# Nucleus Security

> Nucleus Security is a Sarasota, Florida company that unifies the messy output of 200+ security scanners into one system of record, then tells enterprises and government agencies which vulnerabilities to actually fix first. Founded in 2019 by former Department of Defense security practitioners, it now serves 500+ organizations, from Cisco and Autodesk to federal agencies, and closed a $20M Series C in February 2026 to push its move from vulnerability management into full exposure management.

- **Founded:** 2019
- **Headquarters:** Sarasota, Florida, United States
- **Founders:** Steve Carter (CEO & Co-founder), Scott Kuffer (COO/CPO & Co-founder), Nick Fleming (Chief Engineer & Co-founder)
- **Team size:** ~130 employees
- **Products:** Unified Vulnerability & Exposure Management Platform, Vulnerability Aggregation, Risk-Based Prioritization, Remediation Workflows & Automation, Nucleus POAM Process Automation
- **Notable:** Named a Challenger in the first-ever 2025 Gartner Magic Quadrant for Exposure Assessment Platforms - positioned highest among Challengers in Ability to Execute, Best Vulnerability Management Solution at the 2026 SC Awards, Winner of four 2026 Global InfoSec Awards (Exposure Assessment, Exposure Management, CTEM, RBVM)

## Products & services

- **Unified Vulnerability & Exposure Management Platform** — Continuously ingests, normalizes, and correlates data from 200+ security, asset, and infrastructure sources into a single lifecycle-aware data core, giving teams one place to see and act on risk across IT, cloud, application, and OT environments.
- **Vulnerability Aggregation** — Deduplicates and unifies scanner output across the enterprise, matching findings to assets so teams stop counting the same vulnerability five times.
- **Risk-Based Prioritization** — Scores and ranks vulnerabilities using asset context, business context, and real-world threat intelligence (including CISA KEV and exploit data) so teams fix what an attacker would actually target.
- **Remediation Workflows & Automation** — Automates ticketing, SLA assignment, and remediation orchestration across ServiceNow, Jira, and other operational systems.
- **Nucleus POAM Process Automation** — Automates the federal Plan of Action & Milestones (POA&M) process - centralized tracking, automated SLA assignment tied to CISA KEV, and audit-ready evidence storage for federal agencies and their vendors.
- **Vulnerability Intelligence** — Enriches findings with threat context and exploitability data to separate theoretical risk from active, exploitable risk.

## Achievements

- Named a Challenger in the first-ever 2025 Gartner Magic Quadrant for Exposure Assessment Platforms - positioned highest among Challengers in Ability to Execute
- Best Vulnerability Management Solution at the 2026 SC Awards
- Winner of four 2026 Global InfoSec Awards (Exposure Assessment, Exposure Management, CTEM, RBVM)
- Gold winner in four categories at the 2026 Cybersecurity Excellence Awards
- FedRAMP Moderate Authorized and CDM-approved for federal agencies
- CEO Steve Carter named a 2025 Security Business Innovator
- Deloitte Technology Fast 500 recognition
- Reported average 60% reduction in mean time to remediate within six months for customers

## Latest updates

- **2026-02** — Closed a $20M Series C led by Delta-v Capital, with Arthur Ventures participating, to scale exposure management operations and R&D.
- **2026-01** — Named Best Vulnerability Management Solution at the 2026 SC Awards and won four 2026 Global InfoSec Awards.
- **2025-10** — Placed as a Challenger in the first Gartner Magic Quadrant for Exposure Assessment Platforms.
- **2024-10** — Launched Nucleus POAM Process Automation for federal agencies and their vendors.

## Links

- Website: https://nucleussec.com
- LinkedIn: http://www.linkedin.com/company/nucleussec
- Twitter/X: https://twitter.com/nucleussec
- Facebook: https://facebook.com/nucleussec

---

Profile page: https://yespress.io/nucleus-security
Published by YesPress — https://yespress.io
Last updated: 2026-08-20
