Draft — This entry has not yet been attested. Complete every field marked "To attest", record the officer's signature and date, then delete this banner before publishing.

Registry entry 0001 · Onshore Disclosure Standard v0.1

EasyDocForms

Patient intake, charting and scheduling software for independent medical practices, operated by AI Documentation LLC. This entry records where EasyDocForms customer data — including protected health information — is stored, who administers the systems, which people in which countries can reach it, and who controls the company, as attested by a named officer of the company.

Attested status
To attest: Fully onshore · Onshore with disclosed exceptions · Not onshore
Attested by
To attest: name and title
Attestation date
To attest: date
Evidence on vendor domain
To attest: URL on easydocforms.com
Entry published
Revision
1

Relationship to the registry

EasyDocForms is built by David Main, who also operates OnshoreFacts. This entry was prepared and published by the same person who runs the registry, and it is listed first for that reason: the operator should be the first to answer the registry's questions. No independent party verified this entry. Like every entry, it rests on a named officer's signature, evidence published on the vendor's own domain, and the legal exposure attached to a knowingly false statement made to induce a purchase.

The four dimensions

Where is EasyDocForms customer data stored, and who can reach it?

To attest: one-sentence summary — e.g. "All storage, administration, and personnel access is in the United States; the company is controlled from the United States; there are no exceptions." Only if true.

The table gives the attested countries for each dimension and each data tier. Vendor marketing collapses these four questions into the phrase "US-based"; the standard forces them apart.

Attested countries by dimension and data tier. Tier 3: Social Security numbers, protected health information, biometrics, video of identifiable people, drug-test results, Controlled Unclassified Information. Tier 2: identifiable personal data, worker geolocation, union membership and grievance records. Tier 1: operational data not tied to individuals.
Dimension Tier 3PHI, SSNs, biometrics Tier 2Identifiable personal data Tier 1Operational data
StorageProduction data, backups, disaster-recovery replicas, log aggregation To attest: countries — name the Google Cloud region(s) for production, backups, DR, and logs To attest To attest
Administration and remote maintenanceWhere systems are operated, patched, and maintained from To attest: countries To attest To attest
Personnel with production data accessCountries and approximate headcount, by function
SupportTo attest: countries, approx. headcountTo attestTo attest
Engineering and QATo attest: countries, approx. headcountTo attestTo attest
Infrastructure and database administrationTo attest: countries, approx. headcountTo attestTo attest
Data entry and business-process outsourcingTo attest: countries, approx. headcount — or "none"To attestTo attest
Human review of AI outputTo attest: countries, approx. headcount — include any review of Vertex AI or Deepgram output by vendor staff or subprocessor staff, or "none"To attestTo attest
Sales and customer success with account accessTo attest: countries, approx. headcountTo attestTo attest
Ultimate corporate controlPerson or entity in ultimate control, and country To attest: controlling person or entity, and country of control — e.g. "AI Documentation LLC, a [state] limited liability company, controlled by [name], United States"

Subprocessors

Which third parties can reach EasyDocForms customer data?

Four are named in the vendor's privacy policy, last updated 27 May 2026: Google Cloud (including Firebase Authentication and Vertex AI), Deepgram, Stripe, and Apple or Google sign-in, plus integration providers a practice chooses to connect. The functions below are as the vendor publishes them; the data tier and processing location are attested.

Subprocessors as published in the EasyDocForms privacy policy (easydocforms.com/privacy/, last updated 27 May 2026, retrieved 30 August 2026), with attested data tier and processing location.
Subprocessor Function, as published Data tier reachable Processing location
Google CloudIncluding Firebase Authentication and Vertex AI "to host, authenticate, store, secure, and process data" To attest: tier To attest: region(s) and country
Deepgram "speech-to-text transcription and related audio processing when audio dictation, speech recognition, or similar features are enabled" To attest: tier — the policy says audio may contain PHI To attest: country
Stripe "subscription billing, payment processing, and related billing-portal workflows" To attest: tier To attest: country
Apple and GoogleSign in with Apple, Google sign-in "process the information necessary to complete that authentication flow" To attest: tier To attest: country
Customer-authorized integrationsEmail, SMS, scheduling, EMR Providers a practice chooses to connect, including Square Appointments and custom EMR integrations named on the vendor's site To attest: tier, or state that these are selected and controlled by the customer To attest

Disclosed exceptions

To attest: "None" — or, for each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.

Published evidence

What does EasyDocForms publish about where its data goes?

As of 30 August 2026, the vendor's privacy policy states that its core application infrastructure is operated from the United States and names its subprocessors, and its home page states that support and onboarding are US-based. The domain has no dedicated subprocessor, DPA, BAA, trust, or security page; the standard's evidence page is recorded in the ledger above once published.

  • Our core application infrastructure is operated from the United States.Privacy Policy, easydocforms.com/privacy/, last updated 27 May 2026 · retrieved 30 Aug 2026
  • EasyDocForms is operated by AI Documentation LLC.Privacy Policy, as above
  • We use Google Cloud infrastructure and services, including Firebase Authentication and Google Cloud-hosted processing services such as Vertex AI and related Google Cloud tools where enabled, to host, authenticate, store, secure, and process data.Privacy Policy, as above
  • We may use Deepgram for speech-to-text transcription and related audio processing when audio dictation, speech recognition, or similar features are enabled.Privacy Policy, as above
  • We use Stripe for subscription billing, payment processing, and related billing-portal workflows.Privacy Policy, as above
  • When we process PHI on behalf of healthcare practices or other covered entities, we act as a service provider/business associate as applicable and will enter into a Business Associate Agreement (BAA) where required by law.Privacy Policy, as above
  • USA-based tech support and onboarding, 7 days a weekHome page, easydocforms.com · retrieved 30 Aug 2026
  • If you access or use the Services from New Zealand, Singapore, or another jurisdiction outside the United States, your information may be collected, transferred to, stored in, and processed in the United States and in other countries where our service providers operate on our behalf.Privacy Policy, as above

Statement to reconcile

The last passage permits processing "in other countries where our service providers operate on our behalf." The attestation on this page is the specific statement of where processing actually occurs. If the attested status is Fully onshore, the vendor should amend that policy wording to match; if any service provider processes outside the United States, it belongs in the disclosed exceptions above. We note this on the operator's own entry because it is exactly the kind of gap the registry exists to close.

Pages checked and absent

On 30 August 2026 the following paths on easydocforms.com returned HTTP 404: /subprocessors, /sub-processors, /dpa, /legal, /trust, /security, /baa, /hipaa. The subprocessor list exists only inside the privacy policy. This is the same check applied to every vendor in the OnshoreFacts survey.

Attestation and revisions

Who attested this entry, and what has changed?

Attestation

Onshore Disclosure Standard v0.1

Attested by To attest: full name, To attest: title, AI Documentation LLC, on To attest: date.

Evidence published by the vendor at To attest: URL on easydocforms.com.

The attestation is a statement by a named officer that the disclosures on this page are accurate as of the attestation date. A knowingly false statement made to induce a purchase is exposed under Section 5 of the FTC Act. OnshoreFacts did not audit this entry.

Revision history

RevisionDateChange
1Initial entry.

Found a discrepancy between this entry and what the vendor publishes or does? Tell us at hello@onshorefacts.com. We put the question to the vendor and publish any revision here, dated.