L3dgr: Legal & Compliance

Product EULA, privacy policy, terms of service, and compliance PDFs for L3dgr and the Docker Desktop Extension. View or download below.

Docker Extension Permissions & Trust Extension Updates Legal Compliance

L3dgr Docker Desktop Extension

Plain-language summary of extension data practices. Authoritative terms are in the L3dgr legal PDFs in the Legal section.

Local by default

Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.

Host access

The extension reads and writes Docker-shared /host paths for .f33 sidecars, manifests, receipts, audit JSONL, and staging artifacts from seal, verify, and staging runs.

May leave your machine

OAuth and license checks may contact Fors33 servers. Telemetry is optional, defaults off in Settings, and when enabled reports only event name, platform, timestamp, and status.

Opt-in telemetry events

When enabled in Settings, the extension may report coarse events only:

scan_run, attest_run, certificate_download, undertaking_pdf_download, verification_receipt_download, drift_export, verification_report_export, job_timeout, job_resumed_on_mount, job_polling_resync_after_sleep_gap

Not sent in telemetry

Telemetry never includes file paths, contents, hashes, emails, tokens, connector URLs, bucket names, environment variables, or stack traces from your environment.

Regulated modes

Regulated-mode tooling supports evidence workflows only; it does not certify compliance. You supply timestamp services and bucket policies your organization accepts.

Uninstall

Uninstalling the extension or deleting its Docker volumes removes local extension state. Export identity from Settings before destructive volume or extension removal.

Extension summary · not a substitute for the published policies

Docker Desktop permissions and trust

L3dgr is a Docker Desktop Extension. Installing it grants the extension VM access consistent with Docker’s extension model. Review these points before install in regulated or shared-workstation environments.

Extension VM

L3dgr runs inside Docker Desktop’s extension guest VM, not directly on the host OS. The UI talks to a local backend over Docker’s extension socket API.

Host mount (/host)

Docker mounts your machine under /host inside the VM. L3dgr reads and writes only paths you select in the UI (seals, manifests, receipts, staging, and optional connector output). Treat selected folders as in scope for read, hash, and write operations.

Named volumes

Settings, identity, stream state, and extension databases live in Docker named volumes (under /var/lib/fors33 in the VM). Uninstalling the extension without export can delete this state.

Network

Outbound HTTPS may contact Fors33 for OAuth, license sync, optional telemetry, timestamp services you configure, and connector destinations you enable. Live Ingest connectors can reach URLs and credentials you supply in Settings.

Privilege and shared workstations

The extension can perform cryptographic operations and write artifacts to mounted host paths. On shared machines, use separate Google accounts and Lab seat roles so operators do not share portal keys or extension identity.

Marketplace listing

The Docker Marketplace listing describes required permissions and links to this hub. Compare the installed version in Help & Support → System Information with the listing before upgrades.

Operational summary · see L3dgr EULA for license terms

Extension Updates and Continuity

Operational guidance for Docker Desktop extension updates, volume persistence, and Live Ingest continuity. For support, see L3dgr Support.

What persists across an update

  • Settings, identity, connection profiles, and stream state live in Docker named volumes under /var/lib/fors33.
  • Use Manage → Update in Docker Desktop Extensions. Do not uninstall first; uninstall deletes volumes.
  • Use Help & Support → System Information for version parity after rebuilds or marketplace updates.

Live Ingest continuity (licensed operators only)

The following applies when your license includes Live Ingest (network streaming). Free scan-and-verify operators see only the locked continuity card under Settings → System → Extension Updates.

While you are away (engine running)

  • Live network streams and scheduled jobs can continue when the L3dgr tab is closed, as long as the Docker engine stays up.
  • Optional host continuity: when enabled in Settings → System → Extension Updates, you may release active streams to a host supervisor before quitting Docker Desktop.

Extension updates with active streams

  • When you update from Docker Desktop while network streams are running, L3dgr attempts an automatic handoff so ingest overlap can continue across the container restart.
  • After update, verify schedules and streams in the Jobs view and Readout tab.

Optional host continuity

  • Enable host continuity in Settings → System → Extension Updates, install the host supervisor, then use Release Streams to Host before quitting Docker Desktop.
  • Host ingest is opt-in and operator-attributed. It runs only within the host license window set at release (default one hour; your deployment may allow up to 24 hours). When the window expires, host ingest stops until you open L3dgr and use Release Streams to Host again.
  • With a prior release to host, ingest may continue across a full machine reboot until that license window expires. Reopen Docker Desktop and L3dgr to reconcile host segments into your stream ledgers.

Sleep, reboot, and outages

  • Sleep or hibernate may interrupt WebSocket connectors; streams reconnect when the machine wakes.
  • Resource Saver or engine pause stops in-VM ingest; host continuity applies only when you have released streams to the host supervisor.
  • A full machine shutdown stops in-VM ingest. Host ingest continues only when you released streams to the host supervisor first and the host license window has not expired. Scheduled jobs can redispatch after Docker and L3dgr start again.

License sync and offline grace

  • L3dgr Pro and multiseat licenses refresh through GET /api/licenses/sync when the extension can reach Fors33 (Google OAuth Bearer).
  • Subscription licenses carry a JWT exp claim; renew via sync before expiry when back online.
  • Paid subscriptions include a three-day period-end grace on ledger expires_at after Stripe renewals.
  • During Stripe past_due, access remains until Fors33 revokes on unpaid; update payment in Plans and Billing.
  • Air-gapped (perpetual) licenses use updates_until in the JWT instead of exp; major updates follow your air-gap entitlement terms.

Legal documents

Product-specific policies for L3dgr deployments, licensing, and the Docker Desktop Extension. Customer-facing release notes: L3dgr release notes.

  1. End User License Agreement (EULA)

    License terms for L3dgr software and the Docker Desktop Extension. L3DGR-EULA-2.2.

    View / download PDF
  2. Privacy Policy

    Privacy for L3dgr including extension /host, volumes, telemetry, connectors, support bundles, legal manifest, and Seal Beta applications. L3DGR-PRIVACY-2.3.

    View / download PDF
  3. Terms of Service

    Portal and subscription terms for L3dgr. L3DGR-TOS-2.2.

    View / download PDF
  4. Seal Beta Program

    Participation terms for the L3dgr Seal Beta cohort (promotion codes, requirements, revocation, graduation). L3DGR-SEALBETA-1.5.

    View / download PDF

Compliance

Regulatory review materials for L3dgr deployments (not legal policy documents).

  1. SEC 17a-4 WORM Compliance Checklist

    Technical readiness worksheet for retention, immutability, and chain-of-custody review. Not legal advice or certification. Document ID: L3DGR-SEC17A4-2.0. Request access through the checklist form; the PDF is delivered after you submit your contact details.

    Request Download