Where your information sits, and who can reach it
Your firm's own private instance, managed by AntChambers
A firm evaluating software has to answer two questions for its own clients: where does our information sit, and who else can reach it. This page is written so you can answer both without ringing anybody.
The answer before the detail
A boundary you can inspect.
- PeopleBrowser
- Firm's front doorTLS & web tier
- ApplicationAntChambers
That work does not require a shared copy of matters, documents, bills or time entries.
- Dedicated
- One deployable stack and one PostgreSQL database for the firm.
- Managed
- AntChambers operates updates, service health and the subscription boundary.
- Recoverable
- The standard service scope includes daily encrypted off-server backups retained for 30 days, with a restore test before launch and quarterly thereafter. Recovery arrangements are confirmed before go-live.
- Exportable
- The firm retains ownership; a complete export is produced on request within ten working days.
What a firm actually gets
One firm, one private instance.
Your firm gets its own private instance. Not an account on a system other firms also use — a private instance operated for one firm and holding nothing but that firm's work.
- Your own application boundary, provisioned and operated by AntChambers for one firm.
- Your own database, holding only your clients and matters.
- Your own document store, isolated from every other firm.
- Your own backup boundary, with retention and restore terms stated before go-live.
- Your own web address, with certificates managed as part of the service.
We operate an isolated application and database for your firm. Underlying cloud infrastructure may be shared; the standard offer does not include a dedicated physical server.
Managed by one provider does not have to mean stored in one shared system.
Operations without pooled firm data
Managed centrally. Isolated where it matters.
For each isolated stack, AntChambers administers the signed subscription entitlement, tested releases, backup routines and health checks. Those functions do not require moving matters, clients, documents, bills or time entries into a shared customer database.
The instance reads its signed entitlement locally and has a grace state before becoming read-only. A renewal or network incident should not become a sudden lock-out from current legal and financial records.
A module you have not selected is simply not there — no screens, no menu entries, and nothing running quietly in the background.
Who can see what, and what is remembered
Access, and the record of it.
Getting in
People sign in with an email address and a password, and can be required to confirm with a code from their phone as well. Repeated failed attempts lock an account. An administrator can reset a password; nobody at our end can read one.
Seeing only what you should
Every module carries its own permissions — who may look, who may change, who may approve — and the firm decides which of them each designation gets. A supervisor approving a team’s week, a partner reviewing a matter and an associate seeing only their own entries are three different grants. The rules are enforced by the system itself, not merely hidden from the screen.
The record
Changes are recorded as they happen, with the person and the time against each one. Operational archiving preserves history; retention and deletion follow the signed agreement. Sign-ins are recorded alongside. When somebody asks who altered a bill in March, the answer is a search rather than an investigation.
Our operational access
Infrastructure administration and application support are separate from a user's authority to open matters. Support access that could expose firm data is restricted, time-bound and recorded rather than left permanently open.
What we do not claim
Document access follows the matter it is filed under, so there is no per-document permission list yet. We hold no third-party security certification today, and we would rather say so than imply one. The full security review is kept with the software and can be shared under NDA during an evaluation.
Bringing a firm live
Four steps.
Agree the operating boundary
We record the hosting region, data and backup location, retention, recovery expectations, firm size and modules in the implementation scope.
Provision the private instance
AntChambers creates the application, database, Redis, document store and backup boundary, then applies the firm’s identity and settings.
Secure the front door
The agreed web address, managed TLS, access rules, administrator setup and operational monitoring are verified before data migration.
Import and go live
Standard setup includes one template import of up to 1,000 combined client and matter records and two one-hour remote training sessions. Historical bills, time, document archives and cleanup are separately quoted.
The detail your IT people will want
For your IT team.
Everything above, stated the way an engineer would want it. If you have someone who looks after your systems, this is the part to forward to them.
- Shape
- A dedicated application stack per firm. The product remains a modular monolith; isolation comes from the deployment boundary, not tenant labels in one shared database.
- Platform
- .NET 10 and Angular. A Linux host with Docker.
- Database
- PostgreSQL — one database per firm instance, a separate schema per module, no foreign keys crossing between them.
- Cache & jobs
- Redis for cache, distributed locks, background-job coordination and real-time notifications. This is what lets the application tier scale out later without a rewrite.
- Background jobs run on Hangfire; the dashboard is deny-by-default and permission-gated.
- File storage
- A dedicated volume or object-storage boundary for the firm, in the location stated in the order and security schedule.
- Entitlements
- The standard subscription includes all standard modules and a named-user allowance. The instance verifies its signed entitlement locally, with a grace state before it becomes read-only.
- Authentication
- JWT bearer with short-lived access tokens and rotating refresh tokens. TOTP two-factor with recovery codes, and lockout on repeated failures. Signing keys are generated per private instance during provisioning.
- Authorisation
- Permissions are declared by modules and assigned by core; every protected endpoint requires an explicit permission policy. The server is the enforcement point — the SPA's route guards are convenience, not a boundary.
- Audit
- Captured at the data layer via a SaveChanges interceptor plus auth events, with soft deletes and created/updated/deleted-by on every entity. Filterable in-app, exportable as CSV.
- Transport
- TLS terminates at the managed web tier. Security headers and a content-security policy apply to the API host and web tier. The API is versioned at /api/v1 and throttled per client address. Uploads stream to the isolated file store, size-capped at the web tier.
- Health
- /healthz for liveness and /readyz for readiness (database and Redis), so monitoring can tell "starting" from "broken".
- Upgrades
- AntChambers schedules a tested image, takes a pre-upgrade backup and runs migrations under a distributed lock before completing health checks.
- Backups
- Scheduled per-instance database and document backups, with retention and restore responsibility recorded in the service schedule.
What partners ask before signing
Straight answers.
Where exactly does our information sit?
Inside a private AntChambers instance dedicated to your firm, with its own database and document-storage boundary. The hosting region, backup location and retention terms are recorded in the order and security schedule.
Can it work with no internet connection?
No. AntChambers is a managed private service and people need a secure network connection to use it. Private means isolated per firm; it does not mean an offline server operated by the client.
Who at your end can see our matters?
Routine operations use health, version and backup status rather than matter content. Any support access that could expose firm data must be restricted, time-bound and recorded, with the firm informed under the support process.
What happens if we stop paying?
Renewal does not erase or strand firm data. The contract states the reminder and grace process, what becomes read-only after expiry, how exports are provided and how long the isolated instance is retained before deletion.
How do updates reach us?
AntChambers schedules and applies tested updates to the managed instance. Material maintenance is announced, backed up first and followed by health checks; the support schedule records the maintenance arrangement.
Is this a shared multi-tenant system?
No. The service is managed centrally, but each firm has its own application stack, database and document store. There is no tenant column separating your matters from another firm’s matters in one shared database.
Where to read next
Related
- Module catalogue
What the managed plan can turn on.
- Pricing
How the subscription and implementation are put together.
- Product overview
What the software does once it is up.
See how it fits your practice
A working demo takes about forty minutes. We use sample or anonymised matters, timesheets and fee notes to walk through your workflow. Please do not share confidential client information.