Local by default
Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.
Product EULA, privacy policy, terms of service, and compliance PDFs for L3dgr and the Docker Desktop Extension. View or download below.
Plain-language summary of extension data practices. Authoritative terms are in the L3dgr legal PDFs in the Legal section.
Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.
The extension reads and writes Docker-shared /host paths for .f33 sidecars, manifests, receipts, audit JSONL, and staging artifacts from seal, verify, and staging runs.
OAuth and license checks may contact Fors33 servers. Telemetry is optional, defaults off in Settings, and when enabled reports only event name, platform, timestamp, and status.
When enabled in Settings, the extension may report coarse events only:
scan_run, attest_run, certificate_download, undertaking_pdf_download, verification_receipt_download, drift_export, verification_report_export, job_timeout, job_resumed_on_mount, job_polling_resync_after_sleep_gap
Telemetry never includes file paths, contents, hashes, emails, tokens, connector URLs, bucket names, environment variables, or stack traces from your environment.
Regulated-mode tooling supports evidence workflows only; it does not certify compliance. You supply timestamp services and bucket policies your organization accepts.
Uninstalling the extension or deleting its Docker volumes removes local extension state. Export identity from Settings before destructive volume or extension removal.
L3dgr is a Docker Desktop Extension. Installing it grants the extension VM access consistent with Docker’s extension model. Review these points before install in regulated or shared-workstation environments.
L3dgr runs inside Docker Desktop’s extension guest VM, not directly on the host OS. The UI talks to a local backend over Docker’s extension socket API.
/host)Docker mounts your machine under /host inside the VM. L3dgr reads and writes only paths you select in the UI (seals, manifests, receipts, staging, and optional connector output). Treat selected folders as in scope for read, hash, and write operations.
Settings, identity, stream state, and extension databases live in Docker named volumes (under /var/lib/fors33 in the VM). Uninstalling the extension without export can delete this state.
Outbound HTTPS may contact Fors33 for OAuth, license sync, optional telemetry, timestamp services you configure, and connector destinations you enable. Live Ingest connectors can reach URLs and credentials you supply in Settings.
The extension can perform cryptographic operations and write artifacts to mounted host paths. On shared machines, use separate Google accounts and Lab seat roles so operators do not share portal keys or extension identity.
The Docker Marketplace listing describes required permissions and links to this hub. Compare the installed version in Help & Support → System Information with the listing before upgrades.
Operational guidance for Docker Desktop extension updates, volume persistence, and Live Ingest continuity. For support, see L3dgr Support.
/var/lib/fors33.The following applies when your license includes Live Ingest (network streaming). Free scan-and-verify operators see only the locked continuity card under Settings → System → Extension Updates.
GET /api/licenses/sync when the extension can reach Fors33 (Google OAuth Bearer).exp claim; renew via sync before expiry when back online.expires_at after Stripe renewals.past_due, access remains until Fors33 revokes on unpaid; update payment in Plans and Billing.updates_until in the JWT instead of exp; major updates follow your air-gap entitlement terms.Product-specific policies for L3dgr deployments, licensing, and the Docker Desktop Extension. Customer-facing release notes: L3dgr release notes.
License terms for L3dgr software and the Docker Desktop Extension. L3DGR-EULA-2.2.
View / download PDFPrivacy for L3dgr including extension /host, volumes, telemetry, connectors, support bundles, legal manifest, and Seal Beta applications. L3DGR-PRIVACY-2.3.
View / download PDFPortal and subscription terms for L3dgr. L3DGR-TOS-2.2.
View / download PDFParticipation terms for the L3dgr Seal Beta cohort (promotion codes, requirements, revocation, graduation). L3DGR-SEALBETA-1.5.
View / download PDFRegulatory review materials for L3dgr deployments (not legal policy documents).
Technical readiness worksheet for retention, immutability, and chain-of-custody review. Not legal advice or certification. Document ID: L3DGR-SEC17A4-2.0. Request access through the checklist form; the PDF is delivered after you submit your contact details.