Draft — This entry has not yet been attested. Complete every field marked "To attest", record the officer's signature and date, then delete this banner before publishing.

Registry entry 0003 · Onshore Disclosure Standard v0.1

LicenseKit

A software-licensing API for B2B software vendors, OEMs and resellers — license keys, metered entitlements, offline activation and audit trails — operated at licensekit.dev. This entry records where LicenseKit customer data, including the vendor's own end-customer license records, is stored, who administers the systems, which people in which countries can reach it, and who controls the company, as attested by a named officer of the company.

Attested status
To attest: Fully onshore · Onshore with disclosed exceptions · Not onshore
Attested by
To attest: name and title
Attestation date
To attest: date
Evidence on vendor domain
To attest: URL on licensekit.dev
Entry published
Revision
1

Relationship to the registry

LicenseKit is built by David Main, who also operates OnshoreFacts. This entry was prepared and published by the same person who runs the registry. No independent party verified it. Like every entry, it rests on a named officer's signature, evidence published on the vendor's own domain, and the legal exposure attached to a knowingly false statement made to induce a purchase.

The four dimensions

Where is LicenseKit customer data stored, and who can reach it?

To attest: one-sentence summary — only if true

LicenseKit holds its customers' account data and, on their behalf, records about their end customers: license keys, activation identifiers, metered usage events, and audit trails. Under the standard most of this is Tier 2 (identifiable personal data of the vendor's customers) and Tier 1 (operational data); whether any Tier 3 data is held is attested below.

Attested countries by dimension and data tier. Tier 3: Social Security numbers, protected health information, biometrics, video of identifiable people, drug-test results, Controlled Unclassified Information. Tier 2: identifiable personal data, worker geolocation, union membership and grievance records. Tier 1: operational data not tied to individuals.
Dimension Tier 3If any — state "none" Tier 2End-customer identity, license records Tier 1Operational data
StorageProduction data, backups, disaster-recovery replicas, log aggregation To attest: countries — no location is published anywhere on licensekit.dev; name the hosting provider and region(s) for production, backups, DR, and logsTo attestTo attest
Administration and remote maintenanceWhere systems are operated, patched, and maintained from To attest: countriesTo attestTo attest
Personnel with production data accessCountries and approximate headcount, by function
SupportTo attest: countries, approx. headcountTo attestTo attest
Engineering and QATo attest: countries, approx. headcountTo attestTo attest
Infrastructure and database administrationTo attest: countries, approx. headcountTo attestTo attest
Data entry and business-process outsourcingTo attest: countries, approx. headcount — or "none"To attestTo attest
Human review of AI outputTo attest: countries, approx. headcount — or "none"To attestTo attest
Sales and customer success with account accessTo attest: countries, approx. headcountTo attestTo attest
Ultimate corporate controlPerson or entity in ultimate control, and country To attest: controlling person or entity, and country of control — no legal entity is named on licensekit.dev; state the entity, its state of formation, and its controller

Subprocessors

Which third parties can reach LicenseKit customer data?

None is named. The vendor's privacy policy, effective 8 April 2026, refers only to categories — cloud hosting, database, DNS, and email providers. The standard requires each subprocessor that can reach customer data to be named with its function, data tier, and processing location; every row below is attested.

Subprocessor categories as published in the LicenseKit privacy policy (licensekit.dev/privacy, effective 8 April 2026, retrieved 30 August 2026), with attested identity, data tier and processing location.
Subprocessor Function, as published Data tier reachable Processing location
Cloud hosting providerUnnamed in the policy "to host, secure, and operate LicenseKit" To attest: tier To attest: name the provider, region(s) and country
Database providerUnnamed in the policy as above To attest: tier To attest: name the provider, region(s) and country
DNS providerUnnamed in the policy as above To attest: tier — typically none To attest: name the provider and country
Email providerUnnamed in the policy as above To attest: tier To attest: name the provider and country

Disclosed exceptions

To attest: "None" — or, for each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.

Published evidence

What does LicenseKit publish about where its data goes?

As of 30 August 2026, licensekit.dev publishes no statement of where data is stored or processed, and names no legal entity. Its privacy policy and terms, both effective 8 April 2026, refer to the service as "LicenseKit" and describe service providers only by category. There is no subprocessor, DPA, trust, security or legal page. The standard's evidence page is recorded in the ledger above once published.

  • We may share data with infrastructure and service providers only as needed to host, secure, and operate LicenseKit, such as cloud hosting, database, DNS, and email providers.Privacy Policy, licensekit.dev/privacy, effective 8 April 2026 · retrieved 30 Aug 2026
  • Effective date: April 8, 2026.Privacy Policy and Terms of Service, licensekit.dev/terms · retrieved 30 Aug 2026
  • © 2026 LicenseKit.devHome page footer, licensekit.dev · retrieved 30 Aug 2026 — the only identification of the operator on the domain

Statements to reconcile

Two gaps the attestation must close, and that the vendor should also fix on licensekit.dev: the domain names no legal entity — the standard requires the entity whose officer signs — and it makes no statement anywhere about where data is stored, administered, or accessed. The terms also state no governing law. Until the site is amended, this entry is the only public statement of either.

Pages checked and absent

On 30 August 2026 the following paths on licensekit.dev returned HTTP 404: /security, /subprocessors, /sub-processors, /dpa, /legal, /trust, /baa, /hipaa. This is the same check applied to every vendor in the OnshoreFacts survey.

Attestation and revisions

Who attested this entry, and what has changed?

Attestation

Onshore Disclosure Standard v0.1

Attested by To attest: full name, To attest: title, To attest: legal entity — not named on licensekit.dev, on To attest: date.

Evidence published by the vendor at To attest: URL on licensekit.dev.

The attestation is a statement by a named officer that the disclosures on this page are accurate as of the attestation date. A knowingly false statement made to induce a purchase is exposed under Section 5 of the FTC Act. OnshoreFacts did not audit this entry.

Revision history

RevisionDateChange
1Initial entry.

Found a discrepancy between this entry and what the vendor publishes or does? Tell us at hello@onshorefacts.com. We put the question to the vendor and publish any revision here, dated.