Effective 2026-07-01.
Our security model is architectural, not promotional. LexArbiter is built so that client data cannot leave your hardware by default — because there is no server, no account, and no network code in the core application to carry it anywhere.
LexArbiter is a Windows desktop application that runs entirely on the attorney's own machine. It has no cloud back end, no user account, no login, and no license server. The AI search model ships inside the product and loads in forced-offline mode, so nothing is downloaded or transmitted during normal use. This is not a policy promise you have to trust — it is a property of how the software is built, and you can verify it yourself (see "Verify it yourself" below).
LexArbiter can optionally connect to Clio so that documents you have prepared can be filed into the matter you choose. Because this feature moves data between your machine and a cloud service, we hold it to a clear, auditable standard:
In short: the core product is fully offline; the Clio integration is the one place data intentionally leaves your machine, and it goes only where you send it — into your own Clio account — with us nowhere in the path.
Data in transit for the optional Clio integration is protected with TLS. Data at rest is protected by the security controls of your own operating system and hardware (for example, Windows account controls and full-disk encryption such as BitLocker, which we recommend enabling on any machine that holds client files).
The core application has no remote authentication because it exposes no remote surface — access to the app is access to your computer, governed by your own OS login and physical security. The Clio integration authenticates through Clio's own OAuth login; we never handle those credentials.
To run the business (not the software) we use a small set of standard providers: a payment processor (Stripe) and storefront platforms (Payhip, Etsy, Gumroad) for purchases, and email for delivery and support. None of these providers receive your client documents or case data — they see only order and contact information necessary to complete a sale and deliver a download. See our Privacy Policy for details.
We do not hold your client documents or case data at all, so there is nothing on our side to breach or subpoena. For purchases, we retain order records as required for delivery, license tracking, and tax/legal compliance. You may request a copy or deletion of your purchase records, subject to legal retention requirements, at the contact below.
LexArbiter was designed around ABA Formal Opinion 512 on generative AI in legal practice: PII is redacted before AI sees a page (Competence, Rule 1.1); no data leaves your device in normal use and there is no server to subpoena (Confidentiality, Rule 1.6); and a local, exportable, time-stamped audit log records tool actions (Supervision, Rule 5.3).
Every LexArbiter package includes a one-click air-gap self-test (Verify_Air_Gap.bat). It runs the real indexing-and-search engine while actively blocking and reporting any non-loopback network call. A "PASS" result means nothing left your machine during that run. You can also confirm independently with tools like Wireshark or Windows Resource Monitor.
We welcome good-faith security research. If you believe you have found a vulnerability in LexArbiter or the Clio connector, please see our Vulnerability Disclosure & Patch Policy and email contact@victoriousbyrachael.com.
Security questions, questionnaires, and disclosure reports: contact@victoriousbyrachael.com.
This page describes our security practices in good faith and may evolve as our products do. It is not a warranty or legal advice.