Governed workflows for every approval-heavy backlog, including the industries not on our menu
For housing and real estate companies, construction and engineering firms, tax, audit and law firms, and associations, foundations and non-profits: build tenant, client and member portals, onboarding with identification, funding and register evidence, and contractor management as production software with review points, traceability and code ownership.
Same platform, same governance, same code ownership as for insurers and banks. Pick the segment that matches you; if none does, the pilot path still applies.
Where it runs
Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU, or your own cloud (BYOC) and on-premise on Enterprise.
What it connects to
Property management (Wodis, iX-Haus and others), DATEV and accounting, construction and project software, member and donor CRM, document management and e-mail via APIs, exports and database views.
What we do not touch
Your accounting, your property management ledger, your DATEV data and your case management system. Apps run beside them and consume what they expose.
Who owns the code
You do. Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database. Export it at any time.
What these teams evaluate first
These are the questions the managing director, the partner, the board and the person who currently runs the process in Excel ask before a pilot gets a budget line.
Hosting in Germany
Nuclicore-managed on Hetzner in Germany or Azure in the EU, with BYOC or on-premise on Enterprise. No data leaves the EU unless you decide otherwise.
No IT department required
You describe the workflow, review the tasks and approve the release. The platform builds, tests, secures and deploys. A part-time IT contact is enough for the interfaces.
Beside your core system, not inside it
Property management, DATEV, project software and CRM stay the systems of record. Apps read what they expose and write back through supported interfaces.
Audit trail your supervisor accepts
Who raised, who reviewed, who approved, when, with what evidence. Exportable per case for the chamber, the funding body, the auditor or the tenant's lawyer.
Portals for tenants, clients and members
External users get a portal role that sees exactly their cases, documents and fields. Nothing else is visible, every access is logged.
Security controls you can cite
Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app. Release gates and logs give you documented measures for any questionnaire or audit.
Exit without a rewrite
Standard code, standard database, documented interfaces. The exit path exists before signature, which matters when the board asks what happens if you stop.
Four segments we see most often outside the core industries
Align scope, workflow ownership and governance for the segment you operate in.
Housing and real estate companies
- Tenant requests and damage reports in one queue instead of the phone
- Building compliance deadlines visible per property, not per binder
- Contractor work closed with evidence and cost per building
- Tenant portal and service requests
- Building compliance register per property
- Maintenance and contractor management
Construction and engineering firms
- Change orders approved before the work is done, not after
- Obstruction notices and defects with dates that hold up in a dispute
- Subcontractor documents complete before the first day on site
- Change orders and client approvals
- Site logs, obstruction notices and defect management
- Subcontractor qualification and documents
Tax, audit, law and notary firms
- Client onboarding with identification and risk class recorded per engagement
- AML risk analysis and documentation ready for the July 2027 rules
- Conflict and independence checks with the record the chamber asks for
- Client onboarding and identification
- AML risk analysis and suspicious activity workflow
- Engagement acceptance, conflict and independence checks
Associations, foundations and non-profits
- Funding evidence assembled from the process, not reconstructed at year end
- Member, donor and board decisions with a record per case
- Register filings tracked with deadlines and responsible persons
- Funding and grant evidence
- Member, donor and board workflows
- Statutory register and filing tracker
Why delivery models are changing outside the core industries
The organisations that ship fastest keep the core system standard, move approvals out of mail and treat compliance as running software.
Common Reality
The core system is fine. The approvals happen next to it.
Property management, DATEV, project software and the member database each do their job. The tenant's damage report, the client's identification, the change order and the funding receipt all travel through mail, phone and shared folders, and nobody can produce the chain when asked.
Common Reality
Small teams, statutory deadlines, personal liability
Remote-readable meters by December 2026, e-invoice issuance from January 2027, the EU anti-money-laundering regulation from July 2027, the foundation register since January 2026. Each one lands on a managing director, partner or board member who is personally accountable and has no IT department.
Common Reality
The industry software does not do the exception
It handles the standard case well. The moment a case needs a second approver, a photo, a deadline or an external party, it leaves the system. From there it lives in Excel, and Excel has no audit trail.
What you can build across portals, compliance and operations
Deliver governed software around your systems of record, with review points, traceability and code ownership.
Tenants, clients and members
Tenant portal and service requests
Tenants report damage and requests with photos, see the status, receive documents and statements, and every case has an owner, a deadline and a closure with evidence.
- Tenant portal role
- Photo evidence
- Status per case
Client onboarding and identification
Engagement intake, identification of the client and beneficial owners, risk classification, engagement letter approval and the record the anti-money-laundering rules require, per engagement.
- Identification checklist
- Risk class recorded
- Record per engagement
Member, donor and board workflows
Applications, admissions, fee decisions, donor acknowledgements and board resolutions with the approval record per case and the consent records data protection requires.
- Approval per case
- Consent records
- Board resolution record
Change orders and client approvals
Construction change orders with scope, price and schedule impact, client approval before execution, and the link from the order to the invoice line that bills it.
- Approval before execution
- Impact recorded
- Order to invoice trace
Compliance and registers
Energy certificate expiry, legionella tests, meter remote-readability status, heating replacement plans and funding records per building, with the deadline and the responsible person visible.
- Per property
- Deadline tracking
- Evidence on request
Firm-level risk analysis, per-client risk review, sanctions screening record, suspicious activity assessment and the documentation the supervisory chamber expects, structured for the rules applying from July 2027.
- Risk analysis versioned
- Sanctions record
- Chamber-ready export
Funding and grant evidence
Budget versus actual per grant, receipts attached as they arrive, deadlines per funding body, and the usage report assembled from the process instead of reconstructed at year end.
- Per grant
- Receipts attached
- Report assembled
Statutory register and filing tracker
Transparency register, foundation register, lobby register and similar filings with the deadline, the responsible person, the evidence of submission and the review date.
- Deadline per filing
- Submission evidence
- Review dates
Operations, projects and field
Maintenance and contractor management
Requests from tenants or staff, contractor assignment with documents on file, execution with photos, closure with evidence, and the cost recorded per building and asset.
- Contractor role
- Cost per building
- Asset history
Daily site logs, obstruction notices with dates and recipients, defects with photos and deadlines, and acceptance records that hold up when the dispute comes.
- Dated notices
- Photo evidence
- Acceptance record
Prequalification, minimum wage and social fund evidence, clearance certificates and insurance collected in a portal, checked, approved and tracked to expiry.
- Document expiry
- Two-step approval
- Partner portal role
Conflict of interest check across clients and matters, independence confirmation, engagement acceptance by the partner and the record per engagement the chamber or the audit oversight asks for.
- Conflict check
- Independence confirmation
- Partner sign-off
Fits your systems of record
Most ROI comes from removing manual handoffs between the office, the field, external parties and finance, and from connecting to your core system with clear ownership of every interface.
We build governed workflows around property management, accounting and DATEV, project and construction software, member and donor CRM, document management and e-mail. We read what these systems expose and write back through their supported interfaces. We do not replace them.
What we need from you
- Interface specs, exports or sandbox access for your core system
- Sample documents and the current Excel or mail process for the workflow
- One named owner per workflow on the business side and one IT contact, internal or external
- The approval matrix: who may approve what, per entity and per value
Integration patterns supported
- APIs and exports of your property management, accounting and CRM systems
- File exchange via SFTP (CSV, XML and the formats your systems already produce) with validation and error queue
- Read-only database views and scheduled extracts
- E-mail intake and notifications for external parties without a portal login
- Document handover to DMS and archive systems with retention metadata
Governed releases, stable production
- Scope is clarified and acceptance criteria are defined before implementation.
- Every change is a task with a reviewer, a preview and an approval record.
- Releases move through Preview, Test and Production, and any earlier release can be redeployed from the history.
- Entity, property and site-specific configuration is data, not code, so one release serves all of them.
- External roles are scoped per case and per field, and documented.
- Audit trail per case and per release, exportable for supervisors, funding bodies and auditors.
Security and data controls
Each application runs its own backend, with a managed, encrypted Postgres per environment. Single-tenant infrastructure, BYOC and on-premise on Enterprise. Hosting in Germany or the EU by default.
RBAC, audit logs and monitoring keep access controlled per entity, role and external party. Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app, which gives you documented technical measures for any questionnaire or audit. Your workspace content is not used to train models.
Security controls in practice
- Own backend per application, managed Postgres per environment with each application on its own table suffix, dedicated or single tenant databases on Enterprise.
- RBAC with entity, role and external-party scopes; SSO on Enterprise
- Audit log of every write action and sensitive read, exportable
- Dependency scanning, CVE patching and nightly ZAP scan on every app
- Portal roles for tenants, clients, members and contractors see only their own cases and fields
What a first pilot looks like
We align on one approval-heavy workflow and deliver reviewable increments with clear governance.
Scope, acceptance criteria, architecture outline
Pick one workflow (for example tenant service requests, client onboarding, change orders or funding evidence). Define roles, approval matrix, the core system fields to read and the records to write back.
First working version in Preview
Forms, routing, deadlines, approvals and the read integration to your core system exports. The people who run the process today click through and comment in the task.
Test environment with real roles and real data
Internal and external roles, SSO if applicable, write-back to the core system or DMS, audit trail export. Your IT contact reviews the interface and the access concept.
Production release and handover
Approval, release to Production, redeploy of an earlier version verified. Documentation for management, the process owner and, where applicable, the works council. Decision on the next workflow.
Success criteria examples
- Every case in the pilot workflow closed with a complete approval chain, no mail threads
- Audit trail export accepted by the process owner or an external auditor
- Core system interface documented and signed off by the system owner
- Zero change requests to the core system vendor
Other Industries FAQ
Answers for managing directors, partners, boards and the people who run the process today.
My industry is not on this page either. Does Nuclicore still fit?
If your work involves approvals, deadlines, external parties and evidence, yes. The four segments here are the ones we see most often; the pilot path is the same for any other. Book a demo and bring the workflow that currently lives in Excel.
What does "governed" mean for a small organisation?
Work is organised into reviewable tasks with acceptance criteria. Releases move through Preview, Test and Production with approval, and any earlier release can be redeployed. Every case carries who raised, reviewed and approved it, with timestamps and evidence. That is the trail your chamber, funding body, auditor or tenant's lawyer asks for, produced without an IT department.
We have no IT department. Who runs this?
You describe the workflow, review the tasks and approve the release; the platform builds, tests, secures and deploys. For the interfaces to your core system a part-time contact, internal or your external IT provider, is enough.
Do you replace our property management, DATEV or project software?
No. Those stay the systems of record. Apps read what they expose and write back through supported interfaces, and handle what happens around them: the request, the approval, the evidence, the external party.
Can tenants, clients, members or subcontractors log in?
Yes. Portal roles see only their own cases and the fields you expose. Where an external party should not have a login, the app can work by e-mail intake and notifications instead. Every access is logged.
We are a tax or law firm. Does this cover the new anti-money-laundering rules?
It covers the process side: client identification, risk classification, sanctions screening record, suspicious activity assessment and documentation, structured for the EU regulation applying from July 2027. The legal assessment of which obligations apply to which engagement remains with the responsible partner.
Can it run on-premise or in our own tenant?
Yes. BYOC and on-premise deployment are available on Enterprise. The default is Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU.
We manage several legal entities, properties or sites. One app or many?
One app, one codebase, one release. Entity, property and site-specific fields, approvers and thresholds are configuration, not code. Deployment labels let you release per entity when one needs a different cutover date.
Who owns the code and the data?
You do. Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database. You can export the code and the data at any time and run it yourself, or hand it to your IT provider.
Who maintains the app after the pilot?
Your team, through the same platform: describe the change, review the task, approve the release. Security patches to dependencies are applied by the platform. If you want to take the code and maintain it elsewhere, you can.
What is not a fit?
Accounting itself, tax filing, the property management ledger, the case management system, CAD and BIM, and anything that must live inside those systems. Nuclicore builds the governed workflows around these systems, not the systems.
Bring the workflow that lives in Excel, and leave with governed software.
Ship beside your core system, with portals, audit trail and code you own, no IT department required.