Nucleus One SOX (Sarbanes-Oxley) compliance documentation
What Nucleus One provides for your Sarbanes-Oxley (SOX) program — the control capabilities, the audit evidence it produces, and the infrastructure certifications behind it.
Nucleus One runs on Google Cloud infrastructure independently attested to SOC 2 Type II and SOC 1 Type II and certified to ISO 27001 — and is built for controlled documents on top of it: enforced multi-party approvals, a complete who-did-what event history on every document, version history that can't be rewritten in normal use, and access control down to the folder. This page maps those capabilities to SOX control objectives and the evidence each one produces.
The short version:
- The infrastructure carries independent certifications — Google Cloud SOC 2 Type II, SOC 1 Type II, and ISO 27001, with reports available directly from Google Cloud
- Every change is recorded — twelve event types with actor, timestamp, and before/after detail, on every document
- Approvals are enforced, not optional — multi-party sign-off (any/all/majority), blocked until required fields are complete
- History can't be quietly rewritten — restoring an old version creates a new revision on top of the record
- Access is deliberate — roles, per-area levels, folder inheritance, and organization-enforced MFA
One sentence of precision: Sarbanes-Oxley (SOX) compliance attaches to your company's internal controls over financial reporting — no software can be "SOX certified," and vendors who claim it are overreaching. What a platform provides is control capabilities and evidence, and Nucleus One provides both in depth.
The certifications behind the platform
The infrastructure layer carries independent certifications. Nucleus One runs entirely on Google Cloud — App Engine, Cloud Firestore, and Cloud Storage — and every layer beneath our application (data centers, physical security, network, storage durability, encryption at rest and in transit, operational controls) is covered by Google Cloud's independent SOC 2 Type II and SOC 1 Type II attestations and ISO 27001 certification. The reports are available directly through Google Cloud's Compliance Reports Manager — the public SOC 3 summary and the ISO 27001 certificate without any Google account — and they're the same artifacts Fortune 500 security teams accept for the platform layer.
The application layer is where Nucleus One adds its own controls: organization-enforced multi-factor authentication, the role- and area-scoped access model, enforced approval processes, the document event history, revision integrity, and HTTPS-only transport with strict transport security on every route. It's the same shared-responsibility model AWS- and Azure-hosted software uses — infrastructure attestations from the cloud provider, application controls from the vendor — and the capability table below is the application-layer control description.
How Nucleus One maps to SOX control objectives
SOX audits of IT systems come down to a familiar set of control objectives — authorization, change management, logical access, segregation of duties, data integrity, and audit evidence. Here is the direct mapping:
| SOX control objective | Nucleus One capability | Evidence it produces |
|---|---|---|
| Authorization — financial documents are approved before they take effect (§302/404 control activities) | Approval Processes with group approvals requiring any, all, or a majority of assignees; required fields for approve block sign-off on incomplete records; block re-entry prevents decided items from silently re-entering approval | Every approve/decline recorded with process name, step, participants, and timestamp |
| Change management & audit evidence — changes to records are traceable for control testing | Document events: twelve event types (revisions, field changes, name changes, folder moves, approval actions, signature events and more), each with actor, timestamp, and before/after detail | Per-document event log plus a project-wide, filterable Events feed — the sample-and-test trail auditors walk |
| Data integrity — original records are preserved and alterations are visible | Full revision history — every revision retained with author and timestamp; restoring an old revision creates a new revision rather than overwriting history | Revision list with visual comparison between any two versions |
| Logical access (ITGC) — only authorized people reach financial records | Roles (organization administrator, project manager, stakeholder, read-only), per-area access levels (Everything / Direct assignments / Nothing), folder-level sharing with inheritance, project Groups | Membership and access configuration reviewable per project |
| Segregation of duties (ITGC) — preparers aren't their own approvers | Approvals assignable to users or groups distinct from submitters; "Disallow content removal by project members" restricts deletion to project managers | Process and project configuration showing the separation |
| Access security (ITGC) — accounts are protected | Organization-enforced multi-factor authentication (TOTP) for all members; scoped API keys | MFA enforcement visible in Security Settings |
Configuration is part of the control. The mapping above holds when the settings are configured to match your control design.
This page describes product capabilities and is not legal or audit advice. Compliance determinations rest with your organization and its advisors.
