Licensed source/43-state launch design/Controls stated as controls

Compliance is the product.

In 2026 the FTC warned thirteen data brokers with penalties up to $53,088 per violation, and that number explains this company. Scrapeless Data is designed around one method: we license and index already-compiled, provenance-known data under supply contract, and we do not scrape. The MVP is designed to launch in 43 states, with 6 excluded by design, and every compliance mechanism described on this page is a design decision stated as one, not a claim of operational status.

The method

What does license-and-index mean?

It means the sourcing question is settled before the product question. We negotiate a supply contract with a holder of already-compiled US consumer and business files, the contract grants resale rights and names the files it covers, and only then are those files indexed into one lookup surface. The result is that every planned API response can carry a provenance object naming its supply contract, its source file, and the contract date, because those facts exist before the record is ever servable.

01
Contract first
Sourcing agreements are in progress and nothing ships until a supply contract is executed. A record without a contract behind it never enters the index.
02
Provenance as a field
The provenance object rides on every planned response: supply_contract, source_id, contracted_at. Origin is an API field, not a marketing claim.
03
No collection apparatus
There is no scraper to audit because none exists. The company will hold only what it contracts for, with the paper to show for every file.

The launch map

Why launch in 43 states by design?

Because the state statutes are not interchangeable, and pretending they are is how data companies meet regulators. We mapped every state data-broker statute before building, and six states are excluded from the launch design because full day-one compliance there is either economically or operationally out of reach for an MVP. This is a design decision about where to operate first, not a description of filings or operations, and none exist today.

NJ
Registry fees that can reach seven figures a year, plus a per-record penalty on sensitive data with no consent override. The exposure math does not close at launch scale.
CA
A statewide deletion platform that must be reconciled every 45 days, with per-day penalties per unprocessed request. It is engineering we plan to do properly, later, not partially at launch.
IL
A biometric statute with a private right of action requiring no showing of injury, and recent settlements in the tens of millions. We carry no biometric data, and we still stay out at launch.
WA
A health-privacy statute under which inferred health data counts, with treble damages and a private right of action. Inference risk is not something to discover in production.
MD
An absolute ban on sensitive-data sales at our planned revenue threshold, with a constructive-knowledge standard for minors. The compliant version of launch here is no launch.
CT
Per-consumer, per-day penalties for operating without the required filing, and a state-specific deletion mechanism arriving in 2028. It joins the roadmap when the mechanism does.

Texas is planned to follow once its filing is made, and Texas and California are designed to come online together in a later phase, because that is where both the records and the buyers are densest and because the California deletion-platform integration deserves to be built once, properly, on the same suppression pipeline the rest of the product already uses.

The controls

What controls are in the launch design?

The launch design specifies controls in three layers: protecting the data, controlling access to it, and protecting the consumer behind every record. Each item below is a design commitment the product is being built to, stated as exactly that. None of it is a certification claim, and independent verification has its place after activation, not on a marketing page before it.

01
Protecting the data
TLS end to end, encryption at rest, an isolated server, and nightly encrypted backups with a monthly restore drill. The salted-file control sits here too: the holder seeds contracted files with control records, so misuse outside the contracted channel identifies itself. It is a detection control, and we describe it as one.
02
Controlling access
Keys shown once and stored hashed, per-key rate limits, an append-only audit log, and a weekly audit that must cite live evidence rather than attest from memory. End-user certification gates every key, and its wording is under legal review before any key is issued.
03
Protecting the consumer
Query-time suppression that returns records as suppressed rather than silently serving them, opt-out and data-request endpoints designed against statutory clocks, sensitive-file gating, and a written breach runbook. One certification flow is designed to satisfy supplier, state, and company requirements at once.

The entity posture is part of the same plan: Scrapeless Data is planned as a manager-managed Wyoming LLC formed under that state authorized-agent framework, in which members and managers are held of record by an authorized agent rather than published on the public registry. That is a privacy-by-structure decision consistent with the rest of the design, it is stated here as a plan, and formation details are counsel work in progress rather than accomplished facts.

Compliance questions, answered plainly

Does Scrapeless Data scrape any data?

No, and the company name is the design document. Every record in the planned index enters through a written supply contract with a data holder, carrying resale rights and a documented origin. There is no crawler, no scraper, and no collection mechanism of any kind in the architecture. If a file cannot be contracted with provenance attached, it does not enter the index, whatever its commercial value.

Is Scrapeless Data operating in 43 states today?

No. The MVP is designed to launch in 43 states, and that sentence is a statement about design, not about present operations. No records are servable today, and state-level duties attach when the product operates, not before. The 43-state figure exists because we mapped every state statute before writing the product, decided where the launch design could be fully compliant on day one, and excluded the six where it could not.

How would misuse of the data be detected?

Through a control that is standard in the wholesale data trade: salted files. The data holder seeds contracted files with a small number of control records that correspond to no real customer, so any salted record surfacing outside the contracted channel identifies the leak, including which customer file it left through. We describe this as a control because that is what it is: a detection mechanism that protects the holder, the company, and every certified customer using records lawfully.

What is the end-user certification, and when does it apply?

Certification is the planned gate between creating an account and holding an API key: a signed attestation of who the customer is and which permitted uses the records will serve. The wording is load-bearing, because it is what keeps every account inside the permitted-use condition of the supply contract, so it is under legal review and no key is issued until it is final. Accounts created today hold early-access status and wait for exactly this step.

Read the paper trail yourself.

The provenance object is documented in the API reference, the glossary defines every term this page uses, and the machine surface declares the same facts to agents that this page declares to you. When the certification wording is final and keys issue, the changelog will say so on the day it happens.