Effective 2026-07-01.
We take the security of our software seriously and welcome reports from users and security researchers acting in good faith. This policy explains how to report a vulnerability, what you can expect from us, and how we deliver patches.
This policy covers the LexArbiter desktop application and the LexArbiter Clio connector, as distributed by Victorious by Rachael. Because the core application runs entirely on the user's own machine with no server component, our attack surface is deliberately small — but no software is perfect, and we want to hear from you.
Email contact@victoriousbyrachael.com with the subject line "Security — Vulnerability Report." Please include:
If you wish to encrypt your report, say so in an initial email and we will arrange a secure channel.
We will not pursue legal action against researchers who, in good faith, discover and report a vulnerability under this policy, provided you:
Because LexArbiter runs locally, we ask that you never test against a real client's live case files. Use synthetic or your own test data.
| Stage | Target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Initial assessment & severity triage | Within 10 business days |
| Status updates during remediation | At least every 2 weeks |
| Coordinated public disclosure (if any) | By mutual agreement, typically within 90 days |
These are targets, not contractual guarantees. Victorious by Rachael is a small, founder-run business; we will always tell you honestly where a fix stands.
| Severity | Example | Remediation target |
|---|---|---|
| Critical | Unauthorized exposure of client data; remote code execution | Patched build issued as quickly as practicable — priority over all other work |
| High | Local privilege or data-integrity issue with a plausible path to exploitation | Targeted within 30 days |
| Medium / Low | Hardening gaps, edge-case bugs with limited impact | Rolled into the next scheduled maintenance release |
By design, LexArbiter does not phone home or silently auto-update — that is a core part of its privacy guarantee. Because of that, security updates are delivered directly to licensed customers, not pushed automatically:
Free bug-fix and security updates are provided for the current major version (v1.x). Feature upgrades to a future major version (v2.0) may be a paid upgrade, with an early-adopter discount for existing owners.
The current v1.x release line receives security support. When a future major version ships, we will publish how long the prior line continues to receive security fixes.
We are happy to credit researchers who responsibly disclose valid vulnerabilities, if you would like acknowledgment. We do not currently operate a paid bug-bounty program.
All security reports and questions: contact@victoriousbyrachael.com.
This policy describes our good-faith practices and may be updated as our products evolve. It is not a warranty or legal advice.