A workspace that plans, builds and releases software with review points.
Who is responsible for the product
The thing I care most about is what happens after the pilot. You get a real repo, real migrations, real tests. If you leave Nuclicore, your application keeps running. That's the bar we build to.
Dr. Christoph Schaller
Product Director
The Nuclicore Platform
Nuclicore is not a chatbot. Every request becomes a task with acceptance criteria, every task becomes a commit, every release passes a security gate and your approval. Start from a prompt, a prototype or a GitHub repo.
What you get
- Working web apps, APIs, automations and agents
- Own backend per application, managed Postgres per environment
- Preview, Test and Production with scoped secrets
- Exportable git repository
Who it’s for
- Business teams needing speed
- IT leaders needing control
- Regulated teams needing governance
Why companies choose this
Software projects usually fail for predictable reasons: unclear scope, handoffs, rework, and long feedback loops.
Nuclicore reduces those costs with a controlled process:
- Scope is locked in tasks with acceptance criteria before implementation
- Progress lands as reviewable increments, one commit per task
- Releases pass a security gate and your approval, with full history
Result: faster delivery, fewer surprises, and a pipeline your own people can operate without an engineering department behind it.
Three phases, one workflow
A structured workflow with outputs you can review at each step. From discovery to production.
You Describe
Describe the goal, users, approvals, data and integrations, or import a prototype or repo. Nuclicore asks clarifying questions and writes tasks with acceptance criteria you can edit in chat.
- Reviewable scope & acceptance criteria
- Task plan & architecture outline
Product Manager
Turns intent into a build plan you can approve
Captures goals, stakeholders, constraints and risk, then writes tasks with acceptance criteria. Records what is out of scope so it stays out, sets dependencies between tasks, and links Knowledge entries to the tasks they govern. Every task field change is recorded in the Audit Trail with the value before and after.
AI Team Builds
The team maps data model, permissions, APIs and UI, then builds and tests each task in order. Each completed task is one commit. You get a Preview URL.
- Working software you can click and review
A task is handed over once the application installs, builds and starts, not when the code was written. A failed dependency install gets one automatic repair attempt, a failed build or a runtime failure up to ten, and each attempt reads the real error output, changes the code and runs the check again. The same error twice in a row stops the repair and the task is marked failed with the error rather than handed over as done.
Developer
Builds production-ready systems and interfaces
Works in a real React and Node.js repository, installs the dependencies the task needs, runs runtime checks, and asks in the task thread when a decision is needed instead of guessing. Manual edits made in the Code tab become tasks and commits too.
DB Admin
Owns the schema and every migration
Designs the data model and writes versioned migrations, kept under version control in the repository and applied in order to Preview, Test and Production. The most recent migration of a database can be rolled back.
QA Engineer
Validates every feature before you see it
Tests against the acceptance criteria of the task and reports which criteria were verified and which were not exercised, so a gap is visible rather than implied.
You Approve & Deploy
Release through Test to Production. The security check runs static code analysis with Semgrep and dependency scanning with Trivy, and safe dependency upgrades are applied automatically. You approve. Deployment labels serve the release under every brand's domain.
- Production software with traceability
SecOps
Enforces security gates before release
Runs the security check before every build: static code analysis with Semgrep and dependency scanning with Trivy. Critical and high findings stop the release, and a scan that cannot complete stops it too. Safe dependency upgrades are applied automatically and committed on their own. Nightly ZAP scans run against the running application.
DevOps
Deploys with confidence across environments
Builds the container images, pushes them to a private registry, deploys to Test, waits for the approval, releases to Production, and keeps every release in the history for redeploy. A release can be scheduled for a fixed time or cancelled while it runs.
Building Blocks you select in the chat
Pre-built code and integrations the agents wire into your application, so the common parts are not rebuilt from a prompt every time.
Code blocks
CRUD, a data table with a REST API.
email and password, phone and SMS one time code, magic link, two factor authentication, passkeys and WebAuthn, social login, SSO and SAML inside your application.
email, in-app, SMS, webhooks, push.
approval workflows.
Integrations
Anthropic, Google and OpenAI.
PDF generation from DOCX templates, PDF merging and compression, file validation, OCR and text extraction, e-signature to eIDAS.
Stripe payments, IBAN verification.
Platform services
- Email via Mailgun
- SMS via Azure Communication Services with Spryng as fallback
- Payments via Stripe
- Files and storage via Azure Blob
- PDF and documents via the platform document service
- E-invoicing to EN 16931 as ZUGFeRD and Factur-X, validated against the official Schematron rules with the PDF/A-3 output checked using veraPDF
- AI models direct or through Azure AI Foundry
- Beyond the catalogue: any NPM package, any REST or SOAP API, and a private NPM registry on Enterprise.
- Every integration call leaves through the Nuclicore integration gateway, which only connects to approved provider addresses. An application cannot use a platform integration to reach an arbitrary host.
- Usage is metered in credits, each integration has its own monthly budget with a soft or hard limit and email alerts, and AI is switched off for a new application until you enable it.
Inside the workspace
Eleven tabs. Everything the engineering department would otherwise run in six tools.
Tasks
Kanban with approval gates and auto-accept. Every card is editable in chat.
Knowledge
Rules, assets and requirements the agents must respect on every task.
Code
Full editor and file tree. Manual edits become tasks and commits too.
Database
Managed Postgres with Preview, Test and Production, SQL filters and CSV import.
Secrets
Per environment, with per-label overrides.
Integrations
Email, payments, storage, PDF, e-invoicing, AI models. Monthly budget and hard limit per integration.
Logs
Every agent action, by role and level.
Preview
Live app with console, network and error panels.
Analytics
Users, sessions, pages, funnels, retention. No third-party tag needed.
Monitoring
Requests, errors, latency, incidents, security scans.
Deploy
Security check, build, Test, approval, Production. History with redeploy. Custom domain and API subdomain.
And outside a single application
- Dashboard and applications list across the workspace.
- Databases: the managed ones and any external database you have connected.
- Workspace analytics across applications.
- Audit Trail: approvals, releases, member changes, secret changes, file actions, skill changes, and every task field change with the value before and after.
- Subscription: members and roles (Owner, Admin, Billing Admin, Developer), credits, custom domain prefix, deployment labels on Enterprise, billing and ownership transfer.
Your rules, and how the team works
Knowledge says what must be true in your application. A Skill says how the agents should work.
Knowledge
- Persistent entries with a category and a priority: Design Assets, Required Features, Brand Guidelines and your own categories, with file attachments.
- The agents apply them to every task, not only the next one.
- Entries can be linked to individual tasks.
Worked example: an entry "Invisible honeypot required on all custom forms" with priority Critical means every form built from then on has one, without anyone remembering to ask.
Skills
- Reusable working methods the agents load when a task calls for them.
- Built in and available in every application: brainstorming, design, writing plans, executing plans, test driven development, systematic debugging, verification before completion, requesting code review, receiving code review.
- Custom skills per subscription or per application: a name and description, instructions in plain language, the agent roles they apply to, an optional condition, templates handed to the agent, and an on or off switch.
- Governance: skills are created and changed by Owners and Admins, and every change is recorded in the Audit Trail.
Custom skills are set up by Nuclicore on request.
This is why the second application costs less effort than the first: the rules and the working methods are already in the workspace.
- Choose automatic, one model for all agents, or a different model per agent role.
- Nuclicore offers the frontier models and the cost efficient models of all large providers.
- Bringing your own API key is possible, the details are confirmed for your plan.
Control and portability
Own the code, the data, the environments and the release.
Own the code and data
Export the full source repository and keep data ownership while maintaining clear audit trails.
Environments and secrets
Preview, Test and Production, each with its own database and secrets, inside the builder. Run on Nuclicore-managed infrastructure or your cloud.
One version, many brands
Deployment labels run one release on several branded domains with separate secrets and data.
Governed releases
Security gate, approval and traceability on every release. Redeploy any earlier release from the history.
Frequently asked questions
Answers to the questions that get deals unstuck.
How it works
Procurement
What does it mean when you say Nuclicore builds "real software"?
It means we don't rely on proprietary black boxes. We ship the stack professional teams use: React 18 + TypeScript on the frontend, an Express and TypeORM backend, and a managed PostgreSQL database. You get full Docker containerisation, proper API layers and security testing on every release. It is fully customisable, extendable and production-ready from day one.
Which AI models do the agents use?
You choose: automatic, one model for all agents, or a different model per agent role. Nuclicore offers the frontier models and the cost efficient models of all large providers, and the catalogue changes as new models ship, so nothing in your application is tied to one vendor. Bringing your own API key is possible, we confirm the details for your plan.
How do I make sure the agents follow our rules?
Add them to the app's Knowledge base: brand assets, required features, compliance rules, design instructions. Entries are prioritised and linked to tasks, so a rule like "every form needs a honeypot" applies to every future task.
Which integrations are built in?
Email (Mailgun), payments (Stripe), file storage (Azure Blob), PDF generation and merging, file validation, OCR and text extraction, e-signature to eIDAS, IBAN verification, e-invoicing (ZUGFeRD and Factur-X), and AI models from Anthropic, OpenAI and Google. Beyond that, any NPM package or REST or SOAP API.
Can I use external NPM packages or 3rd-party libraries?
Yes. Since you have a full Node.js environment, you can install any package from the NPM registry. Whether you need a specific PDF generation library, a complex math utility, or a niche SDK, you can add it just like you would in a local development environment.
Can we integrate with ERP or SAP?
Often yes. We connect to ERP and CRM systems, middleware and on-premise databases over REST, SOAP or a custom API handler, so a modern portal can sit in front of the existing landscape without a rewrite. Feasibility depends on the available interfaces and test access.
How do I handle bug fixes and updates after the initial build?
You continue to use the AI team to iterate. Ask for 'fix the bug in the checkout flow' or 'add a dark mode toggle' and it plans and executes the change on your existing codebase without breaking current functionality. Every task is one commit, and every release is in the deployment history, so you can redeploy any earlier version.
How does deployment, hosting, and self-hosting work?
Every workspace has Preview, Test and Production environments with their own database and secrets. A release runs a security check, builds containers, deploys to Test, waits for your approval, then goes to Production. Every release stays in the history and can be redeployed.
What happens if my application traffic spikes?
Managed infrastructure on Azure with monitoring and alerts included. Scaling requirements are agreed in the pilot scope; dedicated capacity is available on Enterprise.
What is a workspace?
An isolated environment for your team, applications, and data. It is the boundary for access control and billing.
What does a first pilot look like?
Four weeks, one workflow: scope in week one, a clickable first slice in week two, integration in a test environment in week three, security gate and production release in week four. The full plan is on the homepage.
What does my team need to provide?
A process owner, access to test data, and integration endpoints. If SSO is required, an IT contact for setup.
How predictable is cost if you use credits?
Credits are visible per app and subscription. Every integration has a monthly budget with a hard or soft limit and alerts. For contractual caps, use an enterprise agreement.
Is there a free tier?
Yes. The Free plan gives you 100 credits a month, one public application, the frontier models, a managed encrypted Postgres, your own backend per application and the Preview environment, with no time limit and no credit card. Import from GitHub, a zip or a prototype starts at Business Starter.
Do you offer SLAs or dedicated support?
Enterprise includes a contractual service level agreement for availability and dedicated support. On the other plans, support follows the plan.
Who owns the IP?
You do. You can export the full source repository and keep operating it under your control.
Where is data stored and who can access it?
Nuclicore-managed apps run on Azure in the EU; Hetzner in Germany is available. Your own cloud or on-premise on Enterprise. Access is governed by RBAC, audit log and your policies.
Do you train your AI models on my code or proprietary data?
Your code and data stay in your workspace, and your workspace content is not used to train models. EU hosting applies by default.
What support do we get?
Plan-based support and onboarding options, including dedicated support for enterprise setups.
What contracts are available?
DPA with every account. SLA and security pack on Enterprise. The subprocessor list is public on this site.
Turn backlog into running software.
Without losing control.