No more typing reviews! Try our Samantha, our new voice AI agent.

Nucleus Security vs The NodeZero Platform by Horizon3.ai comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 23, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.0
Qualys TotalCloud streamlines vulnerability remediation and operations, improving efficiency and saving significant costs and resources.
Sentiment score
7.3
Nucleus Security enhances time savings and workflow efficiency through task automation, improving resource allocation and engineering productivity.
Sentiment score
3.8
NodeZero Platform reduces pen testing costs and time while enhancing security, saving up to 20% and improving efficiency.
It has saved about 90% of our time.
Senior Consultant at a consultancy with 10,001+ employees
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
Security Manager at a consultancy with 10,001+ employees
CallStream helps us integrate and automate tasks.
Senior Security Consultant at CyberNxt Solutions LLP
With security, it is always hard to quantify, and we did not really save money, but we used time more effectively and changed our way of working.
Cyber Security Architect at a retailer with 10,001+ employees
We have seen an absolutely clear return on investment in Nucleus Security, and it primarily shows up in massive time savings and vastly improved resource utilization.
Manager at a computer software company with 201-500 employees
Automation handles reporting on a scheduled basis and alerts system owners about their posture each week.
Vulnerability And Compliance Manager at a insurance company with 5,001-10,000 employees
A reduction in remediation time has been seen because it is finding things before they happen.
Director of Enterprise Security at a energy/utilities company with 51-200 employees
Being able to find them because there have been no eyes on that particular section so far ever, and fixing those potentially prevented those companies from getting breached.
IT Security Consultant at Systemhaus for you GmbH
So far, I have seen a return on investment with The NodeZero Platform by Horizon3.ai, as we managed to save a lot of time and effort with this because this is an autonomous tool, and our manual effort is significantly reduced because of a product of this type.
Senior Manager | Manager Security Services at RISK ASSOCIATES
 

Customer Service

Sentiment score
6.8
Qualys TotalCloud's customer service is generally satisfactory, with reliable support but needing improvements in communication and timeliness.
Sentiment score
8.2
Nucleus Security's customer service is highly praised for being reliable, effective, and offering helpful, timely responses, ensuring strong satisfaction.
Sentiment score
7.3
NodeZero Platform provides excellent support with fast responses and knowledgeable staff, achieving high satisfaction ratings from users.
They are helpful, respond to my queries, and can answer any question.
Developer at a consultancy with 10,001+ employees
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Service Manager, Security Operations at CDA IT SOLUTIONS
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
Works at a consultancy with 10,001+ employees
I would describe Nucleus Security's customer support as absolutely fantastic.
Manager at a computer software company with 201-500 employees
Customer support is great; I have always had communication with executive leaders, been able to have roadmap calls, and talk with support.
Vulnerability And Compliance Manager at a insurance company with 5,001-10,000 employees
Overall, when it comes to The NodeZero Platform's tech support, you can reach them via a chat message on their website, and they respond almost immediately.
Director of IT Security at a manufacturing company with 1,001-5,000 employees
Previously, with time-sensitive engagements, I would worry about resolving issues before deadlines. That concern has diminished as they've become more responsive and require less escalation to engineering.
Principal Consultant at JTI Cybersecurity
The vast majority of times they are able to resolve the exact questions my team has on the first attempt, which is really good for customer or technical support.
Chief Information Officer at a construction company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
7.4
Qualys TotalCloud is scalable and adaptable, though it may need experienced management and external tools for optimal visualization.
Sentiment score
8.5
Nucleus Security offers seamless scalability, enhancing performance, supporting growth, and managing extensive assets with an efficient centralized interface.
Sentiment score
7.4
NodeZero by Horizon3.ai offers scalable, flexible, and efficient deployment across networks, supporting extensive coverage and multiple concurrent tests.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
CIO at a venture capital & private equity firm with 11-50 employees
Our organization currently uses it to manage over 1200 web applications.
Analyst, Information Security at Infosys
It is absolutely scalable, and I would rate its scalability as nine out of ten.
retired at a consultancy with 10,001+ employees
The platform has done a great job of handling both stability and scalability excellently.
Manager at a computer software company with 201-500 employees
The scalability of Nucleus Security is fairly impressive; even when ingesting multiple assets, there is no noticeable impact.
Vulnerability And Compliance Manager at a insurance company with 5,001-10,000 employees
We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues.
CEO at cybovate
We currently scan approximately 1,500-2,000 assets and haven't encountered any scaling or throughput issues.
Information Security Manager at a non-profit with 51-200 employees
The platform offers various insider threats, segmentation tests, phishing tests, and PCI DSS tests.
Head Dig IT Al And Response/ Consultant at a tech services company with 11-50 employees
 

Stability Issues

Sentiment score
8.3
Qualys TotalCloud is praised for its reliable performance, high stability ratings, and effective support, ensuring minimal disruptions.
Sentiment score
8.4
Nucleus Security is praised for stability and reliability, performing well under heavy loads and large automation tasks.
Sentiment score
8.3
The NodeZero Platform is stable, reliable, and performs well, with occasional external scan delays and minor optimizations needed.
Overall, the support provided has been excellent.
Analyst, Information Security at Infosys
It is a stable solution, which is why we chose it.
CIO at a venture capital & private equity firm with 11-50 employees
Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
Developer at a consultancy with 10,001+ employees
We rarely, if ever, encounter downtime or performance degradation, even when the platform is running massive automation rules and background synchronization tasks during peak operational hours.
Manager at a computer software company with 201-500 employees
We have not encountered any issues on the platform regarding accessibility, performance, or stability.
CEO at cybovate
Regarding stability, it has never crashed, and there has not been any lagging from deployment or running.
Director of Enterprise Security at a energy/utilities company with 51-200 employees
I would rate the stability of The NodeZero Platform by Horizon3.ai as a ten.
Senior Manager | Manager Security Services at RISK ASSOCIATES
 

Room For Improvement

Qualys TotalCloud needs improvements in remediation, integration, UI, vulnerability detection, compliance, container security, and pricing competitiveness.
Nucleus Security requires intuitive UI, enhanced reporting, streamlined integration, and better onboarding with customizable dashboards and exposure management.
Users want better flexibility, integration, scalability, testing efficiency, visibility, and reporting in vulnerability management and notification systems.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Analyst, Information Security at Infosys
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Project Lead at Persistent Systems
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Senior Information Security Engineer at a consultancy with 10,001+ employees
Nucleus Security needs a better view into exposure management, as exposure management and attack path management are missing.
Cyber Security Architect at a retailer with 10,001+ employees
Having more intuitive step-by-step visualized wizards or guided templates for building complex triage workflows would make the onboarding process much smoother for new team members.
Manager at a computer software company with 201-500 employees
It could be integrated with SentinelOne, but it was not showing any SentinelOne alerts.
Head of Security at a consultancy with 51-200 employees
This service reveals which credentials and email addresses are available on the deep web, as well as which domains have been set up using typo-squatting techniques.
Information Security Manager at a non-profit with 51-200 employees
The one thing that is very much asked from us as a service provider is DAST testing, so when a company is building a software, they could see their current security status while they are building the application.
Offensive Security Analyst at a tech services company with 201-500 employees
If that pen test could be load balanced on more than one system, I believe The NodeZero Platform by Horizon3.ai could leverage that system and complete penetration tests in a much quicker time frame, providing quicker results to customers.
Lead Security Engineer at a healthcare company with 10,001+ employees
 

Setup Cost

Qualys TotalCloud offers comprehensive features and flexibility, justifying its higher cost for larger organizations and VMware users.
Enterprise users appreciate Nucleus Security's competitive pricing, straightforward licensing, and value-driven features despite initial costs.
Enterprise users appreciate Horizon3.ai's competitive pricing and flexible IP-based licensing as cost-efficient compared to traditional methods.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Senior Manager at a financial services firm with 10,001+ employees
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
IT Manager at a consultancy with 10,001+ employees
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
Vice President at Inspira Enterprise
The licensing model is straightforward, with one license across multiple assets for multiple connectors.
Vulnerability And Compliance Manager at a insurance company with 5,001-10,000 employees
The pricing is much more affordable than traditional penetration tests.
Manager, Information Technology at a performing arts with 11-50 employees
It's a bit cheaper than manual penetration testing because manual testing typically allows you to scan only a few subnets.
Works at a hospitality company with 201-500 employees
Usually, manual penetration test scans take considerable time and money.
Security Engineer at Herjavec Group
 

Valuable Features

Qualys TotalCloud enhances cloud security with accurate vulnerability detection, automation, centralized monitoring, and robust integration with AWS and Azure.
Nucleus Security enhances safety and efficiency by streamlining risk management, integrating tools, and prioritizing risks for faster remediation.
The NodeZero Platform offers automated, user-friendly penetration testing, providing instant vulnerability insights and enhancing cybersecurity efficiency.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
Works at a consultancy with 10,001+ employees
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
Developer at a consultancy with 10,001+ employees
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
Senior Consultant at a consultancy with 10,001+ employees
By centralizing everything, Nucleus Security has completely eliminated that friction and dramatically cut down on alert fatigue across our infrastructure and support teams because the platform prioritizes risk based on real-world threat intelligence.
Manager at a computer software company with 201-500 employees
The risk-based prioritization has helped my team focus on the most critical vulnerabilities by considering severity, asset context, and the remediation priorities.
Head of Security at a consultancy with 51-200 employees
The best features that Nucleus Security offers in my experience are the unified integrations with all of the different vulnerability management platforms.
Cyber Security Architect at a retailer with 10,001+ employees
When a new vulnerability, such as a zero-day exploit, is identified, they review your previous scans to determine if you might be vulnerable to it, and they proactively notify you.
Director of IT Security at a manufacturing company with 1,001-5,000 employees
The detailed reports not only list the vulnerabilities that matter, but they also include direct links to patches.
Information Security Manager at a non-profit with 51-200 employees
The NodeZero Platform's real attack capabilities help in identifying vulnerabilities on our on-prem systems because it provides actual vulnerabilities by attacking our systems.
Chief Information Security Officer at a construction company with 1,001-5,000 employees
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Vulnerability Management
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
44
Ranking in other categories
Container Security (12th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Nucleus Security
Ranking in Vulnerability Management
43rd
Average Rating
7.2
Reviews Sentiment
7.3
Number of Reviews
4
Ranking in other categories
Application Security Tools (29th), Risk-Based Vulnerability Management (14th), Continuous Threat Exposure Management (CTEM) (12th)
The NodeZero Platform by Ho...
Ranking in Vulnerability Management
9th
Average Rating
8.8
Reviews Sentiment
6.1
Number of Reviews
26
Ranking in other categories
Advanced Threat Protection (ATP) (13th), Penetration Testing Services (1st), Breach and Attack Simulation (BAS) (1st), Risk-Based Vulnerability Management (2nd), AI-Powered Penetration Testing (1st)
 

Mindshare comparison

As of August 2026, in the Vulnerability Management category, the mindshare of Qualys TotalCloud is 1.2%, up from 1.0% compared to the previous year. The mindshare of Nucleus Security is 1.0%, up from 0.8% compared to the previous year. The mindshare of The NodeZero Platform by Horizon3.ai is 1.3%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
The NodeZero Platform by Horizon3.ai1.3%
Qualys TotalCloud1.2%
Nucleus Security1.0%
Other96.5%
Vulnerability Management
 

Featured Reviews

YashwantShinde - PeerSpot reviewer
Soc Analyst at a manufacturing company with 10,001+ employees
Risk-based visibility has transformed how I prioritize cloud vulnerabilities and protect key assets
The best features Qualys TotalCloud offers are cloud asset visibility, vulnerability assessment, and risk prioritization. This risk-based prioritization helped me quickly identify high-risk vulnerabilities and focus on remediation instead of going through every finding. TrueRisk-based prioritization is useful for understanding which vulnerabilities need attention first. It improved our workflow mainly by giving us a single view of cloud assets and their risk, so we could focus on the higher priority vulnerabilities instead of reviewing every finding manually. This helped us prioritize remediations more efficiently and reduce the time spent on vulnerability assessment and follow-up. Qualys TotalCloud helped us identify exposures that might otherwise have been missed, especially across cloud assets, vulnerabilities, and identities. With the SaaS configuration, the unified inventory and risk view made it easier to connect vulnerabilities with asset criticality, exposure, and access permissions, allowing us to investigate high-risk exposures first and address them before they could become bigger security issues.
reviewer2872923 - PeerSpot reviewer
Vulnerability And Compliance Manager at a insurance company with 5,001-10,000 employees
Unified vulnerability view has improved risk-based decisions but reporting still needs work
One of the main issues with Nucleus Security is its lack of reporting capability. The user interface resembles an early 2000s application style, and although its speed is decent, it could be improved as more data is ingested. The overall appearance and feel need work, especially compared to modern applications from Rapid7, Qualys, and Tenable, which have more engaging user interfaces. The reporting capability is severely lacking; not being able to filter to granularity or have custom built queries is an annoyance that needs an overhaul. Additionally, there are bugs that have not been resolved, such as when you create a report and remove an asset, the asset still appears in the report despite not being present in the system anymore, leading to issues that need to be addressed quickly. Nucleus Security can become a difficult investment because I already have a vulnerability management solution, and I question where Nucleus Security fits with its licensing model. While I acknowledge automation has been described, it would be amazing to control the entire vulnerability management workflow from Nucleus Security without needing to log onto other systems. Having controls or actions that can be sent from the console down to the scanner for rescans would be beneficial. If Nucleus Security is going down this path, it should ensure that it becomes a one-stop shop for vulnerability management across multiple applications.
Brent Hamlin - PeerSpot reviewer
Infrastructure Manager at a construction company with 501-1,000 employees
Continuous threat scanning has improved remediation time and strengthened executive reporting
The best features that The NodeZero Platform by Horizon3.ai offers include the automated scans, which are great to use; you set it, scope it, and let it go, which works really well. The executive reporting feature is impactful for me as a manager, providing a strong foundation to give quarterly and yearly reports to our executives and board to see the state of our infrastructure from a security standpoint. The level of detail and clarity in the executive reports from The NodeZero Platform by Horizon3.ai absolutely helps me communicate effectively with leadership. They are detailed enough for me to extract the necessary information tailored for the executives and to provide a broader perspective on our mitigation efforts or accepted risk stance and where additional controls exist. The NodeZero Platform by Horizon3.ai has positively impacted my organization by giving us a better continuous picture of our security posture, what's exploitable, and what can be used against the organization. It allows us to run scans whenever needed, unlike a single third-party system that only provides a snapshot in time; our processes must be ongoing as the security landscape is dynamic. NodeZero's endpoint security effectiveness feature impacts my understanding of potential security threats by providing a clear picture of both the external and internal landscapes within my organization, enabling me to prioritize and adjust as needed for vulnerabilities such as WordPress plugin issues or user enumerations and software code version assessments. I have built The NodeZero Platform by Horizon3.ai into our weekly and monthly workflows for security CI/CD, and we scan our externally accessible assets every week to address anything quickly if it comes up. That includes our firewalls, websites, and anything that is an external web server, which we scan weekly, while the monthly scans are for internal systems that feed our security CI/CD pipeline, enabling us to action across and prioritize any vulnerabilities caught by The NodeZero Platform by Horizon3.ai.
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
910,564 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Comms Service Provider
12%
Outsourcing Company
12%
Financial Services Firm
10%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
8%
Construction Company
8%
Comms Service Provider
9%
Manufacturing Company
8%
Government
7%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise32
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise9
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
To be totally honest, I do not have any best features because I have had a bad experience using this tool, especially...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is vulnerability management and exposure management. I use this tool to evalua...
What is your experience regarding pricing and costs for Nucleus Security?
The licensing model is straightforward, with one license across multiple assets for multiple connectors. It is always...
What needs improvement with Nucleus Security?
While the platform is incredibly powerful, the initial configuration curve of Nucleus Security can be a bit steep. Wh...
What is your primary use case for Nucleus Security?
In the initial phase when we first brought Nucleus Security into our environment, instead of immediately pushing it i...
What needs improvement with Horizon3.ai?
The NodeZero Platform by Horizon3.ai could greatly improve their feature request and product suggestions process. The...
What is your primary use case for Horizon3.ai?
My main use case for The NodeZero Platform by Horizon3.ai is to run automated penetration tests and remediate finding...
What advice do you have for others considering Horizon3.ai?
The advice I would give to others looking into using The NodeZero Platform by Horizon3.ai is to assess their environm...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
Horizon3.ai
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Government agencies, Defense Industrial Base organizations, and enterprises in regulated industries such as finance, healthcare, manufacturing, and criticalinfrastructure rely on NodeZero to meet rigorous security and compliance requirements with continuous, scheduled, and on-demand testing.
Find out what your peers are saying about Nucleus Security vs. The NodeZero Platform by Horizon3.ai and other solutions. Updated: August 2026.
910,564 professionals have used our research since 2012.