# Nucleus One FINRA compliance documentation

What Nucleus One provides toward FINRA books-and-records obligations — the control capabilities, the audit evidence they produce, and the certified infrastructure behind them.

Product: nucleus-one · Audience: system-administrator · Time: 6 minute read · Last verified: 2026-09-01

Canonical: https://help.ademero.com/nucleus-one/compliance/nucleus-one-finra-compliance-documentation

[Download: Nucleus One FINRA Recordkeeping Capability Report (PDF)](https://help.ademero.com/downloads/nucleus-one-finra-compliance-capability-report.pdf)

**Nucleus One runs on Google Cloud infrastructure independently attested to SOC 2 Type II and SOC 1 Type II and certified to ISO 27001. This page maps what it provides toward a broker-dealer's books-and-records program — the capabilities against FINRA's rules and the evidence each one produces.**

First, the regulatory framing: FINRA Rule 4511 requires *firms* to make and preserve records, and defers electronic-storage format requirements to **SEC Rule 17a-4**. These obligations attach to the firm — software is an enabler, and no product is "FINRA certified." Since the SEC's 2022 amendments, 17a-4's electronic-storage requirement can be met with either non-rewriteable/non-erasable (WORM) storage or an audit-trail alternative that can recreate original records — assessed against your storage system and procedures together.

## The certifications behind the platform

Nucleus One runs entirely on **Google Cloud** (App Engine, Cloud Firestore, Cloud Storage), and every layer beneath our application — data centers, physical security, network, storage durability, encryption at rest and in transit — is covered by Google Cloud's independent **SOC 2 Type II** and **SOC 1 Type II** attestations and **ISO 27001** certification. The reports are available directly through [Google Cloud's Compliance Reports Manager](https://cloud.google.com/security/compliance/compliance-reports-manager) — the public SOC 3 summary and the ISO 27001 certificate need no Google account. It's the same shared-responsibility structure firms accept from AWS- and Azure-hosted vendors: infrastructure attestations from the cloud provider, application controls from the software vendor. At the application layer, Nucleus One adds the controls in the table below — enforced MFA, scoped access, supervised approvals, and the event record.

## How Nucleus One maps to FINRA obligations

FINRA evaluations come down to specific rule elements — records of business (4511), supervision with documented review (3110), and safeguarding. Here is the direct mapping:

| FINRA rule element | Nucleus One capability | Evidence it produces |
| --- | --- | --- |
| **Rule 4511 — books and records**: a record of the firm's business activity | **Document events**: twelve event types with actor, timestamp, and change detail — revisions, field changes, folder moves, approvals, signature events — plus a project-wide, filterable **Events** feed | A per-document and per-project activity record reviewable and sortable by examiner request |
| **Rule 4511 — preservation of originals** in normal application use | **Full revision history** — every revision retained with author and timestamp; restoring an earlier revision creates a *new* revision rather than rewriting history | Complete version lineage with visual comparison |
| **Rule 3110 — supervision**: documented supervisory review procedures | **Approval Processes** with multi-party group approvals (any / all / majority), required-fields gates before sign-off, and recorded outcomes | Every supervisory decision logged with process, step, participants, and timestamp |
| **Safeguarding records** — access limited to authorized persons | Organization and project roles, per-area access levels, folder sharing with inheritance, project groups; **organization-enforced MFA** (TOTP) | Access configuration reviewable per project; MFA enforcement visible in Security Settings |

*This page describes product capabilities and is not legal advice. Compliance determinations rest with your firm and its advisors.*
