Frequently Asked Questions

Product Information & Use Cases

What is Nucleus and how does it help organizations manage vulnerabilities?

Nucleus is a unified vulnerability management platform that aggregates data from existing security tools, providing a centralized command center for vulnerability analysis, triage, and remediation. It automates workflows, prioritizes risks using real-world intelligence, and helps organizations align with compliance frameworks. This approach is especially valuable for enterprises and government agencies seeking to streamline vulnerability management and improve security outcomes. Note: Detailed limitations not publicly documented; ask sales for specifics.

What specific problems does Nucleus solve for organizations?

Nucleus addresses challenges such as scattered vulnerability data, inefficient risk prioritization, manual remediation workflows, and complex compliance requirements. It consolidates vulnerability data from multiple tools, automates remediation workflows, and simplifies compliance with standards like NIST, FedRAMP, and CISA. For federal and public sector entities, Nucleus automates Plan of Action and Milestones (POA&M) compliance at scale. Note: Best fit for organizations seeking centralized vulnerability management; teams needing highly customized workflows may want to evaluate integration capabilities.

Who is the target audience for Nucleus?

Nucleus is designed for Security Analysts, Development and IT Teams, CISOs and Security Leadership, GRC and Compliance Teams, and Managed Security Service Providers (MSSPs). It is used by organizations in regulated industries such as healthcare, finance, government, large enterprises, and public sector entities including federal government and SLED (State, Local, and Education). Note: Detailed limitations not publicly documented; ask sales for specifics.

Features & Capabilities

What are the key features and benefits of the Nucleus platform?

Nucleus offers vulnerability aggregation from over 160 tools, risk-based prioritization using asset context and threat intelligence, automation of remediation workflows, compliance framework automation, POA&M compliance for public sector, cloud and application security integration, asset management, and AI-powered threat intelligence. Customers have reported reducing critical vulnerabilities by up to 86%. Note: Best fit for organizations seeking centralized and automated vulnerability management; those requiring highly specialized integrations should review the full integration list.

What integrations does Nucleus support?

Nucleus integrates with over 160 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), SecurityScorecard and Censys (ASM). For a complete list, visit the integrations page. Note: Some legacy or niche tools may require custom integration; check documentation for specifics.

Does Nucleus offer an API for custom integrations and reporting?

Yes, Nucleus provides an API that enables users to query the database for custom dashboards and reports, integrate with SIEM, SOAR, and other security tools, and build real-time updating reports. API documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise; consult documentation for supported endpoints.

Implementation & Support

How long does it take to implement Nucleus, and how easy is it to start?

Nucleus integrates with over 200 tools out of the box, enabling onboarding in hours instead of weeks. Prebuilt connectors and reusable templates simplify deployment. Customers have access to step-by-step guides, video tutorials, and a dedicated support portal. Customer Success Managers and a responsive technical support team assist with implementation and troubleshooting. Note: Organizations with highly customized environments may require additional integration time.

What technical documentation and resources are available for Nucleus?

Nucleus offers comprehensive API documentation (api-docs.nucleussec.com), FlexConnect Framework setup guides (help.nucleussec.com/docs/flexconnect-framework), a help and support portal (help.nucleussec.com), and quickstart guides (help.nucleussec.com/docs/quickstart). These resources support evaluation and implementation. Note: Some advanced features may require technical expertise.

Security & Compliance

What security and compliance certifications does Nucleus hold?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, meeting rigorous security requirements for cloud services used by the U.S. Federal Government. These certifications demonstrate adherence to controls relevant to security, availability, processing integrity, confidentiality, and privacy. Note: For organizations requiring additional certifications, verify with sales for the latest compliance status.

How does Nucleus protect customer data and support compliance frameworks?

Nucleus employs industry-standard administrative, physical, and technical safeguards to protect customer data. It automates compliance framework controls and requirements, supporting standards like NIST, FedRAMP, CISA, and PCI DSS Requirement 6. Under the Master Service Agreement, Nucleus warrants compliance with applicable laws and regulations, including breach notification laws. Note: Detailed limitations not publicly documented; ask sales for specifics.

Customer Success & Business Impact

What business impact can customers expect from using Nucleus?

Customers can expect improved operational efficiency, enhanced security outcomes, cost savings, simplified compliance, centralized visibility, and proven ROI. For example, NRECA achieved faster remediation of critical risks, improved collaboration across teams, and fewer fire drills and false positives. Orange Cyberdefense reported 85% of customers using the platform weekly to reduce exposure to threats. Note: Results may vary based on organizational size and complexity.

Can you share specific case studies or success stories of customers using Nucleus?

Yes. Notable examples include Bank of Hope achieving zero critical vulnerabilities, a Tier-1 airline reducing 86% of critical vulnerabilities, a healthcare enterprise replacing Kenna and reducing its backlog from 4,000 vulnerabilities to nine critical threats, Orange Cyberdefense streamlining vulnerability management, and NRECA achieving centralized risk visibility and action. For more, visit the Customer Stories page. Note: Individual results depend on implementation and organizational context.

Industry Coverage & Customer Proof

Which industries are represented in Nucleus case studies?

Industries include banking and financial services (e.g., Bank of Hope), airlines (Tier-1 airline), healthcare (healthcare enterprise, global health organization), cybersecurity services (Orange Cyberdefense), education (UCSB), energy and utilities (NRECA), retail and consumer goods (large retailer), public sector (US State Agency), and technology (workforce management enterprise). Note: For industry-specific features, consult sales or case studies.

Who are some of Nucleus's customers?

Customers include Autodesk, CISCO, Motorola, Zebra, Delta Dental, Abbott, UCSB, Udemy, Department of Energy, Australian Red Cross, JCPenney, Henkel, Constellation Brands, Paychex, Marathon, American Airlines, Australia Post, and Premier League. For a comprehensive list, visit the platform page. Note: Customer fit varies by industry and use case.

Ease of Use & Customer Feedback

What feedback have customers given about the ease of use of Nucleus?

Customers report that Nucleus is easy to use, with intuitive automation and a smooth onboarding process. For example, a Manager of Security Architecture and Threat Management in Healthcare stated, "Nucleus Security has been an exceptional partner from the beginning…After purchasing, they offered one of the best onboarding/implementations I’ve worked with, and the product is easy to use." A SOC Operations Manager in IT Services commented, "[Nucleus] is extremely easy to work with and takes into account all of your wants and needs for the product. The automation is very easy to navigate and provides immediate value." Note: Ease of use may vary based on organizational complexity and user experience.

Performance & Metrics

What performance improvements and metrics are associated with Nucleus?

Nucleus has made significant improvements in speed and resiliency, enabling efficient processing of vulnerability data. Enhanced reporting features provide customizable dashboards and real-time metrics. Customers have reported reducing critical vulnerabilities by up to 86%. Note: Performance may vary based on deployment scale and integration complexity.

CUSTOMER STORY

NRECA’s Journey to Centralized Risk Visibility and Action with Nucleus

Power lines

Customer Profile

  • Customer: National Rural Electric Cooperative Assocaiation (NRECA)
  • Industry: Electric Utilities
  • Location: Arlington, VA

Business Impact

  • Faster remediation of critical risks
  • Improved collaboration across teams
  • Improved efficiency with fewer fire drills and false positives

About NRECA

The National Rural Electric Cooperative Association (NRECA) is a nonprofit trade association representing nearly 900 rural electric cooperatives across the United States. These cooperatives provide power to approximately 42 million people, covering 56% of the nation’s landmass. NRECA’s mission is to power communities and empower members to improve the quality of their lives.

The Challenge: Siloed Tools, Misaligned Priorities

Before Nucleus, NRECA’s security and IT teams were constantly under pressure to respond to an overwhelming number of vulnerabilities, many of which were flagged as “critical” based solely on CVSS scores. In addition, external exposure and asset context were often missing. This made it impossible to rise above the data noise and make consistent and risk-informed decisions.

“There was a lot of data coming from different scanners and security tools … but if everything is critical, it means nothing is critical.”

-Masie Habib, Lead Security Engineer, NRECA

NRECA’s prioritization challenge was compounded by the fact that their CloudSec, AppSec, and IT teams were operating in silos, each with their own tools and workflows, drowning in millions of alerts that came from siloed tools without a single risk standard. Masie Habib, Lead Security Engineer at NRECA added, “A major focus for us was consolidation—bringing our exposure data and teams together into a single, unified platform.” The organization needed a solution that would be able to unify security operations across teams.

“One of the strongest things Nucleus did for us was help bring our teams together under one umbrella, all working with the same information. Prioritization became aligned. Our disparate security teams of CloudSec, AppSec, and network security were using different tools and getting different prioritization info. We had teams working toward common goals, but in different ways with different info. Now, they’re unified and working off the same standard of measurement.”
-Brandon Hilder, Cybersecurity Engineer, NRECA

The Nucleus Solution

Securing a decentralized network, with dozens of state agencies, posed many unique challenges:

  1. Data Overload: Disparate security scanning tools generated vast amounts of vulnerability and exposure data, making timely analysis and assessment impossible using manual processes.
  2. Emerging Threats: Rapid response to critical vulnerabilities, including zero-day threats, was impeded by the lack of unified threat intelligence across commercial and internal agency feeds.
  3. Remediation Timelines: Manual processes and poor visibility prolonged exposure to high-risk vulnerabilities with remediation timelines regularly missing agency and leadership goals.

Key Selection Criteria

When NRECA began evaluating platforms, they looked for a platform that could connect all the tools in their security stack and aggregate the data. The team was also looking for a platform that allowed users to move from a high-level overview to a granular overview of risk scores. As Masie Habib described, “We wanted to start with that bird’s-eye view to see everything across the environment, narrow the data down into something easier to digest, and then be able to act on it.”

Additionally, the platform had to incorporate threat intelligence and asset context, enriching vulnerability data with external intelligence feeds such as CISA KEV and Google Threat Intelligence (previously Mandiant) to augment NRECA’s risk prioritization with real-world threat data.

Nucleus Platform Screenshot

The Solution: Nucleus Security Platform

To overcome fragmented processes and overwhelming data volume, NRECA selected Nucleus to serve as the unified backbone of its vulnerability management program. Nucleus ingests data from over 160 sources—including scanners, CMDBs, cloud APIs, and threat intelligence feeds—and consolidates it into a trusted, deduplicated view of assets, vulnerabilities, and risk.

“We are able to look at that bird’s eye view, narrow it down to something that is much easier to digest in terms of information, and then act on that.”
-Masie Habib, NRECA

With this scalable foundation, NRECA transitioned from CVSS-only scoring to a contextual risk model that accounts for exploitability, business impact, and asset sensitivity.

Nucleus’ automation framework then operationalized that context—automatically routing issues to the right teams, enforcing SLA policies, managing exceptions, and eliminating manual triage bottlenecks.

Business Impact

Power lines with workers

From Data Chaos to Focused Risk-Based Remediation

NRECA rolled out Nucleus with a clear security vision: to achieve enterprise-wide visibility across critical infrastructure, reduce organizational risk, and streamline remediation. With focus and stakeholder alignment, they were able to roll out a risk-based program with multiple integrations and diverse remediation teams. NRECA achieved three key outcomes with Nucleus: faster remediation of critical risks, stronger collaboration across teams, and fewer wasted resources on false positives.

Just as important, Nucleus helped NRECA unify previously siloed teams. NRECA’s CloudSec, AppSec, and network security teams were each using different tools and working from different prioritization models, which created confusion and inefficiencies despite shared goals. With Nucleus, all teams are now operating under a single platform, using the same risk data, scoring logic, and remediation workflows.

“Nucleus makes it clear what our top priorities are. When a true critical or high-risk issue appears in our environment, we immediately know where to focus our resources and get it resolved quickly.”
-Masie Habib, NRECA

Want to See Nucleus in Action?

Watch our demo on-demand.