Liability caps vs carve-outs: where the real exposure sits
Comparison · enterprise · 4 min read · last verified 2026-07-21
The framing buyers get wrong
The instinct on reading a limitation of liability section is to look at one number: the cap, usually expressed as a multiple of fees paid (12 months of fees is the common baseline; 2x or 3x fees shows up for larger or higher-risk deals). That number feels like the whole story. It isn't. The carve-outs — the categories of claims excluded from the cap, either uncapped or capped separately and higher — are where the real exposure sits, because they determine which claims the headline number actually applies to.
A "3x fees" liability cap sounds like real protection until you notice that data breach, confidentiality, IP infringement, and indemnification claims are all carved out and capped separately, or not capped at all. At that point the 3x number only ever applies to the categories of harm least likely to produce your worst-case scenario — and negotiating it up to 4x buys you nothing on the risks that actually keep you up at night.
How the standard structure works
The cap sets a ceiling on the vendor's (and often, mutually, the customer's) total liability for damages arising from the agreement. It's typically expressed as a multiple of fees paid — commonly fees paid in the 12 months preceding the claim — rather than a flat dollar figure, so it scales with deal size.
The carve-outs list categories of claims that either fall outside the cap entirely (uncapped) or fall under a separate, usually higher, cap. This is standard market structure in commercial SaaS agreements, not unusual or aggressive drafting on its own — the negotiation is over which categories are carved out and how the carve-out is capped, not whether carve-outs exist at all.
Typical carve-out categories:
- Confidentiality breaches — since damages from a leaked trade secret or roadmap can dwarf a modest fee-based cap.
- IP infringement claims and the indemnification obligations tied to them — the vendor's promise to defend and cover costs if their product infringes a third party's patent or copyright.
- Gross negligence or willful misconduct — many jurisdictions limit the enforceability of liability caps against fraud and willful misconduct, so carving those out explicitly costs the vendor little. Gross negligence is a different question: how it is defined and whether a cap can be enforced against it varies materially by jurisdiction, including between US states. That variation is a reason to negotiate the language rather than assume a court will supply the result.
- Data breach / breach of data protection obligations — an increasingly common, and increasingly contested, carve-out as data-heavy SaaS deals have grown. Whether data breach gets its own carve-out, its own higher sub-cap, or stays under the general cap is one of the most actively negotiated points in enterprise SaaS contracts today.
- Payment obligations — a customer's obligation to pay fees owed is typically excluded from any liability cap on either side, since it isn't a "damages" claim in the same sense.
Where the real exposure sits
For a typical B2B SaaS deal, the scenario a customer actually fears — a data breach exposing their end users' personal data, triggering regulatory fines, breach notification costs, and reputational harm — often lands squarely in carve-out territory, not under the general cap. That means the headline cap number is close to irrelevant for the risk the customer is most worried about; what matters is whether data breach has its own carve-out, how that carve-out is capped (if at all), and whether it's mutual.
Conversely, a vendor evaluating its own exposure should look at the same list from the other side: an uncapped indemnification obligation for IP infringement, stacked with an uncapped confidentiality carve-out, can expose the business to liability many multiples of the deal's actual value — which is exactly why vendors push to keep carve-outs narrow and, where they can't avoid a carve-out, to attach a separate super-cap instead of leaving it fully uncapped.
What tends to get negotiated
- Whether data breach gets a carve-out at all, and if so, whether it's uncapped or subject to a separate, higher multiple. Published practitioner and negotiation commentary on data-breach super-caps tends to land in the low single-digit multiples of fees — commonly discussed around 2x–3x, with 3x–5x cited as a fallback position. Treat that as negotiation guidance rather than measured market data: there is no public dataset of executed SaaS caps, and the multiple you actually get is deal-specific and tracks negotiating leverage on both sides.
- Mutuality — whether carve-outs apply symmetrically to both parties or only protect the customer.
- Insurance backstops — cyber liability insurance minimums are increasingly required alongside (not instead of) a liability carve-out, since insurance can cover exposure a contractual cap can't fully absorb.
- Definition precision on "gross negligence" and "willful misconduct", since vague standards create disputes later about whether a carve-out was even triggered.
The practical takeaway
Don't evaluate a liability section by the cap multiple alone. Read the carve-out list first, and ask: for the type of harm we're actually worried about in this relationship — usually data exposure for a data-processing vendor — which number applies? If the answer is "the general cap, because data breach isn't carved out," that's worth flagging before signature, not after an incident.
This describes common market practice in commercial SaaS contracting as general information, not legal advice. Liability and indemnification terms are heavily negotiated and jurisdiction-dependent — have specific contract language reviewed by counsel before relying on it.