Registry · Onshore Disclosure Standard v0.1
Registry of signed disclosures
Every vendor listed here has signed a structured disclosure of where its customers' data is stored, who administers the systems, which people in which countries can reach the data, and who ultimately controls the company — attested by a named officer and backed by evidence published on the vendor's own domain. The registry does not approve, certify, or rank vendors. It records what they disclosed.
- Entries published
- 3
- Founding cohort
- Open — sign the disclosure
- Standard
- Onshore Disclosure Standard v0.1
- Last updated
Entries
Which software vendors have signed the Onshore Disclosure?
Three, as of 30 August 2026 — and all three are products built by the registry's operator: EasyDocForms (patient intake, charting and scheduling, AI Documentation LLC), GoSafety (construction safety documentation, GoSafety AI, Inc.), and LicenseKit (software licensing API). They are listed first for that reason: the operator should be the first to answer the registry's questions, in public, with the relationship stated on every entry. No independent vendor has signed yet; the founding cohort is open.
Entries are listed in the order they are published. Each entry links to the vendor's full disclosure, the evidence the vendor published on its own domain, and a dated revision history. Vendors join by signing the one-page attestation; the founding cohort is open.
| No. | Vendor | Product and market | Attested status | Attesting officer | Attestation date | Entry |
|---|---|---|---|---|---|---|
| 0001 | EasyDocFormsAI Documentation LLC | Patient intake, charting and scheduling for independent medical practices — healthcare | To attest: status | To attest: name and title | To attest: date | View entry 0001 |
| 0002 | GoSafetyGoSafety AI, Inc. | Construction safety documentation — daily reports, checklists, time cards, injury reports, OSHA 300/301/300A — construction | To attest: status | To attest: name and title | To attest: date | View entry 0002 |
| 0003 | LicenseKitTo attest: legal entity | Software licensing API — license keys, metered entitlements, offline activation — B2B software vendors | To attest: status | To attest: name and title | To attest: date | View entry 0003 |
Download the registry as CSV — one row per entry, with the fields in this table plus the attested countries for each dimension. The full attestation for each vendor is on its entry page.
What an entry means
Is this an approval list?
No. OnshoreFacts does not certify vendors, and an entry is not an endorsement. The standard is attest-or-disclose, modelled on California Public Contract Code §12147: a vendor either certifies that all four dimensions are US-only, or describes precisely which parts are not.
A vendor that discloses that its support runs from Manila has made a complete, valid entry. A vendor that is not listed has simply not signed; absence from this registry says nothing about where that vendor's data goes, and we will never present it as if it did. The registry makes no claim about any vendor's encryption, security posture, or breach history — only about geography and access, as the vendor attested.
What stands behind an entry
Each entry rests on three things: a named officer's signature, evidence published on the vendor's own domain, and the legal exposure that attaches to a knowingly false statement made to induce a purchase, under Section 5 of the FTC Act. No entry is audited by OnshoreFacts or by an independent party. If you find a discrepancy between an entry and what a vendor publishes or does, tell us at hello@onshorefacts.com; we will put the question to the vendor and publish any revision, dated.
Structure of an entry
What does a registry entry contain?
Ten fields, the same for every vendor. Each is answered for three data tiers — Tier 3 is Social Security numbers, protected health information, biometrics, video of identifiable people, drug-test results and Controlled Unclassified Information; Tier 2 is identifiable personal data, worker geolocation, union membership and grievance records; Tier 1 is operational data not tied to individuals.
- Vendor and legal entity
- The product name and the legal entity whose officer signs.
- Attested status
- Fully onshore; Onshore with disclosed exceptions; or Not onshore. "Onshore" uses IRS Publication 1075's boundary: the United States, its territories, embassies, and military installations.
- Storage
- Countries where production data, backups, disaster-recovery replicas, and log aggregation reside, for each data tier.
- Administration and remote maintenance
- Countries from which systems are operated, patched, and maintained.
- Personnel with production data access
- Countries and approximate headcount for each function: support; engineering and QA; infrastructure and database administration; data entry and business-process outsourcing; human review of AI output; sales and customer success with account access.
- Ultimate corporate control
- The person or entity in ultimate control of the vendor, and the country of that control.
- Subprocessors
- Each third party that can reach customer data, with its function, the data tier it can reach, and where it processes.
- Disclosed exceptions
- For each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.
- Attestation
- Name and title of the signing officer, the date, and the URL of the evidence the vendor published on its own domain.
- Revision history
- Every change to the entry, dated. Nothing is edited silently.
Joining the registry
How does a vendor get listed?
By signing. There is no audit and no pass mark: a named officer completes the one-page attestation, the vendor publishes it on its own domain, and the entry is published here with a dated revision history.
- Request the attestation formUse the request form — company, product, and a work email. We reply with the form and the standard.
- Complete and signA named officer — not "the company" — answers the four dimensions for each data tier, lists subprocessors and any exceptions, and signs.
- Publish the evidence on your own domainThe signed disclosure, or a page that restates it, at a URL on your domain — so the statement is yours and stays checkable.
- We publish the entryAs a page here, a row in the CSV, and a revision history. Later changes are published as dated revisions, never as silent edits.