Registry entry 0002 · Onshore Disclosure Standard v0.1
GoSafety
Construction safety documentation software — daily reports, safety checklists, time cards, injury reports and OSHA 300, 301 and 300A recordkeeping — delivered through an offline-capable iPhone and iPad app and a web dashboard, operated by GoSafety AI, Inc. This entry records where GoSafety customer data — including injury records, worker location and voice audio — is stored, who administers the systems, which people in which countries can reach it, and who controls the company, as attested by a named officer of the company.
- Attested status
- To attest: Fully onshore · Onshore with disclosed exceptions · Not onshore
- Attested by
- To attest: name and title
- Attestation date
- To attest: date
- Evidence on vendor domain
- To attest: URL on gosafety.ai
- Entry published
- Revision
- 1
Relationship to the registry
GoSafety is built by David Main, who also operates OnshoreFacts. This entry was prepared and published by the same person who runs the registry. No independent party verified it. Like every entry, it rests on a named officer's signature, evidence published on the vendor's own domain, and the legal exposure attached to a knowingly false statement made to induce a purchase.
The four dimensions
Where is GoSafety customer data stored, and who can reach it?
To attest: one-sentence summary — only if true
GoSafety's privacy policy states that the service collects daily report content, safety checklist and inspection responses, time entries including injury attestations, photos, GPS coordinates, and voice audio for transcription. Under the standard, injury and OSHA-log data is Tier 3 (employee medical information) and worker geolocation is Tier 2; that is the data this table is about.
| Dimension | Tier 3OSHA injury records | Tier 2Worker geolocation, identity | Tier 1Operational data |
|---|---|---|---|
| StorageProduction data, backups, disaster-recovery replicas, log aggregation | To attest: countries — the policy says "within the United States"; name the hosting provider and region(s) for production, backups, DR, and logs | To attest | To attest |
| Administration and remote maintenanceWhere systems are operated, patched, and maintained from | To attest: countries | To attest | To attest |
| Personnel with production data accessCountries and approximate headcount, by function | |||
| Support | To attest: countries, approx. headcount | To attest | To attest |
| Engineering and QA | To attest: countries, approx. headcount | To attest | To attest |
| Infrastructure and database administration | To attest: countries, approx. headcount | To attest | To attest |
| Data entry and business-process outsourcing | To attest: countries, approx. headcount — or "none" | To attest | To attest |
| Human review of AI output | To attest: countries, approx. headcount — include any human review of Deepgram transcripts or "AI-assisted processing" output, or "none" | To attest | To attest |
| Sales and customer success with account access | To attest: countries, approx. headcount | To attest | To attest |
| Ultimate corporate controlPerson or entity in ultimate control, and country | To attest: controlling person or entity, and country of control — e.g. "GoSafety AI, Inc., a Delaware corporation, controlled by [name], United States" | ||
Subprocessors
Which third parties can reach GoSafety customer data?
One is named in the vendor's privacy policy, last updated 9 March 2026: Deepgram, for speech processing. The policy also refers to unnamed providers for infrastructure hosting, AI-assisted processing, and error monitoring. The standard requires each of them to be named with its location; the tier and location columns are attested.
| Subprocessor | Function, as published | Data tier reachable | Processing location |
|---|---|---|---|
| Deepgram | "speech processing providers, including Deepgram, to generate transcripts and structured field data" | To attest: tier — voice notes may describe injuries | To attest: country |
| Infrastructure hosting providerUnnamed in the policy | "infrastructure hosting" | To attest: tier | To attest: name the provider, region(s) and country |
| AI-assisted processing providerUnnamed in the policy | "AI-assisted processing" | To attest: tier | To attest: name the provider and country |
| Error monitoring providerUnnamed in the policy | "error monitoring" | To attest: tier — state whether error reports can contain field data | To attest: name the provider and country |
Disclosed exceptions
To attest: "None" — or, for each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.
Published evidence
What does GoSafety publish about where its data goes?
As of 30 August 2026, the vendor's privacy policy states that customer data is stored on servers within the United States and names one speech-processing subprocessor; its terms place the company under Delaware law. No page on the domain names the hosting, AI, or error-monitoring providers, and there is no subprocessor, DPA, trust, or security page; the standard's evidence page is recorded in the ledger above once published.
Your data is stored on secure servers within the United States.
Privacy Policy, gosafety.ai/privacy, last updated 9 March 2026 · retrieved 30 Aug 2026Service providers: We use a limited number of third-party services for infrastructure hosting, speech transcription, AI-assisted processing, and error monitoring.
Privacy Policy, as aboveWhen you use voice transcription features, audio and related transcription data may be securely transmitted to GoSafety and our speech processing providers, including Deepgram, to generate transcripts and structured field data.
Privacy Policy, as aboveThese Terms are governed by the laws of the State of Delaware, United States, without regard to conflict of law principles.
Terms of Service, gosafety.ai/terms, effective 1 March 2025 · retrieved 30 Aug 2026GoSafety AI, Inc.
Legal entity as named in the Privacy Policy and Terms of Service
Statements to reconcile
"Stored on secure servers within the United States" is a statement about storage only. It says nothing about where the systems are administered from, which people can reach production data, or where Deepgram and the unnamed hosting, AI and error-monitoring providers process. The attestation on this page supplies those four answers, and the vendor should name the three unnamed providers on gosafety.ai.
Pages checked and absent
On 30 August 2026 the paths /security, /subprocessors, /sub-processors, /dpa, /legal, /trust, /baa and /hipaa on gosafety.ai each returned HTTP 200 with content identical to a deliberately nonexistent path — the site serves its home page for any unknown address. They are recorded as absent. This is the same check applied to every vendor in the OnshoreFacts survey.
Attestation and revisions
Who attested this entry, and what has changed?
Attestation
Onshore Disclosure Standard v0.1Attested by To attest: full name, To attest: title, GoSafety AI, Inc., on To attest: date.
Evidence published by the vendor at To attest: URL on gosafety.ai.
The attestation is a statement by a named officer that the disclosures on this page are accurate as of the attestation date. A knowingly false statement made to induce a purchase is exposed under Section 5 of the FTC Act. OnshoreFacts did not audit this entry.
Revision history
| Revision | Date | Change |
|---|---|---|
| 1 | Initial entry. |
Found a discrepancy between this entry and what the vendor publishes or does? Tell us at hello@onshorefacts.com. We put the question to the vendor and publish any revision here, dated.