• Platform
    Platform
    Nucleus Platform
    Scale and automate your vulnerability and exposure management program
    Vulnerability Intelligence Platform
    Access centralized and enriched vulnerability intelligence
    Nucleus Insights Intelligence Feed
    AI-powered, expert-validated threat and vulnerability intelligence
    Integrations
    Discover our ecosystem of 200+ connectors
    Capabilities
    Vulnerability Aggregation
    Unify and operationalize your vulnerability data in one platform
    Risk Prioritization
    Prioritize with asset context and threat intelligence
    Vulnerability Remediation
    Automate workflows to prioritize and mitigate critical exposures
    Vulnerability Intelligence
    Enrich vulnerability findings with real-world threat intelligence
    Asset Management
    Unify asset data to automate your vulnerability and exposure management
    Plan of Action and Milestones (POAM)
    Automate POA&M compliance at scale
    Compliance Frameworks
    Align with compliance framework controls and requirements.
    MCP Server
    Interact with your data using natural language and AI tools
  • Solutions
    Public Sector
    Federal Government
    Vulnerability and exposure management for government agencies
    State, Local, and Education (SLED)
    Centralize security and simplify compliance for state and local government
    Use Cases
    Exposure Management
    Scale and automate your exposure management program
    Risk-Based Vulnerability Management
    Address vulnerabilities with risk-based context and prioritization
    Application Security
    Shift left application security with production risk context
    Cloud Vulnerability and Exposure Management
    Conquer critical exposures across hybrid clouds
    Featured Report
    Gartner EAP MQ
    Nucleus Security Recognized as a Challenger in 2025 Gartner® Magic Quadrant™ Report

    We have been recognized for our Completeness of Vision and Ability to Execute.

    GET THE REPORT
  • Partners
    Partner Program
    Program Overview
    Learn more about our growing partner program
    MSSPs
    Explore opportunities for MSSP partnerships
    Marketplaces
    Find Nucleus on leading industry marketplaces
    Partner Resources
    Partner Directory
    Explore our ecosystem of partners
    Become a Partner
    Submit your request to join our partner program
    Deal Registration
    Easily register deals with Nucleus
    Partner Portal
    Log in to our dedicated Partner Portal
    Partner Case Study
    Orange Cyberdefense
    Case Study: Orange Cyberdefense

    Orange Cyberdefense leverages Nucleus to streamline vulnerability management, reduce costs, and drive impactful security insights for its customers.

    LEARN MORE
  • Resources
    Resources
    Resource Library
    Discover customer stories, reports, research, and more
    Blog
    Stay informed with the Nucleus Node blog
    Webinars
    Learn from industry experts and Nucleus leaders
    Events
    Meet with us virtually and in-person
    Featured Resources

    The Exploitability Intelligence Gap

    New CVE research by Nucleus Security gathered in an exclusive company white paper.

    LEARN MORE

    Gartner Exposure Assessment Platform Magic Quadrant

    Nucleus Security recognized as a Challenger by Gartner.

    LEARN MORE
    Featured Articles

    What Claude Mythos Means for Vulnerability Management Programs

    READ MORE

    America’s New Security Doctrine: Hardening Digital and Supply Chain Borders

    READ MORE
    Featured Webinars

    Claude Mythos: AI-Driven Vulnerability Discovery Webinar

    OPEN WEBINAR

    The Exploitability Intelligence Gap Webinar

    OPEN WEBINAR
    Featured Events

    Cybr.Sec.Con

    LEARN MORE

    SecTor

    LEARN MORE
  • Company
    About
    About Nucleus
    Learn more about who we are as a company
    Careers
    Explore our current openings and join the team
    News
    Read the latest news and articles
    Contact
    Contact Us
    Reach out to the Nucleus team
    Watch a Demo on Demand
    Watch our on-demand video demo
    Schedule Custom Demo
    Request a customized demo suited to your business' needs
    Pricing
    Get a quote based on your unique requirements
    Featured Content
    Omdia Tech Validation Report
    Omdia Technical Validation

    Omdia’s Technical Validation, commissioned by Nucleus, details how Nucleus helps organizations build successful vulnerability and exposure management programs.

    LEARN MORE
Watch A Demo

Security at Nucleus

Last updated: July 2026

Security Approach

At Nucleus Security, strong and accurate security is foundational to everything we do. Our founders built their careers in vulnerability management for large, data-sensitive organizations, and that discipline is embedded across our company. We understand how much our customers trust us with their data, and we are committed to transparency about the controls we use to protect our platform and infrastructure.

At the center of our program, we run Nucleus using our own platform to manage vulnerability workflows and analysis. That gives us continuous, first-hand confidence in the security posture of our organization and every customer instance.

Certifications & Authorizations

We maintain independent, third-party-attested certifications for the Nucleus platform, and we host on cloud infrastructure that carries its own extensive compliance portfolio.

Nucleus Platform

  • SOC 2 Type II We maintain an annual SOC 2 Type II attestation covering the security of the Nucleus, NucelusGov, and VIP platforms. Reports are available to customers and prospects under NDA via our trust portal.
  • FedRAMP Moderate Authorized NucleusGov, our platform for government, is FedRAMP Moderate Authorized and listed on the FedRAMP Marketplace (ID: FR2134455708). We also hold multiple direct agency Authorizations to Operate (ATOs) beyond the FedRAMP authorization. Federal agencies can request access to our FedRAMP package via max.gov to complete their ATO process.

Our Cloud Provider

Our production environment is hosted within a cloud boundary that maintains a broad set of certifications, including (but not limited to) ISO 27001, AICPA SOC 1 & SOC 2, PCI DSS, C5, and IRAP. These apply to physical and environmental security controls as well. We work with many cloud providers and we work with you to select the appropriate hosting region so you can meet local compliance requirements.

Application Security

We use a full suite of secure software-development activities and controls. Our developers follow secure coding practices mandated in our Development Style Guide, which guides secure implementation from the start of the development lifecycle through production release.

  • All code is tested regularly with multiple SAST, SCA, and DAST tools, and we consolidate findings within Nucleus to leverage the strengths of each tool.
  • Every application is scanned prior to any new production release.
  • A dedicated team owns remediation of any issues discovered, tracking finding status through the Nucleus platform.
  • We conduct regular, scheduled third-party penetration tests and audits including continuous phishing simulations to validate our defenses against sophisticated attacks.

Infrastructure & Data Protection

We layer multiple controls to protect customer data:

  • Encryption at rest using industry best practices, for both production data and backups.
  • Encryption in transit with TLS 1.2+ enforced on all connections.
  • Multi-factor authentication (MFA) required on all employee accounts, with single sign-on (SSO).
  • Tenant data isolation customer data is tagged and segregated by organization so only authorized users can access it, and isolation is validated annually by a third-party penetration tester. Strict separation between production, government, and dev/test enivornments.
  • Centralized logging and alerting across the environment.
  • Hardened, locked-down instances with controls specifically designed to minimize attack surface.

Vulnerability Management

We practice what we sell. We conduct routine vulnerability scanning of our network and infrastructure using a variety of security tools, consolidating all findings within Nucleus. A dedicated team owns remediation and tracks status through the platform. We also participate in monthly continuous monitoring (ConMon) reviews with our government agency customers.

Trust Center Request Documentation

We are happy to share deeper detail with customers and prospects via our trust portal (https://trust.nucleussec.com):

  • SOC 2 Type II report available under NDA
  • Penetration test attestation available under NDA
  • FedRAMP package available to agencies via max.gov upon request

Report a security issue: If you believe you’ve found a vulnerability or have a security concern, please contact us at [email protected]. We appreciate responsible disclosure and will respond promptly.

Contents
  • Platform
    • Platform Overview
    • Nucleus Vulnerability Intelligence Platform (VIP)
    • Nucleus Insights
    • Integrations
    • Vulnerability Aggregation
    • Risk Prioritization
    • Vulnerability Remediation
    • Vulnerability Intelligence
    • Plans of Actions & Milestones (POAM)
  • Solutions
    • Exposure Management
    • Risk Based Vulnerability Management (RBVM)
    • Application Security
    • Cloud Vulnerability & Exposure Management
    • Federal
    • State / Local / Education
  • Partners
    • Nucleus Partner Program
    • Managed Security Service Providers
    • Partner Portal
    • Partner Directory
    • Marketplaces
    • Deal registration
    • Become a Partner
  • Resources
    • Resource Library
    • Blog
    • Webinars
    • Events
  • Company
    • About
    • Pricing
    • Careers
    • News
    • Support
    • Contact
  • Learn More
    • Exposure Management Explained
    • Effective Vulnerability Management Solutions
    • The Essential Guide to Exposure Assessment Platforms

© 2026 Nucleus Security. All rights reserved

  • Privacy Policy
  • Vulnerability Disclosure Program