FAQ
Short answers. If something isn't here, email Brett. You'll get a person, not a ticket queue.
Compliance software for MSPs. You assess clients against HIPAA, SOC 2, PCI DSS, CMMC, and other frameworks, collect evidence, and deliver white-label reports from one multi-tenant dashboard. It is not a GRC tool for one company doing its own SOC 2.
MSPs and MSSPs selling compliance across many clients. It is not built for an internal security team running one program, and it is not a replacement for Vanta or Drata at a single SaaS company.
Eleven: HIPAA, SOC 2, PCI DSS, NIST CSF, CIS Controls, CJIS, CMMC Level 1 and 2, ISO 27001, FERPA, PIPEDA, and Quebec Law 25. CIS is the master control set; the others map onto it so one assessment covers every framework a client falls under.
No. White-label is included on every plan, including free. Your logo, your reports, your portal. Clients should not see our name.
No. Connections are read-only (OAuth or API) to Microsoft 365, Google Workspace, RMM, and cloud. We do not write, modify, or delete anything in the client environment.
Two clients, all features, all frameworks, white-label reports. No credit card. No clock. When you need more clients, Starter is $99/month for ten.
Flat monthly (or annual) by client count, not by endpoint. Starter $99/mo (10 clients), Growth $299/mo (25), Professional $999/mo (50), Enterprise $1,999/mo (unlimited). All features are on every paid tier except audit-log depth and success-manager extras. See Pricing.
No. You are not billed per workstation, per scan, or per framework. That is the point versus tools that charge for each assessment.
30-day money-back on paid plans. Details are on the refund policy page.
DigitalOcean, United States (NYC). PostgreSQL over TLS. Data at rest is AES-256. Access is scoped per MSP and client. We do not sell client data.
Not today. Type II is in progress. The DigitalOcean infrastructure we run on is SOC 2 Type II certified. First independent pen test target is October 2026. The security page is the honest version of this answer.
No. Readiness comes from mapped CIS controls and check status. Copilot can draft notes and policy language from data already in your tenant. You can ignore Copilot and still run assessments and reports. More on How we use AI.
No. Billing is Stripe (PCI DSS Level 1). Card numbers never enter Nuronus. We keep Stripe customer and subscription IDs so we can manage the plan.
A few fields to register. Demo data is pre-loaded so you can click around immediately. Connecting a real client is typically about 15 minutes if you have M365, Google, or RMM credentials.
Those stay. We read inventory and posture; we do not replace the PSA or RMM. Integrations include ConnectWise, Datto, NinjaRMM, Tactical RMM, Microsoft 365, Google Workspace, Azure, and AWS.
Yes. Email [email protected] or book a 20-minute demo. There is no SDR layer. You talk to the person who built it.
Start free with two clients, or book 20 minutes and walk the product.