Draft — Entries 0001–0003 have not yet been attested. Complete every field marked "To attest", record the officer's signature and date, then delete this banner before publishing.

Registry · Onshore Disclosure Standard v0.1

Registry of signed disclosures

Every vendor listed here has signed a structured disclosure of where its customers' data is stored, who administers the systems, which people in which countries can reach the data, and who ultimately controls the company — attested by a named officer and backed by evidence published on the vendor's own domain. The registry does not approve, certify, or rank vendors. It records what they disclosed.

Entries published
3
Founding cohort
Open — sign the disclosure
Standard
Onshore Disclosure Standard v0.1
Last updated

Entries

Which software vendors have signed the Onshore Disclosure?

Three, as of 30 August 2026 — and all three are products built by the registry's operator: EasyDocForms (patient intake, charting and scheduling, AI Documentation LLC), GoSafety (construction safety documentation, GoSafety AI, Inc.), and LicenseKit (software licensing API). They are listed first for that reason: the operator should be the first to answer the registry's questions, in public, with the relationship stated on every entry. No independent vendor has signed yet; the founding cohort is open.

Entries are listed in the order they are published. Each entry links to the vendor's full disclosure, the evidence the vendor published on its own domain, and a dated revision history. Vendors join by signing the one-page attestation; the founding cohort is open.

Registry entries as of 30 August 2026. Status is the vendor's own attested classification under the Onshore Disclosure Standard v0.1 — Fully onshore, Onshore with disclosed exceptions, or Not onshore. All three are valid entries.
No. Vendor Product and market Attested status Attesting officer Attestation date Entry
0001 EasyDocFormsAI Documentation LLC Patient intake, charting and scheduling for independent medical practices — healthcare To attest: status To attest: name and title To attest: date View entry 0001
0002 GoSafetyGoSafety AI, Inc. Construction safety documentation — daily reports, checklists, time cards, injury reports, OSHA 300/301/300A — construction To attest: status To attest: name and title To attest: date View entry 0002
0003 LicenseKitTo attest: legal entity Software licensing API — license keys, metered entitlements, offline activation — B2B software vendors To attest: status To attest: name and title To attest: date View entry 0003

Download the registry as CSV — one row per entry, with the fields in this table plus the attested countries for each dimension. The full attestation for each vendor is on its entry page.

What an entry means

Is this an approval list?

No. OnshoreFacts does not certify vendors, and an entry is not an endorsement. The standard is attest-or-disclose, modelled on California Public Contract Code §12147: a vendor either certifies that all four dimensions are US-only, or describes precisely which parts are not.

A vendor that discloses that its support runs from Manila has made a complete, valid entry. A vendor that is not listed has simply not signed; absence from this registry says nothing about where that vendor's data goes, and we will never present it as if it did. The registry makes no claim about any vendor's encryption, security posture, or breach history — only about geography and access, as the vendor attested.

What stands behind an entry

Each entry rests on three things: a named officer's signature, evidence published on the vendor's own domain, and the legal exposure that attaches to a knowingly false statement made to induce a purchase, under Section 5 of the FTC Act. No entry is audited by OnshoreFacts or by an independent party. If you find a discrepancy between an entry and what a vendor publishes or does, tell us at hello@onshorefacts.com; we will put the question to the vendor and publish any revision, dated.

Structure of an entry

What does a registry entry contain?

Ten fields, the same for every vendor. Each is answered for three data tiers — Tier 3 is Social Security numbers, protected health information, biometrics, video of identifiable people, drug-test results and Controlled Unclassified Information; Tier 2 is identifiable personal data, worker geolocation, union membership and grievance records; Tier 1 is operational data not tied to individuals.

Vendor and legal entity
The product name and the legal entity whose officer signs.
Attested status
Fully onshore; Onshore with disclosed exceptions; or Not onshore. "Onshore" uses IRS Publication 1075's boundary: the United States, its territories, embassies, and military installations.
Storage
Countries where production data, backups, disaster-recovery replicas, and log aggregation reside, for each data tier.
Administration and remote maintenance
Countries from which systems are operated, patched, and maintained.
Personnel with production data access
Countries and approximate headcount for each function: support; engineering and QA; infrastructure and database administration; data entry and business-process outsourcing; human review of AI output; sales and customer success with account access.
Ultimate corporate control
The person or entity in ultimate control of the vendor, and the country of that control.
Subprocessors
Each third party that can reach customer data, with its function, the data tier it can reach, and where it processes.
Disclosed exceptions
For each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.
Attestation
Name and title of the signing officer, the date, and the URL of the evidence the vendor published on its own domain.
Revision history
Every change to the entry, dated. Nothing is edited silently.

Joining the registry

How does a vendor get listed?

By signing. There is no audit and no pass mark: a named officer completes the one-page attestation, the vendor publishes it on its own domain, and the entry is published here with a dated revision history.

  1. Request the attestation formUse the request form — company, product, and a work email. We reply with the form and the standard.
  2. Complete and signA named officer — not "the company" — answers the four dimensions for each data tier, lists subprocessors and any exceptions, and signs.
  3. Publish the evidence on your own domainThe signed disclosure, or a page that restates it, at a URL on your domain — so the statement is yours and stays checkable.
  4. We publish the entryAs a page here, a row in the CSV, and a revision history. Later changes are published as dated revisions, never as silent edits.

Request the attestation form