Home
About
Core Pillars
Frameworks
Platforms
Solutions
Paxley Insights Contact
Request a briefing →
Our Product
Paxley

The code security platform that enforces trust at every commit.

Paxley is our only product, built to operationalise the NS-CTAF and NS-AIGF frameworks at the point of development. GitHub-native, repo-priced, and designed for enterprises where AI writes a growing share of the code.

NS-CTAFCode Trust Framework
NS-AIGFAI Governance
GitHubNative scanning
The Digital Trust Assurance Company

We don't describe security.
We measure and prove it.

Other firms deliver compliance reports. Nucleus Systems engineers, measures, and continuously proves digital trust, converting cybersecurity complexity into measurable, defensible, board-level confidence across 40+ countries.

Founder-led on every major engagement 26+ years of practitioner experience, not delegated to junior teams
Proprietary IP, not adapted public standards Four owned trust models, not ISO or NIST adaptations with a new logo
Attacker-informed, evidence-based assurance We validate, test, and produce board-ready defensible findings, not interview checklists
End-to-end, from assessment to managed operations Fractional CISO leadership, DevSecOps integration, and 24x7 MSSP capability
40+ Countries served
600+ Engagements delivered
250+ M&A due diligence
4 Proprietary frameworks

One methodology. One trust score. Applied consistently across 40+ countries and six domains of digital trust.

How We Work

Framework. Platform. Service.
Every engagement, in that order.

Most consultancies borrow public standards and apply them loosely. Nucleus Systems starts with proprietary frameworks we built, runs them through platforms we developed, and delivers findings through practitioners who know the difference.

01
FRAMEWORK

Proprietary IP, built from first principles.

Four internally developed frameworks define every control, domain, scoring model and maturity level we use. Not adapted from existing public standards, designed from scratch to make trust scores consistent, comparable and defensible to boards and regulators.

NS-CMMF · 188 controls NS-AIGF · 60 controls NS-AISCA · 108 controls NS-CTAF · 86 controls
Explore our frameworks
02
PLATFORM

Purpose-built delivery, not point-in-time audits.

Our Cybersecurity Maturity Platform and AI Security Assessment Platform turn framework controls into continuous, automated scoring. Every assessment generates a live trust index, not a PDF that sits on a shelf. Boards see real posture. Regulators accept the output.

Cybersecurity Maturity Platform AI Security Assessment Platform Live trust index Continuous scoring
Explore platforms
03
SERVICE

Practitioner delivery, specialist, not generalist.

We deploy deep domain specialists across 40+ countries. Every engagement is led by a practitioner who has operated in the sector, understands the regulator's lens, and knows how to translate technical findings into language a board can act on.

600+ engagements 40+ countries Board-ready output Regulatory accepted
Start an engagement
Latest Thinking

From the Nucleus Systems desk

View all insights
Our People

Built by practitioners.
Driven by trust.

Every engagement at Nucleus Systems is led by a specialist who has operated in the sector, not a generalist analyst reading a playbook. We deploy people with decades of hands-on experience in the most demanding regulated environments globally.

Godfrey Kutumela
Founding CEO
Godfrey Kutumela
Project Lead & Senior Cybersecurity Practitioner
CISSP ISO 27001 LA EU CyberNet Expert Mojaloop MOSIP

26+ years across African and Middle Eastern banking, payments and digital public infrastructure. Former Alinma Bank and MTN Fintech. Led 150+ M&A cyber due diligence engagements. Co-creator of OpenSwitchAfrica.

Our practitioners have built cryptographic systems for tier-one banks, led regulatory compliance programmes for central banks, architected cloud security for payment rails and contributed to the open-source platforms that underpin digital public infrastructure across Africa, the Middle East, and Europe.

This depth of direct operational experience is what separates us from advisory-only firms. When we assess your security posture, design your AI governance structure, or lead your M&A cyber due diligence, we are drawing on real-world knowledge, not frameworks read from a textbook.

Team at a glance
100+ Combined years
150+ Engagements led
16 Markets served
Core Pillars

Four domains of digital trust. Each with its own framework, platform and service.

01
NS-CMMF Cybersecurity

Cybersecurity Trust & Resilience

188 controls across 6 NIST-aligned domains. L1→L5 maturity scoring. Board-ready trust index and remediation roadmaps.

Explore
2A
NS-AIGF AI Governance

AI Trust & Governance

60 controls across 7 governance domains. EU AI Act, ISO 42001 and NIST AI RMF aligned. AI system risk classification and governance assurance.

Explore
2B
NS-AISCA AI Security

AI Security & Assurance

108 controls across 12 security domains. GenAI, Agentic AI and MLSecOps threat modelling and control validation.

Explore
03
NS-CTAF Code Trust

Code Trust & Secure Digital Delivery

86 controls across 6 trust domains. CTA-1→CTA-4 certification. DevSecOps, SBOM governance, AI-assisted code security. Delivered via Paxley.

Explore
Our Frameworks

Four frameworks.
Zero borrowed standards.

Explore all frameworks
NS-CMMF v2.4.1
Cybersecurity Trust & Resilience

188 controls across 6 NIST-aligned domains. L1→L5 maturity scoring, board-ready trust index and remediation roadmaps.

32 mapped frameworks · 6 domains
Explore
NS-AIGF v1.3.0
AI Trust & Governance

60 controls across 7 governance domains. EU AI Act, ISO 42001 and NIST AI RMF aligned. AI risk classification and assurance.

EU AI Act · ISO 42001 · NIST AI RMF
Explore
NS-AISCA v1.1.0
AI Security & Assurance

108 controls across 12 security domains. GenAI, Agentic AI and MLSecOps threat modelling and control validation.

GenAI · Agentic AI · MLSecOps
Explore
NS-CTAF v2.0.1
Code Trust & Secure Delivery

86 controls across 6 trust domains. CTA-1→CTA-4 certification. DevSecOps, SBOM governance and AI-assisted code security.

CTA-1 → CTA-4 · 6 trust domains
Explore
Our Platforms

Purpose-built.
Not off-the-shelf.

Explore platforms
Platform 01
Cybersecurity Maturity Platform

Purpose-built for continuous NS-CMMF assessment, scoring and executive reporting. Turns point-in-time audits into a live trust index that boards can track and regulators will accept.

NS-CMMF 188 controls Live trust scoring
See the platform
Platform 02
AI Security Assessment Platform

Structured assessment and reporting for NS-AISCA evaluations across AI systems, pipelines and infrastructure. Findings scored by severity and mapped to remediation roadmaps.

NS-AISCA 108 controls 12 security domains
See the platform
Domain-Specific Solutions

Where frameworks meet
specialised market demands.

Beyond the four core pillars, Nucleus Systems delivers specialist solutions in domains that require deep contextual knowledge, from payment rails to post-quantum cryptography.

Discuss your requirements
S1
Managed Detection & Response

24/7 MDR delivered in partnership with CyberOne MSSP, anchored to NS-CMMF maturity context. Threat detection with trust measurement built in, not bolted on.

NS-CMMF24/7 MDRCyberOne
Learn more
S2
Payment Security & Digital Public Infrastructure

Security architecture for payment rails and digital public infrastructure across emerging markets. Mojaloop, Tazama, COMESA and PCI DSS expertise, deployed where trust is both mission-critical and newly built.

MojaloopTazamaPCI DSSCOMESA
Learn more
S3
Verifiable Credentials & Digital Identity

Security assurance for national identity programmes and verifiable credential infrastructure. MOSIP, OpenG2P, W3C VC and DID ecosystem, securing identity at population scale.

MOSIPOpenG2PW3C VCDID
Learn more
S4
Financial Inclusion & Emerging Markets

Mobile money, agent banking and microfinance security across Africa, Asia and the Pacific. Trust assurance where financial infrastructure is still being built.

Mobile MoneyAgent BankingAfrica
Learn more
S5
Post-Quantum Cryptography Advisory

CBOM analysis, PQC readiness assessments, crypto agility architecture and NIST PQC migration roadmaps. Prepare for CRQC-era cryptographic risk now.

NIST PQCCBOMCrypto Agility
Learn more
Industries

Where trust carries the most weight.

We work where a failure of trust is not an inconvenience, it is a systemic event.

01

Financial Services

Banks, insurers and asset managers where a trust failure triggers systemic regulatory action.

02

Government

Public institutions where digital trust is foundational to governance and citizen confidence.

03

Digital Public Infrastructure

National identity, payment rails and data exchanges that underpin entire economies.

04

Fintech

Regulated disruptors building trust at speed across payments, lending and digital wealth.

05

Healthcare

Patient data, clinical systems and AI diagnostics where trust is a matter of life.

06

Technology

Platforms, SaaS and AI companies proving security posture to enterprise buyers and boards.

07

Private Equity

Deal teams and portfolio companies managing cyber risk through M&A and ownership cycles.

08

Critical Infrastructure

Energy, water and transport operators where a breach carries national consequences.

Work with sector specialists

Don't see your industry?
We likely cover it.

Our practitioners have operated across 40+ countries and a wide range of regulated sectors. Tell us where you are, we'll tell you how we can help.

40+Countries
600+Engagements
8Industries
250+M&A due diligence
Start with a trust review

Ready to make trust
measurable and provable?

Tell us where trust matters most in your organisation, cybersecurity posture, AI governance, code security or digital infrastructure. We will show you how to engineer it, measure it, and keep proving it to your board and regulators.