Company Profile / Cybersecurity
The Company Betting That Scanning Was Never the Hard Part
Every enterprise already owns a dozen scanners that find problems. Nucleus Security built a business on the boring, unglamorous job nobody else wanted: figuring out which of the millions of findings actually matter.
Ask a security team about their worst day and they rarely describe the moment a scanner found a vulnerability. They describe the morning after: a spreadsheet with four million rows, thirty different tools all screaming in different formats, and one honest question no dashboard could answer - which of these do we fix first? Nucleus Security, a company headquartered in Sarasota, Florida, was built entirely around that question. It does not scan for a single vulnerability of its own. It sits on top of everything that does.
That is a strange thing to build a company on. Detection is the glamorous half of cybersecurity - the part with the red graphics and the countdown clocks. Triage is the part everyone actually drowns in. When Steve Carter, Scott Kuffer, and Nick Fleming founded Nucleus in 2019, drawing on years of Department of Defense security work, they made a bet that most of the industry had the problem backwards. Finding vulnerabilities had become easy and cheap. Deciding what to do about them had not.
01What the company actually does
Nucleus calls itself a unified vulnerability and exposure management platform, which is a mouthful for a fairly concrete job. The software continuously pulls in data from more than 200 sources - vulnerability scanners like Tenable and Qualys, cloud security tools, asset inventories, ticketing systems, threat intelligence feeds - and normalizes all of it into a single, lifecycle-aware record. The same server showing up under five different names across five tools becomes one asset. The same flaw reported by three scanners becomes one finding, not three.
Then comes the part that pays the bills: prioritization. Nucleus scores each vulnerability using asset context, business context, and real-world threat intelligence - including whether attackers are actively exploiting it in the wild, cross-referenced against sources like CISA's Known Exploited Vulnerabilities catalog. The output is not a longer list. It is a shorter one. The few hundred things worth someone's weekend, ranked, with the busywork of ticketing and reporting automated on the back end.
Nucleus doesn't run a single scanner of its own. The entire product is about making sense of the tools you already bought.
02The problem, drawn to scale
To understand why customers pay for this, it helps to see the shape of the pile. A large enterprise's scanners will happily surface millions of raw findings. Deduplication collapses that. Threat and asset context collapses it again. What survives - the genuinely exploitable, genuinely reachable, genuinely important - is a tiny fraction of where you started. The whole value of the platform lives in that narrowing.
From noise to a to-do list — illustrative funnel
Figures above are illustrative of the funnel's shape, not a specific customer's numbers. The point is the ratio: the work is in the narrowing, not the finding.
03Who's actually using it
The customer roster is more eclectic than you would guess for a company that markets itself so quietly. Nucleus says it serves more than 500 enterprise and public sector organizations. Named users span technology, insurance, retail, telecom, and the sort of institutions that do not usually appear in the same sentence.
There is a second, quieter customer base: the U.S. federal government. Nucleus is FedRAMP Moderate authorized and approved for the government's Continuous Diagnostics and Mitigation program - credentials that take years and real money to earn, and that keep most competitors out of the room entirely.
04The federal paperwork play
If there is a single feature that captures how Nucleus thinks, it is the one it built for a task no one enjoys. Federal security teams live under the POA&M - the Plan of Action and Milestones - a compliance process of tracking every open finding, its remediation deadline, and its audit evidence. It is spreadsheets, deadlines, and dread. In 2024, Nucleus launched POAM Process Automation to run it: centralized tracking, SLA assignment tied automatically to standards like CISA KEV (15 days for critical, 30 for high), and audit-ready evidence in one place.
It is not a flashy feature. It is exactly the kind of unglamorous, deeply annoying problem the whole company was built to eat.
05How it's different from the alternatives
The risk-based vulnerability management category is not empty. The usual alternatives are Cisco Vulnerability Management (formerly Kenna.VM), Brinqa, and Vulcan Cyber, with open-source DefectDojo lurking for smaller teams. Reviewers tend to give Cisco the edge on raw feature depth, while Nucleus draws consistent praise for ease of deployment and support - the boring virtues that decide whether a platform actually gets used.
| Approach | What it optimizes for |
|---|---|
| Nucleus Security | Scanner-agnostic aggregation, prioritization, fast deployment, federal compliance |
| Cisco (Kenna.VM) | Deep feature set, native to the Cisco security stack |
| Brinqa | Highly customizable risk modeling and data connectors |
| Vulcan Cyber | Remediation orchestration and workflow tooling |
The strategic tell is what Nucleus refuses to do: it will not compete on detection. It stays scanner-agnostic on purpose, positioning itself as connective tissue rather than another tool fighting for the same budget line. That is also its main risk - a platform that depends on everyone else's tools is only as valuable as the ecosystem it sits inside.
06The money, and the market bet
Nucleus has raised roughly $66 million across three rounds, starting small and staying disciplined. Arthur Ventures backed it early and kept backing it; Lead Edge Capital led the growth round; Delta-v Capital led the $20 million Series C that closed in February 2026. The business runs on straightforward B2B SaaS subscriptions, priced by scale, with estimated annual revenue around $18 million.
Funding rounds — USD raised
*Series B shown as reported aggregate growth funding. Some outlets place Nucleus's cumulative total higher than $66M.
Vulnerability and exposure management is increasingly a board-level responsibility; we believe Nucleus is uniquely positioned to define the next phase of this market.Connor Heard, Principal, Delta-v Capital
That quote is also the thesis. The industry vocabulary is shifting from "vulnerability management" to "exposure management" and "continuous threat exposure management" (CTEM) - a broader idea that risk is not just unpatched software but a continuous, business-context question. Nucleus repositioned itself as the system of record for assets, vulnerabilities, and exposures, and the timing has been kind: in 2025 Gartner published its first Magic Quadrant for Exposure Assessment Platforms and placed Nucleus as a Challenger, highest among Challengers on Ability to Execute.
07Expertise, and where it fits
The company's self-description - "built by security practitioners, for security practitioners" - is the kind of line that usually means nothing. Here it maps to the product. The founders spent years doing vulnerability management the hard way before building the tool, and it shows in the choices: the obsessive deduplication, the federal compliance automation, the refusal to reinvent scanning. Nucleus reports customers cutting mean time to remediate by around 60% within six months - a metric that only makes sense if you believe the bottleneck was always triage, never detection.
Where it fits in the market is precisely in the middle: above the scanners, below the boardroom, translating one into the other. The 2026 trophy case backs the position - Best Vulnerability Management Solution at the SC Awards, four Global InfoSec Awards, and four gold Cybersecurity Excellence Awards. For anyone weighing the platform, the honest read is this: if your problem is that you cannot see your vulnerabilities, Nucleus is not a scanner and will not help. If your problem is that you can see all of them and have no idea which matter, that is the entire pitch.
Explore & Connect
- Webnucleussec.com
- LinkedIn/company/nucleussec
- X@nucleussec
- Facebook/nucleussec
- CEOSteve Carter
- PlatformPOA&M Automation
- NewsSeries C announcement
- GuideWhat is exposure management?