Registry entry 0003 · Onshore Disclosure Standard v0.1
LicenseKit
A software-licensing API for B2B software vendors, OEMs and resellers — license keys, metered entitlements, offline activation and audit trails — operated at licensekit.dev. This entry records where LicenseKit customer data, including the vendor's own end-customer license records, is stored, who administers the systems, which people in which countries can reach it, and who controls the company, as attested by a named officer of the company.
- Attested status
- To attest: Fully onshore · Onshore with disclosed exceptions · Not onshore
- Attested by
- To attest: name and title
- Attestation date
- To attest: date
- Evidence on vendor domain
- To attest: URL on licensekit.dev
- Entry published
- Revision
- 1
Relationship to the registry
LicenseKit is built by David Main, who also operates OnshoreFacts. This entry was prepared and published by the same person who runs the registry. No independent party verified it. Like every entry, it rests on a named officer's signature, evidence published on the vendor's own domain, and the legal exposure attached to a knowingly false statement made to induce a purchase.
The four dimensions
Where is LicenseKit customer data stored, and who can reach it?
To attest: one-sentence summary — only if true
LicenseKit holds its customers' account data and, on their behalf, records about their end customers: license keys, activation identifiers, metered usage events, and audit trails. Under the standard most of this is Tier 2 (identifiable personal data of the vendor's customers) and Tier 1 (operational data); whether any Tier 3 data is held is attested below.
| Dimension | Tier 3If any — state "none" | Tier 2End-customer identity, license records | Tier 1Operational data |
|---|---|---|---|
| StorageProduction data, backups, disaster-recovery replicas, log aggregation | To attest: countries — no location is published anywhere on licensekit.dev; name the hosting provider and region(s) for production, backups, DR, and logs | To attest | To attest |
| Administration and remote maintenanceWhere systems are operated, patched, and maintained from | To attest: countries | To attest | To attest |
| Personnel with production data accessCountries and approximate headcount, by function | |||
| Support | To attest: countries, approx. headcount | To attest | To attest |
| Engineering and QA | To attest: countries, approx. headcount | To attest | To attest |
| Infrastructure and database administration | To attest: countries, approx. headcount | To attest | To attest |
| Data entry and business-process outsourcing | To attest: countries, approx. headcount — or "none" | To attest | To attest |
| Human review of AI output | To attest: countries, approx. headcount — or "none" | To attest | To attest |
| Sales and customer success with account access | To attest: countries, approx. headcount | To attest | To attest |
| Ultimate corporate controlPerson or entity in ultimate control, and country | To attest: controlling person or entity, and country of control — no legal entity is named on licensekit.dev; state the entity, its state of formation, and its controller | ||
Subprocessors
Which third parties can reach LicenseKit customer data?
None is named. The vendor's privacy policy, effective 8 April 2026, refers only to categories — cloud hosting, database, DNS, and email providers. The standard requires each subprocessor that can reach customer data to be named with its function, data tier, and processing location; every row below is attested.
| Subprocessor | Function, as published | Data tier reachable | Processing location |
|---|---|---|---|
| Cloud hosting providerUnnamed in the policy | "to host, secure, and operate LicenseKit" | To attest: tier | To attest: name the provider, region(s) and country |
| Database providerUnnamed in the policy | as above | To attest: tier | To attest: name the provider, region(s) and country |
| DNS providerUnnamed in the policy | as above | To attest: tier — typically none | To attest: name the provider and country |
| Email providerUnnamed in the policy | as above | To attest: tier | To attest: name the provider and country |
Disclosed exceptions
To attest: "None" — or, for each exception: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.
Published evidence
What does LicenseKit publish about where its data goes?
As of 30 August 2026, licensekit.dev publishes no statement of where data is stored or processed, and names no legal entity. Its privacy policy and terms, both effective 8 April 2026, refer to the service as "LicenseKit" and describe service providers only by category. There is no subprocessor, DPA, trust, security or legal page. The standard's evidence page is recorded in the ledger above once published.
We may share data with infrastructure and service providers only as needed to host, secure, and operate LicenseKit, such as cloud hosting, database, DNS, and email providers.
Privacy Policy, licensekit.dev/privacy, effective 8 April 2026 · retrieved 30 Aug 2026Effective date: April 8, 2026.
Privacy Policy and Terms of Service, licensekit.dev/terms · retrieved 30 Aug 2026© 2026 LicenseKit.dev
Home page footer, licensekit.dev · retrieved 30 Aug 2026 — the only identification of the operator on the domain
Statements to reconcile
Two gaps the attestation must close, and that the vendor should also fix on licensekit.dev: the domain names no legal entity — the standard requires the entity whose officer signs — and it makes no statement anywhere about where data is stored, administered, or accessed. The terms also state no governing law. Until the site is amended, this entry is the only public statement of either.
Pages checked and absent
On 30 August 2026 the following paths on licensekit.dev returned HTTP 404: /security, /subprocessors, /sub-processors, /dpa, /legal, /trust, /baa, /hipaa. This is the same check applied to every vendor in the OnshoreFacts survey.
Attestation and revisions
Who attested this entry, and what has changed?
Attestation
Onshore Disclosure Standard v0.1Attested by To attest: full name, To attest: title, To attest: legal entity — not named on licensekit.dev, on To attest: date.
Evidence published by the vendor at To attest: URL on licensekit.dev.
The attestation is a statement by a named officer that the disclosures on this page are accurate as of the attestation date. A knowingly false statement made to induce a purchase is exposed under Section 5 of the FTC Act. OnshoreFacts did not audit this entry.
Revision history
| Revision | Date | Change |
|---|---|---|
| 1 | Initial entry. |
Found a discrepancy between this entry and what the vendor publishes or does? Tell us at hello@onshorefacts.com. We put the question to the vendor and publish any revision here, dated.