Breaking
$20M Series C closed Feb 2026, led by Delta-v Capital 500+ enterprise & public sector customers Gartner Challenger in first Exposure Assessment Platforms Magic Quadrant Best Vulnerability Management Solution, 2026 SC Awards 200+ data sources ingested into one system of record FedRAMP Moderate authorized for federal agencies $20M Series C closed Feb 2026, led by Delta-v Capital 500+ enterprise & public sector customers Gartner Challenger in first Exposure Assessment Platforms Magic Quadrant Best Vulnerability Management Solution, 2026 SC Awards 200+ data sources ingested into one system of record FedRAMP Moderate authorized for federal agencies

Company Profile / Cybersecurity

The Company Betting That Scanning Was Never the Hard Part

Every enterprise already owns a dozen scanners that find problems. Nucleus Security built a business on the boring, unglamorous job nobody else wanted: figuring out which of the millions of findings actually matter.

Ask a security team about their worst day and they rarely describe the moment a scanner found a vulnerability. They describe the morning after: a spreadsheet with four million rows, thirty different tools all screaming in different formats, and one honest question no dashboard could answer - which of these do we fix first? Nucleus Security, a company headquartered in Sarasota, Florida, was built entirely around that question. It does not scan for a single vulnerability of its own. It sits on top of everything that does.

That is a strange thing to build a company on. Detection is the glamorous half of cybersecurity - the part with the red graphics and the countdown clocks. Triage is the part everyone actually drowns in. When Steve Carter, Scott Kuffer, and Nick Fleming founded Nucleus in 2019, drawing on years of Department of Defense security work, they made a bet that most of the industry had the problem backwards. Finding vulnerabilities had become easy and cheap. Deciding what to do about them had not.

200+Data sources unified
500+Organizations served
~130Employees
$66MRaised to date

01What the company actually does

Nucleus calls itself a unified vulnerability and exposure management platform, which is a mouthful for a fairly concrete job. The software continuously pulls in data from more than 200 sources - vulnerability scanners like Tenable and Qualys, cloud security tools, asset inventories, ticketing systems, threat intelligence feeds - and normalizes all of it into a single, lifecycle-aware record. The same server showing up under five different names across five tools becomes one asset. The same flaw reported by three scanners becomes one finding, not three.

Then comes the part that pays the bills: prioritization. Nucleus scores each vulnerability using asset context, business context, and real-world threat intelligence - including whether attackers are actively exploiting it in the wild, cross-referenced against sources like CISA's Known Exploited Vulnerabilities catalog. The output is not a longer list. It is a shorter one. The few hundred things worth someone's weekend, ranked, with the busywork of ticketing and reporting automated on the back end.

Nucleus Security executive metrics dashboard
The board's-eye view. Nucleus's executive trends screen turns four million scanner rows into something a CISO can put on one slide without lying about it.

Nucleus doesn't run a single scanner of its own. The entire product is about making sense of the tools you already bought.

02The problem, drawn to scale

To understand why customers pay for this, it helps to see the shape of the pile. A large enterprise's scanners will happily surface millions of raw findings. Deduplication collapses that. Threat and asset context collapses it again. What survives - the genuinely exploitable, genuinely reachable, genuinely important - is a tiny fraction of where you started. The whole value of the platform lives in that narrowing.

From noise to a to-do list — illustrative funnel

Raw scanner findings
~4,000,000
After deduplication
~1,500,000
With asset & business context
~120,000
Actively exploitable / prioritized
~800

Figures above are illustrative of the funnel's shape, not a specific customer's numbers. The point is the ratio: the work is in the narrowing, not the finding.

03Who's actually using it

The customer roster is more eclectic than you would guess for a company that markets itself so quietly. Nucleus says it serves more than 500 enterprise and public sector organizations. Named users span technology, insurance, retail, telecom, and the sort of institutions that do not usually appear in the same sentence.

CiscoAutodeskMotorolaPaychexCBRE GroupJC PenneyRSA InsuranceSwisscomUdemyAmerican Red CrossAustralia PostPremier League

There is a second, quieter customer base: the U.S. federal government. Nucleus is FedRAMP Moderate authorized and approved for the government's Continuous Diagnostics and Mitigation program - credentials that take years and real money to earn, and that keep most competitors out of the room entirely.

The Nucleus Security team
The room where the deduping happens. The Nucleus team, whose founders came out of Department of Defense security work before deciding the busywork was a business.

04The federal paperwork play

If there is a single feature that captures how Nucleus thinks, it is the one it built for a task no one enjoys. Federal security teams live under the POA&M - the Plan of Action and Milestones - a compliance process of tracking every open finding, its remediation deadline, and its audit evidence. It is spreadsheets, deadlines, and dread. In 2024, Nucleus launched POAM Process Automation to run it: centralized tracking, SLA assignment tied automatically to standards like CISA KEV (15 days for critical, 30 for high), and audit-ready evidence in one place.

It is not a flashy feature. It is exactly the kind of unglamorous, deeply annoying problem the whole company was built to eat.

Nucleus Security risk context view
Context, not just a CVSS score. The risk view weighs whether a flaw is reachable and actively exploited - the difference between a real fire and a smoke alarm with a low battery.

05How it's different from the alternatives

The risk-based vulnerability management category is not empty. The usual alternatives are Cisco Vulnerability Management (formerly Kenna.VM), Brinqa, and Vulcan Cyber, with open-source DefectDojo lurking for smaller teams. Reviewers tend to give Cisco the edge on raw feature depth, while Nucleus draws consistent praise for ease of deployment and support - the boring virtues that decide whether a platform actually gets used.

ApproachWhat it optimizes for
Nucleus SecurityScanner-agnostic aggregation, prioritization, fast deployment, federal compliance
Cisco (Kenna.VM)Deep feature set, native to the Cisco security stack
BrinqaHighly customizable risk modeling and data connectors
Vulcan CyberRemediation orchestration and workflow tooling

The strategic tell is what Nucleus refuses to do: it will not compete on detection. It stays scanner-agnostic on purpose, positioning itself as connective tissue rather than another tool fighting for the same budget line. That is also its main risk - a platform that depends on everyone else's tools is only as valuable as the ecosystem it sits inside.

06The money, and the market bet

Nucleus has raised roughly $66 million across three rounds, starting small and staying disciplined. Arthur Ventures backed it early and kept backing it; Lead Edge Capital led the growth round; Delta-v Capital led the $20 million Series C that closed in February 2026. The business runs on straightforward B2B SaaS subscriptions, priced by scale, with estimated annual revenue around $18 million.

Funding rounds — USD raised

$3.1M
Series A
2020
$43M*
Series B
2022
$20M
Series C
2026

*Series B shown as reported aggregate growth funding. Some outlets place Nucleus's cumulative total higher than $66M.

Vulnerability and exposure management is increasingly a board-level responsibility; we believe Nucleus is uniquely positioned to define the next phase of this market.Connor Heard, Principal, Delta-v Capital

That quote is also the thesis. The industry vocabulary is shifting from "vulnerability management" to "exposure management" and "continuous threat exposure management" (CTEM) - a broader idea that risk is not just unpatched software but a continuous, business-context question. Nucleus repositioned itself as the system of record for assets, vulnerabilities, and exposures, and the timing has been kind: in 2025 Gartner published its first Magic Quadrant for Exposure Assessment Platforms and placed Nucleus as a Challenger, highest among Challengers on Ability to Execute.

07Expertise, and where it fits

The company's self-description - "built by security practitioners, for security practitioners" - is the kind of line that usually means nothing. Here it maps to the product. The founders spent years doing vulnerability management the hard way before building the tool, and it shows in the choices: the obsessive deduplication, the federal compliance automation, the refusal to reinvent scanning. Nucleus reports customers cutting mean time to remediate by around 60% within six months - a metric that only makes sense if you believe the bottleneck was always triage, never detection.

Where it fits in the market is precisely in the middle: above the scanners, below the boardroom, translating one into the other. The 2026 trophy case backs the position - Best Vulnerability Management Solution at the SC Awards, four Global InfoSec Awards, and four gold Cybersecurity Excellence Awards. For anyone weighing the platform, the honest read is this: if your problem is that you cannot see your vulnerabilities, Nucleus is not a scanner and will not help. If your problem is that you can see all of them and have no idea which matter, that is the entire pitch.