← Back to home

Vulnerability Disclosure & Patch Policy

Effective 2026-07-01.

We take the security of our software seriously and welcome reports from users and security researchers acting in good faith. This policy explains how to report a vulnerability, what you can expect from us, and how we deliver patches.

Scope

This policy covers the LexArbiter desktop application and the LexArbiter Clio connector, as distributed by Victorious by Rachael. Because the core application runs entirely on the user's own machine with no server component, our attack surface is deliberately small — but no software is perfect, and we want to hear from you.

How to report

Email contact@victoriousbyrachael.com with the subject line "Security — Vulnerability Report." Please include:

If you wish to encrypt your report, say so in an initial email and we will arrange a secure channel.

Safe harbor for good-faith research

We will not pursue legal action against researchers who, in good faith, discover and report a vulnerability under this policy, provided you:

Because LexArbiter runs locally, we ask that you never test against a real client's live case files. Use synthetic or your own test data.

What you can expect from us

StageTarget
Acknowledge your reportWithin 3 business days
Initial assessment & severity triageWithin 10 business days
Status updates during remediationAt least every 2 weeks
Coordinated public disclosure (if any)By mutual agreement, typically within 90 days

These are targets, not contractual guarantees. Victorious by Rachael is a small, founder-run business; we will always tell you honestly where a fix stands.

Severity & patch targets

SeverityExampleRemediation target
CriticalUnauthorized exposure of client data; remote code executionPatched build issued as quickly as practicable — priority over all other work
HighLocal privilege or data-integrity issue with a plausible path to exploitationTargeted within 30 days
Medium / LowHardening gaps, edge-case bugs with limited impactRolled into the next scheduled maintenance release

How patches are delivered

By design, LexArbiter does not phone home or silently auto-update — that is a core part of its privacy guarantee. Because of that, security updates are delivered directly to licensed customers, not pushed automatically:

Free bug-fix and security updates are provided for the current major version (v1.x). Feature upgrades to a future major version (v2.0) may be a paid upgrade, with an early-adopter discount for existing owners.

Supported versions

The current v1.x release line receives security support. When a future major version ships, we will publish how long the prior line continues to receive security fixes.

Out of scope

Recognition

We are happy to credit researchers who responsibly disclose valid vulnerabilities, if you would like acknowledgment. We do not currently operate a paid bug-bounty program.

Contact

All security reports and questions: contact@victoriousbyrachael.com.

This policy describes our good-faith practices and may be updated as our products evolve. It is not a warranty or legal advice.