Magrios / Knowledge / enterprise / Liability caps vs carve-outs: where the real exp

Liability caps vs carve-outs: where the real exposure sits

Comparison · enterprise · 4 min read · last verified 2026-07-21

Reviewed before publication Editorial board — revision applied Independent commercial review
In shortThe liability cap is only half the picture. Carve-outs — the claims excluded from that cap, especially data breach, confidentiality, IP infringement, and gross negligence — determine which risks the headline number actually covers.

The framing buyers get wrong

The instinct on reading a limitation of liability section is to look at one number: the cap, usually expressed as a multiple of fees paid (12 months of fees is the common baseline; 2x or 3x fees shows up for larger or higher-risk deals). That number feels like the whole story. It isn't. The carve-outs — the categories of claims excluded from the cap, either uncapped or capped separately and higher — are where the real exposure sits, because they determine which claims the headline number actually applies to.

A "3x fees" liability cap sounds like real protection until you notice that data breach, confidentiality, IP infringement, and indemnification claims are all carved out and capped separately, or not capped at all. At that point the 3x number only ever applies to the categories of harm least likely to produce your worst-case scenario — and negotiating it up to 4x buys you nothing on the risks that actually keep you up at night.

How the standard structure works

The cap sets a ceiling on the vendor's (and often, mutually, the customer's) total liability for damages arising from the agreement. It's typically expressed as a multiple of fees paid — commonly fees paid in the 12 months preceding the claim — rather than a flat dollar figure, so it scales with deal size.

The carve-outs list categories of claims that either fall outside the cap entirely (uncapped) or fall under a separate, usually higher, cap. This is standard market structure in commercial SaaS agreements, not unusual or aggressive drafting on its own — the negotiation is over which categories are carved out and how the carve-out is capped, not whether carve-outs exist at all.

Typical carve-out categories:

Where the real exposure sits

For a typical B2B SaaS deal, the scenario a customer actually fears — a data breach exposing their end users' personal data, triggering regulatory fines, breach notification costs, and reputational harm — often lands squarely in carve-out territory, not under the general cap. That means the headline cap number is close to irrelevant for the risk the customer is most worried about; what matters is whether data breach has its own carve-out, how that carve-out is capped (if at all), and whether it's mutual.

Conversely, a vendor evaluating its own exposure should look at the same list from the other side: an uncapped indemnification obligation for IP infringement, stacked with an uncapped confidentiality carve-out, can expose the business to liability many multiples of the deal's actual value — which is exactly why vendors push to keep carve-outs narrow and, where they can't avoid a carve-out, to attach a separate super-cap instead of leaving it fully uncapped.

What tends to get negotiated

The practical takeaway

Don't evaluate a liability section by the cap multiple alone. Read the carve-out list first, and ask: for the type of harm we're actually worried about in this relationship — usually data exposure for a data-processing vendor — which number applies? If the answer is "the general cap, because data breach isn't carved out," that's worth flagging before signature, not after an incident.

This describes common market practice in commercial SaaS contracting as general information, not legal advice. Liability and indemnification terms are heavily negotiated and jurisdiction-dependent — have specific contract language reviewed by counsel before relying on it.

Frequently asked questions

What is a liability cap in a SaaS contract?

A ceiling on the total damages a party can recover under the agreement, typically expressed as a multiple of fees paid — often 12 months of fees — rather than a flat dollar amount.

What is a carve-out in a limitation of liability clause?

A category of claims excluded from the general liability cap, either left uncapped or subject to a separate, usually higher, cap. Common carve-outs include confidentiality breaches, IP indemnification, and gross negligence or willful misconduct.

Is data breach usually carved out of the liability cap?

It's one of the most actively negotiated carve-outs in current SaaS contracting. Whether it's uncapped, given its own super-cap, or left under the general cap varies by deal and negotiating leverage — there's no single market default.

Why does the carve-out list matter more than the cap number?

Because the cap only applies to claims that aren't carved out. If the risk you're actually worried about — often data breach — is excluded from the cap, the headline multiple doesn't protect against your real exposure.

Is this legal advice?

No. This describes common market practice in commercial SaaS contracts as general information. Liability terms are heavily negotiated and vary by jurisdiction and deal specifics — have contract language reviewed by qualified counsel.

Further reading — chosen for this article
Entities in this research
liability caplimitation of liabilitycarve-outindemnificationgross negligencewillful misconductconfidentiality breachIP infringement
Related knowledge

What is an MSA? A practical definition for software sellers · shared entities

What Is a Redline? A Practical Definition · shared entities

What is source code escrow? A practical definition · linked

What is vendor consolidation? A practical definition · same topic

Why enterprise deals need a deployment plan before signature, not after · same topic

Recently updated

Magrios vs Athena · 2026-07-21

Magrios vs Writesonic · 2026-07-21

Magrios vs Semrush · 2026-07-21

Magrios vs peec · 2026-07-21

Where does your brand stand?
Check your AI visibility free — real evidence, not a score.
Check my visibility or run the full analysis →