Security at Nucleus
Last updated: July 2026
Security Approach
At Nucleus Security, strong and accurate security is foundational to everything we do. Our founders built their careers in vulnerability management for large, data-sensitive organizations, and that discipline is embedded across our company. We understand how much our customers trust us with their data, and we are committed to transparency about the controls we use to protect our platform and infrastructure.
At the center of our program, we run Nucleus using our own platform to manage vulnerability workflows and analysis. That gives us continuous, first-hand confidence in the security posture of our organization and every customer instance.
Certifications & Authorizations
We maintain independent, third-party-attested certifications for the Nucleus platform, and we host on cloud infrastructure that carries its own extensive compliance portfolio.
Nucleus Platform
- SOC 2 Type II We maintain an annual SOC 2 Type II attestation covering the security of the Nucleus, NucelusGov, and VIP platforms. Reports are available to customers and prospects under NDA via our trust portal.
- FedRAMP Moderate Authorized NucleusGov, our platform for government, is FedRAMP Moderate Authorized and listed on the FedRAMP Marketplace (ID: FR2134455708). We also hold multiple direct agency Authorizations to Operate (ATOs) beyond the FedRAMP authorization. Federal agencies can request access to our FedRAMP package via max.gov to complete their ATO process.
Our Cloud Provider
Our production environment is hosted within a cloud boundary that maintains a broad set of certifications, including (but not limited to) ISO 27001, AICPA SOC 1 & SOC 2, PCI DSS, C5, and IRAP. These apply to physical and environmental security controls as well. We work with many cloud providers and we work with you to select the appropriate hosting region so you can meet local compliance requirements.
Application Security
We use a full suite of secure software-development activities and controls. Our developers follow secure coding practices mandated in our Development Style Guide, which guides secure implementation from the start of the development lifecycle through production release.
- All code is tested regularly with multiple SAST, SCA, and DAST tools, and we consolidate findings within Nucleus to leverage the strengths of each tool.
- Every application is scanned prior to any new production release.
- A dedicated team owns remediation of any issues discovered, tracking finding status through the Nucleus platform.
- We conduct regular, scheduled third-party penetration tests and audits including continuous phishing simulations to validate our defenses against sophisticated attacks.
Infrastructure & Data Protection
We layer multiple controls to protect customer data:
- Encryption at rest using industry best practices, for both production data and backups.
- Encryption in transit with TLS 1.2+ enforced on all connections.
- Multi-factor authentication (MFA) required on all employee accounts, with single sign-on (SSO).
- Tenant data isolation customer data is tagged and segregated by organization so only authorized users can access it, and isolation is validated annually by a third-party penetration tester. Strict separation between production, government, and dev/test enivornments.
- Centralized logging and alerting across the environment.
- Hardened, locked-down instances with controls specifically designed to minimize attack surface.
Vulnerability Management
We practice what we sell. We conduct routine vulnerability scanning of our network and infrastructure using a variety of security tools, consolidating all findings within Nucleus. A dedicated team owns remediation and tracks status through the platform. We also participate in monthly continuous monitoring (ConMon) reviews with our government agency customers.
Trust Center Request Documentation
We are happy to share deeper detail with customers and prospects via our trust portal (https://trust.nucleussec.com):
- SOC 2 Type II report available under NDA
- Penetration test attestation available under NDA
- FedRAMP package available to agencies via max.gov upon request
Report a security issue: If you believe you’ve found a vulnerability or have a security concern, please contact us at [email protected]. We appreciate responsible disclosure and will respond promptly.