Overview
Risk Based Vulnerability Management Nucleus is redefining the vulnerability management software category as the single source of record for all assets, vulnerabilities, and associated data. We unlock value from your existing tools and place you squarely on the path to program maturity by unifying the people, processes, and technology involved in vulnerability management. With Nucleus, you receive unmatched visibility into your program and a suite of tools with functionality that simply cant be replicated in any other way.
Remediate What Matters Most
Nucleus sits at the nexus of your vulnerability data, asset information, and embedded threat intelligence. Providing contextually relevant data at your fingertips, allowing for automated response at scale. Nucleus combines all the asset information, vulnerability data from scanning tools, and threat intelligence from Mandiant into one single platform for vulnerability teams to eliminate laborious manual data analysis and accelerate decision making and prioritization.
Highlights
- Here are the features supported by this Product Native connectors: Yes FlexConnect integrations: Yes Role-based access control: Yes Asset group access control: Yes Trends page: Yes In-platform reports: Yes Bulk data export: Yes Manual and automated ticket integrations: Yes Publicly available threat intelligence (NVD, CISA KEV) integration: Yes Mandiant threat intelligence integration: Yes Recorded Future integration (sold separately): Yes
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Platform | Platform License | $100,000.00 |
Vendor refund policy
All sales are final, non-refundable, and non-returnable except with respect to Products that do not meet applicable specifications in the relevant Documentation.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Standard Support provides access to our global support team via our support portal, access to online resources and knowledge base. Support First Response SLA (Business Hours) Unlimited Email Support Customer Portal Knowledge Base Nucademy (Nucleus online training) Premium Support is our highest level of support for Enterprise customers, providing virtual support sessions, access to an Executive Sponsor, and chat support via Slack integration.
Support First Response SLA (Business Hours) Unlimited Email Support Customer Portal Knowledge Base Nucademy (Nucleus online training) Virtual Support Sessions Enhanced Support Ticket Priority 24x7x365 Critical Support Response (P1 Only) Proactive Monitoring + Support Named Executive Sponsor Slack Communication
For more information visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Endpoint protection has reduced policy rollout time and now manages laptop security centrally
What is our primary use case?
My main use case for Nucleus Security is endpoint security. Nucleus Security is being installed into the personal laptops of the employees, and through that, all the policies are being maintained by the central department of cybersecurity.
What is most valuable?
Nucleus Security offers excellent features including runtime addition or deletion in terms of policy implementation onto specific employees without rebooting the endpoint. The runtime deletion and the fact that we do not need to reboot endpoints has led to less reboot time, and the implementation and turnaround time have increased for the specific department.
Nucleus Security has positively impacted my organization by reducing the turnaround time in terms of implementation. The employees are happy that it does not consume much space in terms of RAM usage. From the employees' feedback, endpoint security used to take up around seventy-five percent of the RAM usage, but now it is reduced to forty percent.
What needs improvement?
Nucleus Security has done a good job, so I suggest maintaining that level of effort.
For how long have I used the solution?
I have been using Nucleus Security for the past one year.
What do I think about the stability of the solution?
Nucleus Security is quite stable.
What do I think about the scalability of the solution?
Nucleus Security's scalability is great and it is working well.
How are customer service and support?
Nucleus Security's customer support is good. I would rate the customer support a nine out of ten.
Which solution did I use previously and why did I switch?
I previously used a different solution called Checkpoint, but we changed it because of the complexity involved in its implementation.
What was our ROI?
I have seen a return on investment from using Nucleus Security. The primary example is that it reduces the time for the turnaround for the implementation of policies, which is a drastic reduction in terms of implementation.
Which other solutions did I evaluate?
Before choosing Nucleus Security, we evaluated many options, with the main competitive one being Palo Alto.
What other advice do I have?
Regarding Nucleus Security's AI capabilities, I am probably not the best one to comment on it; the specific department can provide more insights. As for Nucleus Security's AI capabilities and its accuracy and reliability of output, from what I have heard, it is quite good.
Risk-based prioritization is crucial for addressing vulnerabilities in our organization, and Nucleus Security has contributed significantly by being able to address all of the queries right at runtime. Nucleus Security's integration flexibility with ticketing systems and existing tools has improved our deployment process; it can track pending tasks, and the SLAs are governed by the central ticketing tool, which has helped significantly.
Nucleus Security's ability to handle large volumes of exposure data across complex environments has adhered to all of the requirements for the department, so it has been quite good in handling large data. I have not been able to use the risk reduction measurement feature in Nucleus Security. I have not used the customizable risk model feature either, so I cannot speak to whether it has helped tailor vulnerability prioritization to reflect our environment. I have not been exposed much to natural queries or advanced logic with NQL to identify vulnerabilities, but it is probably quite good; the department was happy implementing it.
I have not been exposed to the pricing, setup cost, and licensing, so I am probably the last one to comment on that because I am just the user of it. The advice I would give to others looking into using Nucleus Security is that it is good, scalable, and robust. I would rate this review overall as a nine out of ten.
Unified vulnerability view has improved risk-based decisions but reporting still needs work
What is our primary use case?
My main use case for Nucleus Security is vulnerability management, along with audit trail commentary and a single pane view.
I can provide a specific example of how I use Nucleus Security for meeting management or audit trails. Nucleus Security filled a gap within the vulnerability management landscape. Multiple tools available did not provide the opportunity to comment against vulnerabilities and assign vulnerabilities automatically. Nucleus Security were pioneers in bringing threat intelligence, EPSS scoring, and threat intelligence Mandiant ratings at the time. It was an opportunity to review and prioritize vulnerabilities differently, but it provides management oversight and capability that did not exist before. The allocation of vulnerabilities, setting due dates, and commentaries were the start of what made Nucleus Security great.
How has it helped my organization?
Nucleus Security has impacted my organization positively by providing a single pane view of vulnerabilities from different connectors and enabling the automation of reporting and alerting on findings that are out of due date or out of SLA. Commentary has provided significant benefit, especially from a licensing perspective, meaning that if an asset exists once, I am never billed twice for those assets as long as they exist in the platform.
Risk-based prioritization is crucial for addressing vulnerabilities in my organization, and Nucleus Security contributes significantly in this area. It is important to note that it is not just Nucleus Security that performs prioritization; multiple vulnerability management scanners do so based on their own threat modeling capabilities. One notable feature of Nucleus Security is its leverage of capability through Google Mandiant, providing real-time threat analytics. The ability to add context to assets, such as whether they are internal or external facing and whether they are critical, is key. Depending on what is important to my company or ecosystem, the prioritization is adjusted, enabling informed decisions on what to tackle next.
What is most valuable?
One of the main benefits of Nucleus Security is having built-in capability or connectors into multiple threat intelligence or vulnerability scanning tools, which enables me to interpret this data with a single connector click without having to do any of that work myself.
The best features Nucleus Security offers are its automation capabilities and the ability to alert application or system owners on their vulnerability posture, letting them know when things are out of SLA and alerting them when things are fixed. It closes the communication cycle, and the most important capabilities are the commentary features, which give visibility of the movement on certain items and the status features. Many vulnerabilities do not get remediated, some are false positives, while others require risk acceptance. The capability to have full control and visibility of the movement of vulnerabilities, whether active or not, is crucial.
The automation and commentary features have changed the way my team works day-to-day. Having a system owner comment on why something has been delayed or when it may be going into production provides context to the vulnerability findings and potential movement.
What needs improvement?
One of the main issues with Nucleus Security is its lack of reporting capability. The user interface resembles an early 2000s application style, and although its speed is decent, it could be improved as more data is ingested. The overall appearance and feel need work, especially compared to modern applications from Rapid7, Qualys, and Tenable, which have more engaging user interfaces. The reporting capability is severely lacking; not being able to filter to granularity or have custom built queries is an annoyance that needs an overhaul. Additionally, there are bugs that have not been resolved, such as when you create a report and remove an asset, the asset still appears in the report despite not being present in the system anymore, leading to issues that need to be addressed quickly.
Nucleus Security can become a difficult investment because I already have a vulnerability management solution, and I question where Nucleus Security fits with its licensing model. While I acknowledge automation has been described, it would be amazing to control the entire vulnerability management workflow from Nucleus Security without needing to log onto other systems. Having controls or actions that can be sent from the console down to the scanner for rescans would be beneficial. If Nucleus Security is going down this path, it should ensure that it becomes a one-stop shop for vulnerability management across multiple applications.
For how long have I used the solution?
I have been using Nucleus Security for about three to four years.
What do I think about the stability of the solution?
Nucleus Security is stable.
What do I think about the scalability of the solution?
The scalability of Nucleus Security is fairly impressive; even when ingesting multiple assets, there is no noticeable impact. I have been in environments with several thousand assets, and it scales in the background without any issues.
How are customer service and support?
Customer support is great; I have always had communication with executive leaders, been able to have roadmap calls, and talk with support. They are fairly responsive with no issues.
How was the initial setup?
The ease of using natural queries or advanced logic with NQL to identify vulnerabilities is fairly simple; it gives an idea of how to build queries and is relatively easy to use.
What about the implementation team?
The integration flexibility with ticketing systems and existing tools has simplified and positively impacted my deployment process with Nucleus Security, as it allows for easy integration into multiple tools.
Nucleus Security excels in handling large volumes of exposure data across complex environments; I believe it is second to none. Even before continuous threat exposure management became a focus, Nucleus Security already identified the potential gap. Although larger players from Rapid7, Qualys, and Tenable have since developed their capabilities, I find Nucleus Security fairly impressive in handling large volumes of exposure data without a noticeable impact on the platform.
What was our ROI?
I have not seen a return on investment in terms of metrics involving fewer employees or money saved, but Nucleus Security saves time. While any deployment requires initial time and effort, once it is set up, the value stream is substantial. Automation handles reporting on a scheduled basis and alerts system owners about their posture each week. In terms of employees, we still need the same number to remediate findings.
What's my experience with pricing, setup cost, and licensing?
The licensing model is straightforward, with one license across multiple assets for multiple connectors. It is always a tough ask regarding budgeting for additional security tools, but in terms of positioning, I find it relatively simple. I cannot recall if the pricing differs from an asset to a container or cloud security workload.
What other advice do I have?
I do not have anything else to add about the features.
I have not really needed to use the customizable risk model feature since we rely on the out-of-the-box capabilities.
I rate Nucleus Security a seven out of ten. I rate customer support an eight out of ten.
I would advise others looking into using Nucleus Security to consider the value offering, especially if they have multiple tools and need a single pane view. While Nucleus Security is great, it is debatable whether it will be the best tool or provide the best value in 2026, as many competitors have moved into the Continuous Threat Exposure Management space. I would recommend assessing existing vulnerability management solutions first before exploring Nucleus Security, as it can be a difficult investment when you have solutions that already meet your needs.
Centralized dashboards have improved risk-based vulnerability focus but integration still needs work
What is our primary use case?
I have been using Nucleus Security for a year.
My main use case for Nucleus Security is primarily for vulnerability management. I can give you a quick, specific example of how I use it for vulnerability management in my organization: we connect that with our public clouds such as Azure . It connects to Azure . For example, if Azure has Defender for Cloud enabled and the vulnerabilities on Azure are being replicated into Nucleus Security, with Nucleus Security, we have asset groups, and we can make sure that we provide good visibility to the required teams.
I have something else to add about how I use Nucleus Security: we have many subscriptions as an example. If we take Azure, we have many Azure subscriptions and all these subscriptions are being looked at by different teams, but the portfolios and the leadership that they report to are almost the same. With Nucleus Security, we have a centralized dashboard for the leadership as well as the teams. We can make sure that role-based access could be granted, so that they can only see the vulnerabilities relevant to them.
How has it helped my organization?
Nucleus Security has positively impacted my organization because we were able to escalate vulnerabilities on time to relevant teams.
I can tell you about specific outcomes: we did not have a centralized platform earlier, which is why we onboarded Nucleus Security. With this, we have really good remediation tracking and workflow management. When new vulnerabilities come in, we have created Jira workflows to create tickets on the respective application teams' Jira board. They are now being prioritized accordingly.
What is most valuable?
The best features Nucleus Security offers, in my opinion, are that it is really great in showcasing things and providing centralized vulnerability management. It also has risk-based prioritization.
The risk-based prioritization has helped my team focus on the most critical vulnerabilities by considering severity, asset context, and the remediation priorities, rather than just looking at the raw vulnerability counts.
Nucleus Security's ability to aggregate, normalize, and organize vulnerability data from different sources into a central, manageable view is also a significant advantage.
I have used the risk reduction measurement feature in Nucleus Security, and it is valuable because it helps translate vulnerability remediation activities into a clearer view of overall security improvement rather than only reporting the number of vulnerabilities closed. It helps the team track reduction in overall exposure all the time and progress against remediation goals.
What needs improvement?
I believe Nucleus Security can be improved due to some integration issues. It could be integrated with SentinelOne, but it was not showing any SentinelOne alerts. If these things could be improved and if those could also be showcased at Nucleus Security, it will be better, not just the vulnerabilities.
What do I think about the stability of the solution?
Nucleus Security is stable.
What do I think about the scalability of the solution?
Nucleus Security's scalability is acceptable.
How are customer service and support?
The customer support is average.
What was our ROI?
I have seen a return on investment, but I cannot share the exact metrics.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was average.
What other advice do I have?
On a scale of one to ten, I would rate Nucleus Security overall a six.
I chose six out of ten because vulnerability management alone is not enough when it comes to security operations. I think if Nucleus Security could provide more features across various other areas, it will be better.
Regarding Nucleus Security's AI capabilities, I do not have any concerns about its governance and security because we reviewed the data classification and all, so we are happy with how they are operating currently.
Regarding Nucleus Security's AI capabilities, in general, it does a good job regarding its accuracy and reliability of output.
I did not purchase Nucleus Security through the AWS Marketplace .
I elaborated on Nucleus Security's feature of providing unified exposure visibility across all tools I use earlier regarding the SentinelOne example.
Risk-based prioritization is very crucial for addressing vulnerabilities in my organization, and I think it helps the team focus on the most critical vulnerabilities.
The integration flexibility with ticketing systems and existing tools has affected my deployment process with Nucleus Security because we were able to do this with Jira workflows very easily.
The advice I would give to others looking into using Nucleus Security is that it is a good tool and covers many areas and tools.
My overall rating for Nucleus Security is six out of ten.
Unified vulnerability workflows have transformed how our teams prioritize and resolve critical risks
What is our primary use case?
In the initial phase when we first brought Nucleus Security into our environment, instead of immediately pushing it into full production, I spent some time exploring the interface, connecting a few test data sources, and seeing how the platform aggregates vulnerabilities in real time. Specifically, I was testing how well it ingested scan data from different tools we use and seeing how the automation rules reacted to those findings. It was basically a hands-on trial period to see how the platform prioritizes the risks and handles asset grouping before we fully integrated it into our daily monitoring and incident response workflows.
I was specifically focusing on setting up automation rules for vulnerability ticketing and risk scoring. In our line of work, we get flooded with scan data from multiple scanners. I wanted to see how intelligently the platform could aggregate those duplicates into a single actionable record. I spent some time setting up the criteria to automatically route high priority vulnerabilities to the right technical teams and tracking how well the tool managed the lifecycle of an incident from discovery to remediation.
In our organization, Nucleus Security is deployed using a hybrid cloud approach. Nucleus Security itself operates as a secure SaaS platform, which makes it incredibly easy to manage without us having to worry about hosting the infrastructure or managing server updates ourselves. However, because our organization manages a complex infrastructure including internal data centers, private cloud environments, and public cloud services, the platform is integrated across all of them. We use their secure connectors and APIs to safely pull vulnerability data from our infrastructure and centralize everything into their cloud interface. This gives us the best of both worlds: a low-maintenance SaaS tool that still has full visibility into our entire hybrid estate.
We use AWS the most within Nucleus Security. A massive chunk of our core cloud infrastructure and workloads live there, so it is naturally our primary data source. We heavily rely on Nucleus Security to ingest and centralize everything coming out of our native AWS security tools, such as Amazon GuardDuty, Inspector , and AWS Security Hub , alongside our standard network and application scanners. The platform is especially useful here because it handles cloud-native vulnerabilities really well, particularly when it comes to tracking ephemeral or short-lived assets and automatically organizing them based on our existing AWS resource tags.
We purchased Nucleus Security directly through the AWS Marketplace . It made the entire procurement and billing process much smoother since we could consolidate the subscription cost right into our existing enterprise AWS billing agreement.
What is most valuable?
For me, the absolute best feature of Nucleus Security is its ability to aggregate and deduplicate data from all our different scanning tools into a single pane of glass. Instead of having our teams dig through separate massive reports from network scanners, cloud tools, and application tests, Nucleus Security normalizes all that data into one place and saves us an incredible amount of manual effort. Another massive standout is the automation engine, which allows us to set up custom triage rules that instantly route high severity vulnerabilities to the right teams or automatically assign due dates based on SLA policies, taking a huge operational burden off our shoulders.
The out-of-the-box API connectors and integrations make it incredibly easy to hook into existing tools without requiring massive custom development. It works smoothly with whatever scanning tools or ticketing platforms we already have in place, which made the initial rollout much less painful.
The biggest positive impact of Nucleus Security has been a massive reduction in our time to remediation. Before using the platform, our technical team spent too many hours trying to sort through conflicting scan data and figure out who was responsible for patching what. By centralizing everything, Nucleus Security has completely eliminated that friction and dramatically cut down on alert fatigue across our infrastructure and support teams because the platform prioritizes risk based on real-world threat intelligence. We are no longer wasting time chasing minor internal issues as if they were major fires. We can instantly pinpoint what is actually critical, assign it to the right teams automatically, and track it through to completion. Nucleus Security has fundamentally changed how we manage our vulnerability lifecycle and made our entire incident response process much more proactive, organized, and reliable.
What needs improvement?
While the platform is incredibly powerful, the initial configuration curve of Nucleus Security can be a bit steep. When first setting up complex, multi-layered automation rules and asset groupings, the interface can feel a little overwhelming. Having more intuitive step-by-step visualized wizards or guided templates for building complex triage workflows would make the onboarding process much smoother for new team members.
Dashboard customization and reporting would definitely be on my wish list. While the default dashboards are great for a general overview, it can take a bit of manual tweaking when building highly tailored workspace views for different engineering groups. Having a more flexible drag-and-drop widget system where individual teams can prioritize exactly what metrics they see first on their layout would be a huge quality of life update. On the reporting side, the data it generates is solid, but I would like to see more granular control over formatting within the platform itself. Sometimes leadership wants data tailored in very specific ways, and currently, we occasionally have to export the data and clean it up externally to meet those exact visual preferences.
For how long have I used the solution?
I have been using Nucleus Security for over four years.
What do I think about the stability of the solution?
Nucleus Security is definitely stable. I would recommend it to anyone in this role to get this task done easily. We rarely, if ever, encounter downtime or performance degradation, even when the platform is running massive automation rules and background synchronization tasks during peak operational hours. It feels incredibly enterprise-grade and dependable.
What do I think about the scalability of the solution?
Nucleus Security performs at a high rate for scalability. The platform has done a great job of handling both stability and scalability excellently. On the scalability part, it grows seamlessly as we have onboarded new cloud workloads.
How are customer service and support?
I would describe Nucleus Security's customer support as absolutely fantastic. I would rate the customer support of Nucleus Security at a ten on a scale of one to ten.
Which solution did I use previously and why did I switch?
This is the first vulnerability management solution that I have tried out, and it worked well for us. I did not get to evaluate other options as this was suggested by our client to see how it would work for us, and it definitely made our day easier and our task easier as well.
How was the initial setup?
I would advise starting with Nucleus Security from scratch and then making use of all the tools in place so that it would give a better understanding of things. My biggest piece of advice would be to map out your existing vulnerability management and incident response workflows before starting to build out your rules in the platform.
What was our ROI?
We have seen an absolutely clear return on investment in Nucleus Security, and it primarily shows up in massive time savings and vastly improved resource utilization. Rather than reducing our headcount or needing fewer employees, it has been about reclaiming engineering hours. Before implementing the platform, our core technical teams were spending roughly fifteen to twenty hours a week just manually aggregating spreadsheets, trying to deduplicate scanning data, and routing tickets to the right infrastructure owners.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified vulnerability data has transformed risk prioritization and optimized remediation effort
What is our primary use case?
My main use case for Nucleus Security is unifying the vulnerability management landscape, providing a single source of truth for vulnerabilities.
What is most valuable?
The best features that Nucleus Security offers in my experience are the unified integrations with all of the different vulnerability management platforms. It is helping quite a lot to unify all of that. It also offers good prioritization based on the EPSS or the CVSS score, as well as different other factors including Mandiant threat intelligence and similar aspects. It helps bring it all into one big picture instead of different silos of vulnerabilities.
The integrations make my job easier because I can connect my other tools, which is the most important part of this tool to bring in all the vulnerabilities from the different other tools. The prioritization changed it from chasing vulnerabilities or pushing colleagues to patch vulnerabilities to providing colleagues with their vulnerabilities and requesting remediation and patching.
Nucleus Security positively impacts my organization by bringing awareness to vulnerability management since we can actually determine how many vulnerabilities we have and how critical the risk is, or we can quantify the risk overall for the company.
What needs improvement?
Nucleus Security needs a better view into exposure management, as exposure management and attack path management are missing. It also needs better and easier self-service integrations, as the integration might take longer than desired.
I do not really use the integration with the ticketing systems. It is reliable, but it is not that easy. I think they will improve it in the future to make it easier to integrate new tools.
For how long have I used the solution?
I have been using Nucleus Security for around two years.
What do I think about the stability of the solution?
Nucleus Security is stable most of the time, but not always; the performance varies.
What do I think about the scalability of the solution?
As long as I purchase enough licenses, Nucleus Security can scale as much as I want.
How are customer service and support?
Customer support has met our expectations. While faster response times would enhance the experience, the support provided has been reliable and effective.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; the topic of unified vulnerability management is rather new, so I did not have any solution before that.
How was the initial setup?
The pricing, setup costs, and licensing are reasonable; while it isn’t a budget option, it offers fair value for the price.
What was our ROI?
I have seen a return on investment. With security, it is always hard to quantify, and we did not really save money, but we used time more effectively and changed our way of working. I would say time saved is the primary benefit.
Which other solutions did I evaluate?
Before choosing Nucleus Security, I evaluated other options and looked into all the other solutions, but at that point in time, Nucleus Security was the main company offering something like this, making it clear that Nucleus Security would be the company to go with.
What other advice do I have?
I assess Nucleus Security's feature of providing unified exposure visibility across all tools I use as great because I can use all of the data and get all the vulnerabilities in one central place. It has a lot of capabilities, and this is the strongest feature of Nucleus Security. Providing this unified exposure visibility is doing a good job. The integrations could be easier, but the rest is working rather well. I have to work a lot with asset rule lists, so I have to do a lot of automation or processing of the data in Nucleus Security, but at the end of the day, as soon as I set up those rules, I am good to go.
Risk-based prioritization is crucial for addressing vulnerabilities in my organization because I cannot fix all the vulnerabilities; I have to know what I need to handle, how big the risk is, and what the highest risk is that I need to tackle. That is exactly what Nucleus Security is offering.
I did not use the risk reduction measurement feature in Nucleus Security, as risk reduction measurement is not something I am familiar with, but I have used the metrics and trends from Nucleus Security to assess how we are developing, especially regarding the remediation performance.
My advice for others looking into using Nucleus Security is to think about your processes as well. You need to consider where you want to go and think a lot about how you want to use and work with vulnerabilities in the future. I have given this review a rating of eight out of ten.