What is in scope
Anything we operate:
- antchambers.com — this website.
- AntChambers private instances we host for subscribing firms, but only an instance you are authorised to access. See clause 04.
- The signed licence mechanism, the update channel, and anything else in the delivery path.
Out of scope: our sub-processors’ own infrastructure — report those to them — and reports that amount to a scanner’s output with no demonstrated impact.
A finding does not need to be exploitable to be worth sending. If you are unsure whether something counts, send it. We would rather triage a non-issue than miss a real one.
How to report
Email support@antchambers.com with “security” in the subject line. Include what you found, where, and the steps to reproduce it. A proof of concept helps; a video is not necessary.
Tell us how you would like to be credited, or that you would rather not be. If you need to encrypt the report, say so in a first message and we will arrange a key.
Please do not open a public issue or post the finding before we have had the chance to fix it. Clause 05 explains what we undertake in return.
What to expect from us
- Acknowledgement
- Within two business days, from a person rather than an autoresponder.
- Triage
- Within five business days: whether we agree it is a vulnerability, our assessment of severity, and what we intend to do.
- Progress
- An update at least every ten business days until it is closed, including when the answer is “still working on it”.
- Disclosure
- We will tell you when the fix ships, and agree timing with you before saying anything publicly.
- If we disagree
- We will say why, in specific terms. “Working as intended” on its own is not an answer we will give you.
Where a finding affects a customer’s instance, that firm is notified on the timetable in our Data Processing Addendum — which does not wait on a fix being ready.
What we ask of you
- Do not access anyone else’s data. If you can reach a firm’s matters or documents, stop, and tell us that you could — that is the finding.
- Do not modify or delete anything that is not yours.
- Do not run denial-of-service tests, load tests, or anything that degrades service for a working firm.
- Do not social-engineer our staff or our customers’ staff, and do not attempt physical access.
- Use your own account or a test instance. Ask us and we will provide one.
- Give us reasonable time to fix it before disclosing.
Our customers are law firms. The material behind these systems is privileged and belongs to their clients — people who never chose to be part of anyone’s research. That is why clause 04 is stricter than it might be elsewhere.
Safe harbour
If you research in good faith and within clause 04, ANT LLP undertakes:
- We will not bring or support legal action against you in relation to the research.
- We will not report you to law enforcement for it.
- We will treat your activity as authorised for the purposes of any applicable computer-misuse law.
- If a third party brings action over research conducted within these rules, we will make it known that it was authorised.
This undertaking is ours to give and covers only our own systems. It cannot bind a customer, a sub-processor or a regulator.
No bounty, and why we say so plainly
We do not currently pay for vulnerability reports. We would rather state that at the top than have you spend a weekend on something in the expectation of a reward that is not coming.
What we do offer: a real answer from someone who understands the system, credit in the release notes if you want it, and a written acknowledgement you can point to. If that changes, this clause changes with it.