L3dgr Trust Center

Product security and procurement resources for the L3dgr Docker Desktop Extension and fors33.com portal. This page describes our posture; it is not a full governance, risk, and compliance platform.

Product Security Subprocessors Data Processing Certifications Procurement

Product security overview

L3dgr runs locally in Docker Desktop’s extension VM. Scan, seal, verify, and staging execute on paths you select. The fors33.com portal handles account sign-in, billing, and seat management. Review Docker permissions and trust for host mount, network, and shared-workstation guidance.

Local by default

Cryptographic work runs in the extension VM. Artifacts stay on host paths and Docker volumes until you enable outbound sync or connectors.

Portal and licensing

Google or Microsoft OAuth on Account issues portal sessions. License sync uses GET /api/licenses/sync when the extension can reach Fors33.

Optional telemetry

Telemetry defaults off in Settings. When enabled, only coarse event names and status are sent. See L3dgr Docker Extension — data practices.

Support diagnostics

Operators may export a support bundle from the extension. Bundles exclude raw paths and secrets by design. See L3dgr Support.

Operational summary · see L3dgr Privacy Policy for full collection detail

Subprocessors

This table is the current list of subprocessors for fors33.com, L3dgr licensing, and Hosted Continuity (Fors33 Relay) when entitled. It is updated when vendors change; privacy policies cross-reference this page. Details align with Fors33 Privacy Policy (FORS33-PRIVACY-2.8) and L3dgr Privacy Policy (L3DGR-PRIVACY-2.11).

Last updated: September 11, 2026

Category Purpose Examples Location
Payment processing Subscriptions, invoices, customer portal, Hosted Continuity metered usage events Stripe United States
Identity Portal and extension OAuth sign-in Google (OAuth), Microsoft (OAuth) United States
Transactional email Account, billing, and program notices Brevo (SMTP) European Union
Product communications Optional audience tags for Fors33 product updates (e.g. L3dgr Pro or Lab segments) Brevo United States
Infrastructure Website, API, license endpoints, and temporary Fors33 Relay spool during Hosted Continuity releases (operational hold after demote; default fourteen days; not a permanent customer archive) Cloud hosting provider United States (production region documented on request; Enterprise may pin region)

Recent changes

  • September 11, 2026 — Identity row: Microsoft OAuth alongside Google.
  • August 16, 2026 — Product communications audience moved from Mailchimp to Brevo; privacy ID FORS33-PRIVACY-2.6.
  • August 6, 2026 — Documented Hosted Continuity / Fors33 Relay temporary spool on infrastructure (default fourteen-day operational hold after demote; not WORM); Stripe metered usage for Relay; privacy ID cross-refs FORS33-PRIVACY-2.5 / L3DGR-PRIVACY-2.9.
  • July 31, 2026 — Added Mailchimp row and location column; aligned with FORS33-PRIVACY-2.3 §5.

Data processing agreements

Institution and Enterprise customers whose order is not an offer of paid services to a customer located in the European Economic Area or the United Kingdom may request a data-processing agreement by contacting legal@fors33.com or using the procurement form below. The DPA is request-only. Standard Contractual Clauses are not auto-attached at Stripe checkout. See the Fors33 Privacy Policy (FORS33-PRIVACY-2.8).

Request DPA Review

Certifications and audit evidence

Fors33, Inc. does not publish a SOC 2 report. Procurement teams may request a security questionnaire under NDA. Use the procurement form below with your company name, role, and questionnaire scope.

Request Evidence

Procurement and security questionnaires

Submit third-party risk (TPRA) questionnaires, vendor security reviews, and procurement requests. We route these to legal@fors33.com. Do not attach confidential production data, API keys, or internal audit packages in this form.