Nucleus Security launches Helix AI engine for exposure management
Nucleus Security launched AI engine Nucleus Helix for exposure management, adding discovery, natural-language interface and expanded threat intelligence.
One of the new capabilities, an expansion of the company’s Nucleus Insights vulnerability intelligence service, is available immediately. The other two — Nucleus Discover and the Nucleus Helix AI Agent — are set to arrive in September. Nucleus Discover is a detection tool designed to surface exposures in the window between a vulnerability becoming public and a scanner learning to identify it. The Nucleus Helix AI Agent adds a natural-language interface for querying findings, tracing affected asset ownership and starting workflows.
Helix draws on the Nucleus Data Core, the normalized store of asset, vulnerability and ownership data the platform already keeps. Nucleus said the engine has three main tasks: building and maintaining a customer’s exposure management program; having reasoning agents close gaps where exposure has gone undetected; and tracking the shifting threat landscape.
Nucleus Discover performs passive detection in areas where scanners do not provide coverage and in newly disclosed flaws that do not yet have a signature. The company describes this as early warning. The Helix AI Agent lets practitioners, chief information security officers and developers type requests rather than work through configuration screens.
The expanded Insights service adds a data-collection agent that reports on in-the-wild attacks, plus new datasets covering Patch Tuesday, end-of-life operating systems and CISA’s Stakeholder-Specific Vulnerability Categorization decision framework. Nucleus said these additions cut investigation effort and sharpen remediation guidance.
The SSVC dataset comes as federal agencies adjust to Binding Operational Directive 26-04, which took effect on June 10 and eliminated fixed patch windows. Under the directive, a flaw already listed in CISA’s Known Exploited Vulnerabilities catalog or a device exposed to the internet pushes an asset up the priority scale, and the worst combinations carry a three-day remediation deadline. Carnegie Mellon University’s CERT Coordination Center has published an SSVC decision tree for agencies implementing the directive.
Nucleus holds FedRAMP Moderate authorization, which lets federal civilian agencies buy the platform. The company said it also supports the Department of Defense and defense industrial base contractors operating under CMMC 2.0. Nucleus, a venture capital-backed startup, last raised $20 million in a Series C round in February and has raised approximately $86.1 million to date.
Michelle Abraham, research vice president in International Data Corp.’s Security and Trust Group, said Nucleus is taking a pragmatic approach by using AI to shape and improve processes while keeping deterministic execution for anything that touches production. Teams want the speed of AI without losing predictability in what actually gets changed, she added.