Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Before I put my team on your paper: what's your standard liability and indemnification structure, and where's your actual flexibility?
The question a General Counsel / Chief Legal Officer (CLO) asks.
The short answer
Cap at trailing twelve months' fees, mutual fault-based indemnities, decision outcomes carved out on fiduciary principle — with genuine anchor-customer flexibility on breach super-caps, notification SLAs, and dated certification milestones. I'll tell you what's immovable so your counsel hours go where they count.
The full executive answer
I'll save your team the first two review cycles by mapping it now. The standard structure: liability capped at fees paid in the trailing twelve months — that's published in our terms, not hidden for negotiation theatre; mutual indemnities where each party covers what it controls — we indemnify for third-party IP claims against the platform itself and stand behind our security and processing obligations; you indemnify for your content and your use. Warranties: the service performs materially as documented, we maintain the named security controls, we comply with applicable law as processor. Disclaimers: the decision-support boundary — no warranty that any business decision informed by the platform succeeds, for the fiduciary-allocation reasons we've discussed.
Where flexibility genuinely exists, because pre-launch anchor customers get real accommodation: super-caps or carve-outs from the general cap for data-protection breaches and confidentiality violations caused by our negligence — the two areas where a cap tied to modest early fees genuinely under-protects you, and where enterprise buyers reasonably push; enhanced notification SLAs; audit rights beyond our standard; certification milestones (SOC 2 Type I by a named date) as contractual commitments with remedies; and DPA terms on your paper if your privacy office requires it. As an early customer you have more leverage over our standard terms than anyone who follows you, and we'd rather trade contract terms than discounts.
Where flexibility doesn't exist, so no one wastes hours: uncapped liability for decision outcomes (the fiduciary allocation is principled, not just protective); warranty of frontier-model training-data provenance (impossible honestly); and unlimited-liability positions generally, which for a company our size would be a promise without an asset behind it — I'd rather tell you the cheque we can't cash than sign it. One more candid note: cyber insurance to stand behind the indemnities binds at commercial launch, so if certificate-of-insurance requirements are gating for you, sequence that into the contract timeline — it's weeks, not quarters.
Grounded in: Standard SaaS limitation-of-liability doctrine; GDPR Art. 82 (allocation of processor/controller liability); SOC 2 TSC CC9.2 (contractual risk transfer context).
The natural next questions
Related governed answers
- Export controls and trade sanctions — does any of this apply to you? We have subsidiaries in jurisdictions that make my trade-compliance team nervous.?
- Under the EU AI Act, are you the provider and am I the deployer? Because if your workforce-analysis modules are Annex III high-risk, one of us owes Brussels a conformity assessment — and I want to know which of us it is.?
- Do you have SOC 2 or ISO 27001? If not, you understand my procurement team will stop reading right there.?
Want this answered live, on your data?