Local by default
Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.
Data practices, permissions, updates, and license sync for the L3dgr extension. Authoritative legal PDFs are on L3dgr legal and compliance. For support bundles and contact, see L3dgr Support.
Plain-language summary of extension data practices. Authoritative terms are in the L3dgr legal PDFs on L3dgr legal and compliance.
Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.
The extension reads and writes Docker-shared /host paths for .f33 sidecars, manifests, receipts, audit JSONL, and staging artifacts from seal, verify, and staging runs.
OAuth and license checks may contact Fors33 servers. Telemetry is optional, defaults off in Settings, and when enabled reports only event name, platform, timestamp, and status.
Telemetry never includes file paths, contents, hashes, emails, tokens, connector URLs, bucket names, environment variables, or stack traces from your environment.
Regulated-mode tooling supports evidence workflows only; it does not certify compliance. You supply timestamp services and bucket policies your organization accepts.
Uninstalling the extension or deleting its Docker volumes removes local extension state. Export identity from Settings before destructive volume or extension removal.
When enabled in Settings, the extension may report coarse events only:
scan_run attest_run certificate_download undertaking_pdf_download verification_receipt_download drift_export verification_report_export job_timeout job_resumed_on_mount job_polling_resync_after_sleep_gap
Installing the L3dgr Docker Desktop Extension grants the extension VM access consistent with Docker’s model. Review these points before install on regulated or shared workstations.
| Surface | Access |
|---|---|
| Extension VM | Runs in Docker Desktop’s extension guest VM. The UI talks to a local backend over Docker’s extension socket API. |
/host mount |
Docker mounts your machine at /host. L3dgr reads and writes only paths you select for seals, manifests, receipts, and staging. |
| Named volumes | Settings, identity, and stream state live under /var/lib/fors33. Uninstalling without export can delete this state. |
| Network | Outbound HTTPS may reach Fors33 for OAuth, license sync, and optional telemetry. Connectors use only URLs and credentials you set in Settings. |
| Shared machines | The extension can write host artifacts and run cryptographic operations. Use separate Google accounts and Lab seat roles on shared machines. |
| Marketplace | The Docker Marketplace listing describes required permissions. Compare your installed version in Help & Support → System Information before upgrades. |
Operational guidance for Docker Desktop extension updates, volume persistence, and Live Ingest continuity in Settings → System → Continuity. For support, see L3dgr Support.
Use Manage → Update; do not uninstall first. Settings, identity, and stream state persist under /var/lib/fors33. Active streams hand off across the restart. Then verify Jobs and Help & Support → System Information.
Live Ingest keeps streams running with the L3dgr tab closed. Before quitting Docker, enable host continuity, install the supervisor, and Release Streams to Host. Sleep or reboot stops in-VM ingest unless released first.
Optional paid add-on for planned outages or always-on cloud-reachable ingest. Purchase in Plans and Billing → Fors33 Relay. Release streams in Settings → System → Continuity, then reconcile when L3dgr is running again.
Pro and Lab tiers are described on the L3dgr product page. Billing and seats are managed in Plans and Billing.
GET /api/licenses/sync when the extension can reach Fors33 (Google OAuth Bearer).exp claim; renew via sync before expiry when back online.expires_at after Stripe renewals.past_due, access remains until Fors33, Inc. revokes on unpaid; update payment in Plans and Billing.updates_until in the JWT instead of exp; major updates follow your air-gap entitlement terms.Extension and operational summary. Not a substitute for the published L3dgr policies. See the EULA for license terms.