FAQ

Questions MSPs actually ask

Short answers. If something isn't here, email Brett. You'll get a person, not a ticket queue.

The product

What is Nuronus?

Compliance software for MSPs. You assess clients against HIPAA, SOC 2, PCI DSS, CMMC, and other frameworks, collect evidence, and deliver white-label reports from one multi-tenant dashboard. It is not a GRC tool for one company doing its own SOC 2.

Who is it for?

MSPs and MSSPs selling compliance across many clients. It is not built for an internal security team running one program, and it is not a replacement for Vanta or Drata at a single SaaS company.

Which frameworks are included?

Eleven: HIPAA, SOC 2, PCI DSS, NIST CSF, CIS Controls, CJIS, CMMC Level 1 and 2, ISO 27001, FERPA, PIPEDA, and Quebec Law 25. CIS is the master control set; the others map onto it so one assessment covers every framework a client falls under.

Do my clients see Nuronus?

No. White-label is included on every plan, including free. Your logo, your reports, your portal. Clients should not see our name.

Do you install an agent?

No. Connections are read-only (OAuth or API) to Microsoft 365, Google Workspace, RMM, and cloud. We do not write, modify, or delete anything in the client environment.

Pricing

What does free actually include?

Two clients, all features, all frameworks, white-label reports. No credit card. No clock. When you need more clients, Starter is $99/month for ten.

How is paid pricing structured?

Flat monthly (or annual) by client count, not by endpoint. Starter $99/mo (10 clients), Growth $299/mo (25), Professional $999/mo (50), Enterprise $1,999/mo (unlimited). All features are on every paid tier except audit-log depth and success-manager extras. See Pricing.

Are there per-endpoint or per-assessment fees?

No. You are not billed per workstation, per scan, or per framework. That is the point versus tools that charge for each assessment.

What is the refund policy?

30-day money-back on paid plans. Details are on the refund policy page.

Security and data

Where does our data live?

DigitalOcean, United States (NYC). PostgreSQL over TLS. Data at rest is AES-256. Access is scoped per MSP and client. We do not sell client data.

Are you SOC 2 certified?

Not today. Type II is in progress. The DigitalOcean infrastructure we run on is SOC 2 Type II certified. First independent pen test target is October 2026. The security page is the honest version of this answer.

Does AI score my clients?

No. Readiness comes from mapped CIS controls and check status. Copilot can draft notes and policy language from data already in your tenant. You can ignore Copilot and still run assessments and reports. More on How we use AI.

Do you store credit cards?

No. Billing is Stripe (PCI DSS Level 1). Card numbers never enter Nuronus. We keep Stripe customer and subscription IDs so we can manage the plan.

Getting started

How long does setup take?

A few fields to register. Demo data is pre-loaded so you can click around immediately. Connecting a real client is typically about 15 minutes if you have M365, Google, or RMM credentials.

We already use ConnectWise, Datto, or Ninja.

Those stay. We read inventory and posture; we do not replace the PSA or RMM. Integrations include ConnectWise, Datto, NinjaRMM, Tactical RMM, Microsoft 365, Google Workspace, Azure, and AWS.

Can I talk to a person?

Yes. Email [email protected] or book a 20-minute demo. There is no SDR layer. You talk to the person who built it.

Still looking?

Start free with two clients, or book 20 minutes and walk the product.