Local by default
Cryptographic work runs in the extension VM. Artifacts stay on host paths and Docker volumes until you enable outbound sync or connectors.
Product security and procurement resources for the L3dgr Docker Desktop Extension and fors33.com portal. This page describes our posture; it is not a full governance, risk, and compliance platform.
L3dgr runs locally in Docker Desktop’s extension VM. Scan, seal, verify, and staging execute on paths you select. The fors33.com portal handles account sign-in, billing, and seat management. Review Docker permissions and trust for host mount, network, and shared-workstation guidance.
Cryptographic work runs in the extension VM. Artifacts stay on host paths and Docker volumes until you enable outbound sync or connectors.
Google OAuth on Account issues portal sessions. License sync uses
GET /api/licenses/sync when the extension can reach Fors33.
Telemetry defaults off in Settings. When enabled, only coarse event names and status are sent. See L3dgr legal and compliance docs.
Operators may export a support bundle from the extension. Bundles exclude raw paths and secrets by design. See L3dgr Support.
This table is the current list of subprocessors for fors33.com and L3dgr licensing. It is updated when vendors change; privacy policies cross-reference this page. Details align with Fors33 Privacy Policy (FORS33-PRIVACY-2.3) §5 and L3dgr Privacy Policy (L3DGR-PRIVACY-2.3) §6.
| Category | Purpose | Examples | Location |
|---|---|---|---|
| Payment processing | Subscriptions, invoices, customer portal | Stripe | United States |
| Identity | Portal and extension OAuth sign-in | Google (OAuth) | United States |
| Transactional email | Account, billing, and program notices | Brevo (SMTP) | European Union |
| Product communications | Optional audience tags for Fors33 product updates (e.g. L3dgr Pro or Lab segments) | Mailchimp | United States |
| Infrastructure | Website, API, and license endpoints | Cloud hosting provider | United States (production region documented on request) |
Enterprise and Institution customers may request a Data Processing Agreement (DPA) or review data-processing terms alongside the Fors33 legal hub and L3dgr product policies. Contact legal@fors33.com or use the procurement form below.
Fors33 may provide SOC 2 Type II or related audit evidence to customers and prospects under NDA and a completed security review. Reports are not published on this page. To request evidence, use the procurement form below with your company name, role, and questionnaire scope.
Submit third-party risk (TPRA) questionnaires, vendor security reviews, and procurement requests. We route these to legal@fors33.com. Do not attach confidential production data, API keys, or internal audit packages in this form.