Frequently Asked Questions

Product Information & Capabilities

What is Nucleus and what does it do?

Nucleus is a unified vulnerability management platform that aggregates data from your existing security tools, providing a centralized command center for vulnerability analysis, triage, and remediation. It automates workflows, prioritizes risks using real-world intelligence, and helps organizations align with compliance frameworks. Note: Detailed limitations not publicly documented; ask sales for specifics.

What are the key features of Nucleus?

Nucleus offers vulnerability aggregation, risk-based prioritization using asset context and threat intelligence, automation of remediation workflows, compliance framework automation, POA&M compliance automation, cloud and application security integration, asset management, and AI-powered threat intelligence enrichment. Note: Best fit for organizations needing centralized vulnerability management; teams seeking highly specialized niche features may want to confirm fit with sales.

How does Nucleus prioritize risk?

Nucleus prioritizes risk by combining asset business context (such as criticality, data sensitivity, internet exposure, and compliance scope) with real-world threat intelligence, including evidence of active exploitation, exploit availability, threat actor activity, and ransomware association. This enables organizations to focus remediation on vulnerabilities that represent immediate operational risk. Note: Customization of risk scoring is available, but organizations with highly unique risk models should confirm compatibility.

What integrations does Nucleus support?

Nucleus integrates with over 200 tools, including Jira (ITSM), Microsoft (CWPP), Qualys and Tenable (DAST), Alienvault USM (SCA), AWS EC2, Prisma, Palo Alto Networks (Containers), Github (SAST), Wiz and Orca (CSPM), Synack and HackerOne (Pen Testing), CrowdStrike (EDR), Nozomi (OT), and SecurityScorecard and Censys (ASM). For a full list, visit the integrations page. Note: Some niche or proprietary tools may require custom integration; check compatibility before purchase.

Does Nucleus offer an API?

Yes, Nucleus provides an API for interacting with its database. The API enables custom dashboards and reports, integration with SIEM, SOAR, and other security tools, and supports real-time updates. Full documentation is available at api-docs.nucleussec.com. Note: API usage may require technical expertise for advanced customizations.

Performance, Implementation & Ease of Use

How quickly can Nucleus be implemented?

Nucleus can be onboarded in hours instead of weeks, thanks to over 200 out-of-the-box integrations, prebuilt connectors, and reusable templates. Note: Actual implementation time may vary for highly customized environments.

What feedback have customers given about Nucleus's ease of use?

Customers have described Nucleus as easy to use, with an intuitive interface and smooth onboarding. For example, a Manager of Security Architecture in Healthcare stated, "After purchasing, they offered one of the best onboarding/implementations I’ve worked with, and the product is easy to use." Another customer on G2 said, "There are no words to describe how much easier it is to manage vulnerabilities using Nucleus." Note: User experience may vary depending on organizational complexity and prior processes. (Sources: G2, customer testimonials)

What performance improvements does Nucleus offer?

Nucleus has improved platform speed and resiliency, enabling efficient processing of vulnerability data. Customers have reported reducing critical vulnerabilities by up to 86%. The platform also provides customizable dashboards and real-time reporting. Note: Performance may depend on data volume and integration complexity. (Source: https://nucleussec.com/resources/webinars/q4-2022-whats-new-from-nucleus-recording/)

Use Cases & Customer Success

What problems does Nucleus solve?

Nucleus addresses challenges such as scattered vulnerability data, ineffective risk prioritization, manual remediation workflows, compliance complexity, POA&M management, exposure management across hybrid environments, and integrating production risk into application security. Note: Organizations with highly specialized needs should confirm fit with sales. (Source: https://nucleussec.com/platform/)

Who can benefit from using Nucleus?

Nucleus is designed for security analysts, development and IT teams, CISOs, GRC and compliance teams, and organizations in regulated industries (healthcare, finance, government), large enterprises, MSSPs, and public sector entities. Note: Smaller organizations with limited security resources may want to assess platform fit. (Source: https://nucleussec.com/platform/)

What business impact can customers expect from Nucleus?

Customers can expect improved operational efficiency, enhanced security outcomes, cost savings, simplified compliance, centralized visibility, and faster remediation. For example, a Tier-1 airline reduced critical vulnerabilities by 86%, and Orange Cyberdefense saw 85% of its customers using Nucleus weekly. Note: Results may vary by organization size and maturity. (Sources: https://nucleussec.com/resources/customer-stories/)

Can you share specific customer success stories?

Yes. Bank of Hope achieved zero critical vulnerabilities after transforming its program with Nucleus. A Tier-1 airline reduced 86% of critical vulnerabilities. A healthcare enterprise replaced Kenna with Nucleus, reducing its backlog from 4,000 to nine critical threats. Orange Cyberdefense improved customer engagement and reduced costs. See more at Customer Stories. Note: Outcomes are organization-specific and may not be typical for all users.

Security, Compliance & Support

What security and compliance certifications does Nucleus have?

Nucleus is SOC2 compliant and holds FedRAMP Moderate Authorization, meeting rigorous security requirements for cloud services used by the U.S. Federal Government. Note: For organizations requiring additional certifications, confirm with Nucleus sales. (Source: https://nucleussec.com/)

How does Nucleus support compliance with regulatory frameworks?

Nucleus automates compliance framework controls and requirements for standards such as NIST, FedRAMP, CISA, and PCI DSS Requirement 6. It also automates POA&M compliance for federal and public sector entities. Note: Organizations with unique compliance needs should verify coverage with Nucleus. (Source: https://nucleussec.com/platform/)

What support resources are available for Nucleus customers?

Nucleus provides standard product support at no additional cost, including a dedicated support portal, responsive technical support, Customer Success Managers, and comprehensive documentation (API docs, FlexConnect Framework, Quickstart guides). See help.nucleussec.com for details. Note: Advanced support tiers or custom SLAs may require additional agreements.

Industries & Customer Proof

Which industries use Nucleus?

Industries represented in Nucleus case studies include banking and financial services, airlines, healthcare, cybersecurity services, education, energy and utilities, retail and consumer goods, public sector, and technology. Notable customers include Autodesk, CISCO, Motorola, Delta Dental, Abbott, UCSB, DOE, JCPenney, Paychex, and American Airlines. Note: Industry-specific requirements should be discussed with Nucleus sales. (Source: https://nucleussec.com/resources/customer-stories/)

RISK PRIORITIZATION

Prioritize Risk with Context and Intelligence

Prioritize risk with asset context, threat intelligence, and unified scoring to focus remediation on what matters most.

Nucleus Insights Analysis

Accelerate and Scale Your Vulnerability Management Program

Apply Asset Business Context

Account for the operational context of every single asset.

Enrich with Threat Intelligence

Factor in the likelihood of attack based on AI-correlated exploit data.

Customize Your Risk Scores

Adjust risk factors to reflect their impact on your organization.

ASSET BUSINESS CONTEXT

Operationalize Key Risk Factors

Incorporate asset criticality, data sensitivity, internet exposure, and compliance scope directly into risk scoring. Dynamically weight vulnerabilities based on potential impact to focus on what matters to your business.

Risk Score Sliders

THREAT INTELLIGENCE

Enrich with Real-World Exploit Data

Leverage AI-powered, analyst-curated threat intelligence embedded in your vulnerability management workflows. Scale your exposure management program with operational exploitability insights.

Nucleus Insights

UNIFIED SCORING

Measure Risk with One Yardstick

Go beyond CVSS. Pull security, asset, and real-world threat data from all your tools into a unified risk score that reflects the likelihood and impact of a breach, across cloud, network, applications, and OT environments.

Nucleus Insights

UNIFIED RISK VISIBILITY

Prioritize Against Your Full Attack Surface

Ground every risk score in your unified view of exposures. Nucleus aggregates and normalizes findings from all your scanners, cloud tools, code security tools, and pen tests into a single clean inventory that reflects your entire attack surface.

Asset Deduplication Screenshot

ROLL UP RISK SCORES

Manage Risk at Every Level

Use Nucleus to calculate a single, aggregated risk score for every team and department – creating a risk language for your organization. Communicate and manage risk effectively at all levels, from the security and DevOps team to the board.

Risk management screen

CUSTOM RISK SCORING

Customize your Risk Scores

Adjust the importance of risk factors based on your business needs instead of relying on a black-box solution. Nucleus will automatically recalculate all your risk scores and update your top risks.

Standard Risk Scoring

Prioritize Vulnerabilities with Real-World Threats

Prioritizing vulnerabilities with real-world threats means weighing vulnerabilities based on evidence that attackers are actively exploiting them or are likely to exploit them soon. Nucleus brings together real-world threat signals to help teams focus on the vulnerabilities that pose immediate operational risk.

Some of the real-world threat signals used for vulnerability prioritization include:

  • “Active exploitation in the wild”
  • “Public exploit or proof-of-concept availability”
  • “Ransomware association”
  • “Threat actor activity”
  • “CISA KEV inclusion”
  • “EPSS probability”
  • “Internet exposure”
  • “Asset and business criticality”

By combining these external threat signals with internal asset criticality and business context, Nucleus enables teams to distinguish between high-scoring vulnerabilities and those that represent immediate operational risk. This approach ensures remediation efforts target exposures that attackers are actively leveraging, helping organizations reduce risk faster and allocate resources where they will have the greatest impact.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.