Nucleus One FINRA compliance documentation
What Nucleus One provides toward FINRA books-and-records obligations — the control capabilities, the audit evidence they produce, and the certified infrastructure behind them.
Nucleus One runs on Google Cloud infrastructure independently attested to SOC 2 Type II and SOC 1 Type II and certified to ISO 27001. This page maps what it provides toward a broker-dealer's books-and-records program — the capabilities against FINRA's rules and the evidence each one produces.
First, the regulatory framing: FINRA Rule 4511 requires firms to make and preserve records, and defers electronic-storage format requirements to SEC Rule 17a-4. These obligations attach to the firm — software is an enabler, and no product is "FINRA certified." Since the SEC's 2022 amendments, 17a-4's electronic-storage requirement can be met with either non-rewriteable/non-erasable (WORM) storage or an audit-trail alternative that can recreate original records — assessed against your storage system and procedures together.
The certifications behind the platform
Nucleus One runs entirely on Google Cloud (App Engine, Cloud Firestore, Cloud Storage), and every layer beneath our application — data centers, physical security, network, storage durability, encryption at rest and in transit — is covered by Google Cloud's independent SOC 2 Type II and SOC 1 Type II attestations and ISO 27001 certification. The reports are available directly through Google Cloud's Compliance Reports Manager — the public SOC 3 summary and the ISO 27001 certificate need no Google account. It's the same shared-responsibility structure firms accept from AWS- and Azure-hosted vendors: infrastructure attestations from the cloud provider, application controls from the software vendor. At the application layer, Nucleus One adds the controls in the table below — enforced MFA, scoped access, supervised approvals, and the event record.
How Nucleus One maps to FINRA obligations
FINRA evaluations come down to specific rule elements — records of business (4511), supervision with documented review (3110), and safeguarding. Here is the direct mapping:
| FINRA rule element | Nucleus One capability | Evidence it produces |
|---|---|---|
| Rule 4511 — books and records: a record of the firm's business activity | Document events: twelve event types with actor, timestamp, and change detail — revisions, field changes, folder moves, approvals, signature events — plus a project-wide, filterable Events feed | A per-document and per-project activity record reviewable and sortable by examiner request |
| Rule 4511 — preservation of originals in normal application use | Full revision history — every revision retained with author and timestamp; restoring an earlier revision creates a new revision rather than rewriting history | Complete version lineage with visual comparison |
| Rule 3110 — supervision: documented supervisory review procedures | Approval Processes with multi-party group approvals (any / all / majority), required-fields gates before sign-off, and recorded outcomes | Every supervisory decision logged with process, step, participants, and timestamp |
| Safeguarding records — access limited to authorized persons | Organization and project roles, per-area access levels, folder sharing with inheritance, project groups; organization-enforced MFA (TOTP) | Access configuration reviewable per project; MFA enforcement visible in Security Settings |
This page describes product capabilities and is not legal advice. Compliance determinations rest with your firm and its advisors.
