, Nucleus automates vulnerability management workflows using its Data Core architecture and dynamic automation framework. This includes ticketing, ownership assignment, and compliance tasks. Note: Automation features may require integration with supported tools for full functionality.

What integrations are available with Nucleus?

Nucleus integrates with over 200 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), SecurityScorecard and Censys (ASM). For a full list, visit the integrations page. Note: Some integrations may require additional configuration or licensing.

Does Nucleus provide an API?

Yes, Nucleus offers an API for custom dashboards, real-time reporting, and integration with SIEM, SOAR, and other security tools. API documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise for setup.

Performance & Business Impact

What performance improvements does Nucleus offer?

Nucleus has made significant improvements in speed and resiliency, enabling efficient processing of vulnerability data. Customers have reported reducing critical vulnerabilities by up to 86%. Note: Performance may vary based on environment and integration complexity.

What business impact can customers expect from using Nucleus?

Customers can expect improved operational efficiency, enhanced security outcomes, cost savings, compliance support, centralized visibility, and faster remediation. For example, Orange Cyberdefense reported 85% of their customers use Nucleus weekly to reduce exposure, and NRECA achieved faster remediation and fewer false positives. Note: Impact depends on organizational adoption and integration depth.

Implementation & Ease of Use

How long does it take to implement Nucleus?

Nucleus integrates with over 200 tools out of the box, enabling onboarding in hours instead of weeks. Prebuilt connectors and reusable templates simplify deployment. Note: Implementation time may vary based on environment complexity and integration requirements.

Is Nucleus easy to use?

Customer feedback highlights Nucleus's intuitive interface, easy automation, and smooth onboarding. Reviews from G2 and IT Services managers cite its user-friendliness and immediate value. Note: Ease of use may depend on user familiarity with vulnerability management concepts.

Security & Compliance

What security and compliance certifications does Nucleus have?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, meeting rigorous security requirements for cloud services used by the U.S. Federal Government. Note: Certifications may not cover all industry-specific requirements; verify with your compliance team.

How does Nucleus protect customer data?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect the security, confidentiality, and integrity of customer data. It warrants compliance with all applicable laws and regulations, including breach notification laws. Note: For detailed data protection policies, refer to the Master Service Agreement.

Does Nucleus have a vulnerability disclosure program?

Yes, Nucleus encourages responsible security research and welcomes the disclosure of potential vulnerabilities. Researchers are protected from legal action if they follow program guidelines. See the disclosure program for details. Note: Disclosure guidelines must be followed for legal protection.

Use Cases & Target Audience

Who is the target audience for Nucleus?

Nucleus is designed for Security Analysts, Development and IT Teams, CISOs and Security Leadership, GRC and Compliance Teams, large enterprises, regulated industries (healthcare, finance, government), MSSPs, and public sector entities (federal, state, local, education). Note: Smaller organizations with limited vulnerability management needs may want to evaluate fit.

What industries are represented in Nucleus case studies?

Industries include banking and financial services, airlines, healthcare, cybersecurity services, education, energy and utilities, retail and consumer goods, public sector, and technology. See customer stories for details. Note: Case studies may not cover all industry-specific scenarios.

Customer Proof & Success Stories

Can you share specific case studies or success stories of customers using Nucleus?

Yes. Bank of Hope achieved zero critical vulnerabilities, a Tier-1 airline reduced 86% of critical vulnerabilities, a healthcare enterprise replaced Kenna and reduced its backlog from 4,000 to nine critical threats, Orange Cyberdefense streamlined vulnerability management, UCSB transformed risk management, NRECA achieved centralized risk visibility, and a global health enterprise scaled risk reduction across hybrid cloud environments. See customer stories for details. Note: Results may vary by organization.

Who are some of Nucleus's customers?

Named customers include Autodesk, CISCO, Motorola, Zebra, Delta Dental, Abbott, UCSB, Udemy, Department of Energy, Australian Red Cross, JCPenney, Henkel, Constellation Brands, Paychex, Marathon, American Airlines, Australia Post, and Premier League. For more, visit the platform page. Note: Customer list may change over time.

Technical Documentation & Support

Where can I find technical documentation for Nucleus?

Technical resources include API documentation (api-docs.nucleussec.com), FlexConnect Framework setup (help.nucleussec.com/docs/flexconnect-framework), a support portal (help.nucleussec.com), and Quickstart guides (help.nucleussec.com/docs/quickstart). Note: Some documentation may require login or partner access.

What support options are available for Nucleus customers?

Standard product support is included at no additional cost, with access to a dedicated support portal and responsive technical support. Customer Success Managers assist with implementation and troubleshooting. Note: Support levels may vary based on contract and region.

VULNERABILITY AGGREGATION 

Manage All Your Vulnerability Data in One Hub 

Unify, normalize, and operationalize data from all your security tools to accelerate your vulnerability management program, at scale. 

Vulnerability Aggregation

Accelerate and Scale Your Vulnerability Management Program

Connect to 200+ Sources

Ingest data from all your tools with 200+ built-in integrations and FlexConnect universal adapter.

Operate at Enterprise Scale

Nucleus processes 8+ billion findings daily for world-leading private and public sector organizations.

Automate Vulnerability Management

Aggregate assets, findings, and threat data to automate risk-based workflows and accelerate remediation.

ASSET DEDUPLICATION

Manage Assets Instead of Duplicate Noise

Consolidate duplicate assets into a single, clean inventory with our advanced asset-matching technology:

  • Detect duplicates across multiple scanning tools.
  • Maintain consistent asset IDs over time.
  • Link identical container images across environments and repositories.
Asset Deduplication Screenshot Asset Deduplication Screen

STANDARDIZED RISK SCORING

Manage Risks on a Single Scale

Establish a unified standard to prioritize risks and keep teams aligned on critical issues. Nucleus normalizes risk scores into a standard format, enabling security teams to communicate and remediate risks effectively.

Standard Risk Scoring

WORKFLOW AUTOMATION

Automate at Enterprise Scale

Accelerate your vulnerability management workflows with the Nucleus Data Core — our specialized data fabric architecture and dynamic automation framework. Operationalize your risk and vulnerability data to remediate vulnerabilities, at scale.

AGGREGATE AND EXPLORE

Analyze Deeply with Nucleus Explore

Aggregate and explore your vulnerability data with precision. Nucleus Explore delivers instant, natural language insights into historical trends, granular analytics, and program performance. Save and share custom views to keep stakeholders aligned with real-time, data-driven visibility.

Nucleus Explore and All Findings

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.