AntChambers

ANT LLP · antchambers.com

Responsible Disclosure

If you have found a security problem, we would rather hear it from you than from a customer. This says how to tell us and what happens next.

Effective
23 August 2026
Applies to
antchambers.com and the AntChambers service
Governing law
India · courts at Mumbai
Clause 01

What is in scope

Anything we operate:

  • antchambers.com — this website.
  • AntChambers private instances we host for subscribing firms, but only an instance you are authorised to access. See clause 04.
  • The signed licence mechanism, the update channel, and anything else in the delivery path.

Out of scope: our sub-processors’ own infrastructure — report those to them — and reports that amount to a scanner’s output with no demonstrated impact.

A finding does not need to be exploitable to be worth sending. If you are unsure whether something counts, send it. We would rather triage a non-issue than miss a real one.

Clause 02

How to report

Email support@antchambers.com with “security” in the subject line. Include what you found, where, and the steps to reproduce it. A proof of concept helps; a video is not necessary.

Tell us how you would like to be credited, or that you would rather not be. If you need to encrypt the report, say so in a first message and we will arrange a key.

Please do not open a public issue or post the finding before we have had the chance to fix it. Clause 05 explains what we undertake in return.

Clause 03

What to expect from us

Acknowledgement
Within two business days, from a person rather than an autoresponder.
Triage
Within five business days: whether we agree it is a vulnerability, our assessment of severity, and what we intend to do.
Progress
An update at least every ten business days until it is closed, including when the answer is “still working on it”.
Disclosure
We will tell you when the fix ships, and agree timing with you before saying anything publicly.
If we disagree
We will say why, in specific terms. “Working as intended” on its own is not an answer we will give you.

Where a finding affects a customer’s instance, that firm is notified on the timetable in our Data Processing Addendum — which does not wait on a fix being ready.

Clause 04

What we ask of you

  • Do not access anyone else’s data. If you can reach a firm’s matters or documents, stop, and tell us that you could — that is the finding.
  • Do not modify or delete anything that is not yours.
  • Do not run denial-of-service tests, load tests, or anything that degrades service for a working firm.
  • Do not social-engineer our staff or our customers’ staff, and do not attempt physical access.
  • Use your own account or a test instance. Ask us and we will provide one.
  • Give us reasonable time to fix it before disclosing.

Our customers are law firms. The material behind these systems is privileged and belongs to their clients — people who never chose to be part of anyone’s research. That is why clause 04 is stricter than it might be elsewhere.

Clause 05

Safe harbour

If you research in good faith and within clause 04, ANT LLP undertakes:

  • We will not bring or support legal action against you in relation to the research.
  • We will not report you to law enforcement for it.
  • We will treat your activity as authorised for the purposes of any applicable computer-misuse law.
  • If a third party brings action over research conducted within these rules, we will make it known that it was authorised.

This undertaking is ours to give and covers only our own systems. It cannot bind a customer, a sub-processor or a regulator.

Clause 06

No bounty, and why we say so plainly

We do not currently pay for vulnerability reports. We would rather state that at the top than have you spend a weekend on something in the expectation of a reward that is not coming.

What we do offer: a real answer from someone who understands the system, credit in the release notes if you want it, and a written acknowledgement you can point to. If that changes, this clause changes with it.