Limitation of Liability in SaaS Agreements: What Software and IT Companies Should Consider
- May 22, 2025
- 13 min read
A limitation of liability clause can be one of the most important provisions in a SaaS or software agreement.
A technology company may be entering into a contract worth $50,000, $250,000 or several million dollars. But without an appropriate limitation of liability provision, the financial exposure created by that agreement may be significantly greater than the revenue the company expects to earn from the customer.

This is one reason limitation of liability provisions are frequently among the most heavily negotiated sections of enterprise SaaS and IT contracts.
For SaaS, software and technology companies, the issue is not simply whether the agreement contains a liability cap.
The more important questions are:
What liabilities are actually covered by the cap?
How is the cap calculated?
Are some claims subject to a higher cap?
Are any liabilities completely uncapped?
How do indemnification obligations interact with the limitation?
Are certain damages excluded?
Does the clause apply consistently across the MSA, SOW, order form and SLA?
Does the company's insurance correspond with the contractual exposure it is accepting?
These questions can materially change the risk created by a technology contract.
What Is a Limitation of Liability Clause?
A limitation of liability clause establishes contractual boundaries on the damages or financial exposure one party may face if something goes wrong.
In a SaaS agreement, the clause commonly addresses two different concepts.
The first is a monetary liability cap.
For example, the contract may limit a party's aggregate liability to an amount connected to the fees paid or payable under the agreement.
The second is an exclusion of certain categories of damages.
The agreement may attempt to exclude categories such as indirect, incidental, special or consequential damages, or particular types of economic loss.
These concepts are related but distinct.
A contract may contain a liability cap while still allowing certain categories of damages within that cap.
Similarly, it may exclude certain damages while leaving other claims subject to a financial limit.
The wording of the clause matters.
Why Limitation of Liability Matters in SaaS and IT Contracts
Technology providers can face risks that are disproportionate to the value of an individual customer contract.
Consider a SaaS company charging a customer $75,000 annually.
The customer may depend on the software for an important business process. If the software becomes unavailable, the customer might claim lost revenue, operational disruption or other losses significantly exceeding the subscription fees it paid.
Without an appropriate contractual allocation of risk, the provider may be exposed to claims that bear little relationship to the economics of the transaction.
A limitation of liability clause attempts to create a more predictable allocation of that risk.
This can be particularly important for companies providing:
SaaS platforms;
cloud-based software;
enterprise software;
IT services;
cybersecurity services;
software implementation;
system integrations;
data processing;
professional technology services; or
other technology-dependent services.
For growing companies, liability provisions should therefore be considered as part of the broader SaaS and IT contract modernization process rather than treated as generic boilerplate.
What Is a Liability Cap in a SaaS Agreement?
A liability cap establishes the maximum amount one party may be required to pay for claims covered by the limitation.
A common structure ties the cap to fees.
For example, a contract might limit liability by reference to:
fees paid during the previous 12 months;
fees paid and payable during the previous 12 months;
fees under the applicable order form;
total fees under the agreement;
fees associated with the affected services; or
another agreed financial amount.
Although these formulations may sound similar, they can produce very different results.
Example: Fees Paid in the Previous 12 Months
Suppose a customer pays $20,000 per month.
If the liability cap is based on fees paid during the preceding 12 months, the cap may eventually reach $240,000.
But what happens if a claim occurs during the first month?
Only $20,000 may have been paid.
That may not reflect what either party intended.
For this reason, seemingly small drafting differences in a liability clause can create meaningful commercial consequences.
Should the Liability Cap Be Based on Annual Fees?
There is no universal formula that is appropriate for every SaaS contract.
A cap based on 12 months of fees is common in commercial negotiations, but whether it is appropriate depends on matters such as:
the value of the contract;
the nature of the technology;
the customer's reliance on the service;
the risks associated with failure;
the type of data involved;
insurance coverage;
bargaining power; and
the broader commercial relationship.
A contract lawyer reviewing a SaaS agreement should therefore consider the liability provision in the context of the actual transaction rather than treating a particular multiple of fees as automatically appropriate.
Aggregate Liability vs. Liability Per Claim
Another important distinction is whether the liability cap applies in aggregate or separately to each claim.
An aggregate cap generally limits total liability across all covered claims.
A per-claim cap may potentially apply multiple times.
For a technology provider entering into a long-term relationship, that difference can significantly affect exposure.
The agreement should make clear whether the agreed cap applies:
per claim;
per event;
per SOW;
per order form;
per contract year; or
in aggregate across the entire agreement.
Ambiguity can undermine the commercial purpose of the limitation.
What Is a SaaS Liability Supercap?
Enterprise customers increasingly request different liability caps for different categories of risk.
Rather than having one general cap apply to every claim, the agreement may contain:
General cap: For example, an amount tied to 12 months of fees.
Higher cap or "supercap": A larger amount that applies to specified categories of claims.
The higher cap might apply to matters such as:
confidentiality;
privacy obligations;
security incidents;
intellectual property indemnification; or
other specifically negotiated risks.
A supercap may be expressed as:
two times the general cap;
three times the general cap;
a fixed dollar amount;
available insurance proceeds; or
another negotiated amount.
Whether a SaaS provider should accept a supercap depends on the particular risk and transaction.
The important point is that a higher cap is still a cap.
That is materially different from agreeing to unlimited liability.
What Does It Mean When Liability Is "Uncapped"?
An uncapped liability is not subject to the contractual financial limit.
For a software provider, that can create substantial exposure.
Customers may request unlimited liability for claims involving:
fraud;
wilful misconduct;
gross negligence;
confidentiality;
data breaches;
privacy;
intellectual property infringement;
indemnification obligations; or
violations of law.
Not every request should necessarily be treated the same way.
Some exclusions may be commercially common or legally appropriate in particular circumstances. Others may create exposure that is disproportionate to the contract.
The provider should understand exactly which claims have been carved out of the cap and why.
A phrase such as:
"except for breach of this Agreement"
could potentially undermine the cap much more broadly than a narrowly defined exception.
This is why carve-outs deserve careful review.
What Are Carve-Outs From a Limitation of Liability?
A carve-out removes a particular type of liability from the general limitation.
There are several ways this can work.
A claim may be:
subject to the ordinary cap;
subject to a higher cap; or
completely excluded from the cap.
These are very different outcomes.
During a SaaS agreement review, it is important to identify not only the stated cap but every provision that may bypass it.
Should Confidentiality Breaches Be Uncapped?
Customers sometimes request unlimited liability for breaches of confidentiality.
Whether that is appropriate should be considered carefully.
Not every confidentiality breach carries the same potential consequences.
For example, accidentally disclosing commercially sensitive customer information is different from disclosing publicly available information that technically fell within an overly broad contractual definition.
Rather than automatically accepting unlimited exposure, parties may negotiate alternatives such as:
applying the general cap;
applying a separate supercap;
limiting the carve-out to particular categories of confidential information; or
distinguishing between ordinary breaches and more serious conduct.
The appropriate position depends on the relationship and the information involved.
How Should Data Breach Liability Be Addressed?
Data and cybersecurity risks are frequently central to modern SaaS negotiations.
Enterprise customers may seek enhanced liability where a security incident results in unauthorized access to customer data.
From the customer's perspective, a data incident may create regulatory, operational and financial consequences.
From the SaaS provider's perspective, unlimited data-related liability can create exposure far beyond the contract value and potentially beyond available insurance.
Technology companies should therefore consider questions such as:
What categories of data are being processed?
Is personal information involved?
What security obligations has the provider actually accepted?
Does the provider rely on third-party infrastructure?
What cyber insurance is available?
What types of losses could realistically arise?
Is a higher liability cap appropriate?
Should certain customer-caused incidents be excluded?
Cybersecurity obligations and liability provisions should be reviewed together.
There is little value in negotiating a carefully structured liability cap if a separate security schedule effectively creates unlimited exposure.
How Does Intellectual Property Indemnification Affect Liability?
Intellectual property infringement is another recurring issue in SaaS agreements.
A customer may request that the provider indemnify it against third-party claims alleging that the software infringes another party's intellectual property rights.
That may be commercially reasonable depending on the circumstances.
The separate question is how much liability attaches to that indemnification obligation.
An IP indemnity might be:
subject to the general liability cap;
subject to a higher IP-specific cap; or
uncapped.
The provider should also consider whether the indemnity excludes claims resulting from:
customer modifications;
unauthorized use;
combinations with third-party products;
customer-provided materials; or
continued use after notice of an infringement issue.
Indemnification and limitation of liability should therefore always be reviewed together.
Indemnification and Limitation of Liability Are Not the Same Thing
This distinction is important.
An indemnity identifies circumstances in which one party must protect or compensate the other in relation to specified claims.
A limitation of liability establishes boundaries on the amount or type of liability that may arise.
The existence of an indemnity does not necessarily tell you whether the indemnified claim is capped.
That depends on how the provisions interact.
A SaaS agreement might say:
The provider will indemnify the customer against specified third-party IP claims.
Elsewhere, the agreement might state:
The limitation of liability does not apply to indemnification obligations.
The effect may be that the IP indemnity is unlimited.
That result may not be obvious when reading either provision separately.
A proper software contract review should therefore examine cross-references and interactions across the entire agreement.
What Are Consequential Damages?
Technology agreements often exclude "indirect, incidental, special, exemplary or consequential damages."
Those terms are frequently repeated in contracts, but the more important issue is what losses the parties actually intend to exclude.
Contracts may also expressly address categories such as:
lost profits;
lost revenue;
loss of business;
loss of goodwill;
business interruption;
loss of anticipated savings; or
loss or corruption of data.
The parties should consider how these exclusions interact with the actual risks of the service.
For example, if the customer is purchasing business-critical software, claims for lost revenue may be among the most foreseeable consequences of an outage.
The contract should make clear whether those claims are intended to be recoverable.
Direct Damages vs. Indirect Damages
A common mistake is assuming that a particular loss will always be considered "direct" or "indirect."
Characterization can depend on the circumstances, the contractual language and the applicable law.
For that reason, technology agreements often identify particular categories of damages expressly rather than relying entirely on broad labels.
The goal is greater predictability.
A well-drafted clause should help the parties understand the commercial allocation of risk before a dispute occurs.
How Does an SLA Affect the Liability Clause?
Service Level Agreements often provide specific remedies for service failures.
For example, a customer may receive service credits if availability falls below an agreed threshold.
That raises an important question:
Are service credits the customer's exclusive remedy for an SLA failure, or can the customer also claim damages?
If the documents do not answer this question clearly, the provider may face both service credits and a broader damages claim.
The interaction between the SLA and the liability clause should therefore be considered when structuring the contract.
This is particularly important where the company uses an MSA and SOW contracting structure with separate schedules or service terms.
Does the Liability Cap Apply to Every SOW?
This becomes important when one MSA governs multiple projects.
Suppose a customer pays:
$150,000 for its annual SaaS subscription;
$200,000 for implementation;
$75,000 for another SOW; and
$100,000 for additional consulting.
If the agreement says liability is capped at "fees paid under this Agreement," what amount is being referenced?
All fees?
Fees under the affected SOW?
Fees during a particular period?
The contract should answer this intentionally.
A modular contracting framework requires equally careful liability drafting.
Should Liability Be Mutual?
Customers sometimes request that liability provisions be mutual.
A mutual limitation applies the same general framework to both parties.
That can appear inherently fair.
However, the parties may face different types of risk.
For example, the technology provider may have substantial obligations concerning:
software performance;
intellectual property;
security;
data processing; and
service availability.
The customer's principal obligations may concern:
payment;
permitted use;
customer data; and
compliance with use restrictions.
The appropriate allocation therefore depends on the particular relationship.
"Mutual" does not necessarily mean economically equivalent.
What Happens When the Customer Uses Its Own Contract?
Many enterprise customers require technology vendors to sign the customer's procurement agreement rather than the provider's standard SaaS agreement.
This can materially change the risk analysis.
Customer-drafted agreements may contain:
unlimited liability;
broad indemnification obligations;
extensive security warranties;
penalties or credits;
broad IP ownership provisions;
significant audit rights;
long survival periods; and
liability provisions drafted primarily for the customer's protection.
A company should not assume that agreeing to the customer's MSA is simply an administrative step required to close the deal.
For larger transactions, an IT contract lawyer can review the customer agreement against the company's existing contractual positions and identify areas requiring negotiation.
Liability Should Be Considered Against Contract Value
Risk allocation should make commercial sense.
If a SaaS provider earns $25,000 from a contract but assumes potentially unlimited liability for a broad range of claims, the economics may be difficult to justify.
On the other hand, an enterprise customer paying substantial fees for mission-critical software may reasonably expect a provider to accept meaningful responsibility for risks within its control.
The goal is not necessarily to transfer every risk to the other party.
It is to establish a proportionate and understandable allocation of responsibility.
Liability Should Also Be Considered Against Insurance
Contract negotiations should not occur independently from insurance coverage.
Technology companies may carry coverage such as:
commercial general liability insurance;
technology errors and omissions insurance;
cyber liability insurance; or
other specialized policies.
However, having insurance does not mean every contractual liability will necessarily be insured.
Policy limits, exclusions, deductibles and coverage conditions matter.
For this reason, agreeing to liability "up to available insurance" should be considered carefully.
The company should understand the difference between its contractual exposure and its actual insurance coverage.
Common Limitation of Liability Mistakes in SaaS Contracts
Several issues regularly deserve attention during IT and software contract review.
Assuming the Cap Applies to Everything
A contract may contain a liability cap followed by several exceptions that substantially reduce its value.
Accepting Broad Carve-Outs
Phrases such as "any breach of confidentiality" or "any violation of law" can create significantly broader exposure than anticipated.
Reviewing Indemnification Separately
Indemnification obligations may fall outside the cap depending on the wording.
Ignoring Security Schedules
A security schedule may contain separate liability language or warranties inconsistent with the MSA.
Failing to Coordinate the MSA and SOW
One document may inadvertently create obligations that undermine protections in another.
Using the Same Liability Structure for Every Customer
A $10,000 subscription and a $1 million enterprise agreement may justify different risk allocations.
Agreeing to Liability Without Checking Insurance
The contractual risk should be considered against actual coverage.
Focusing Only on the Dollar Cap
Damage exclusions, carve-outs, indemnities and remedies may be just as important as the headline number.
What Should a SaaS Company Consider When Negotiating a Liability Cap?
Before negotiating, a technology company should understand its preferred position.
That may include identifying:
the preferred general liability cap;
whether a minimum cap is necessary during the first contract year;
which damages should be excluded;
whether any risks justify a higher cap;
which liabilities the company will not accept on an unlimited basis;
how indemnification interacts with the cap;
how the cap applies across SOWs and order forms;
how SLA remedies interact with damages;
what insurance is available; and
who within the company can approve deviations.
This is particularly valuable for companies negotiating enterprise agreements repeatedly.
Instead of deciding the company's risk tolerance from scratch during every customer negotiation, management and legal counsel can develop defined contracting positions and escalation thresholds.
For companies managing frequent contract negotiations, ongoing legal support can also help maintain consistency across customer agreements.
When Should a SaaS Company Have a Liability Clause Reviewed by an IT Lawyer?
An IT lawyer, SaaS lawyer or software contract lawyer can assist where the liability provisions are material to the transaction or difficult to assess in isolation.
Legal review may be particularly useful where:
the customer is requesting unlimited liability;
multiple carve-outs apply;
a data or cybersecurity supercap is proposed;
the agreement contains broad indemnification;
the company is signing customer paper;
several SOWs will operate under one MSA;
the contract contains significant SLA remedies;
the agreement involves sensitive data;
the customer proposes substantial security obligations;
the liability language differs from the company's standard position; or
the company cannot readily determine its maximum exposure.
A good IT contract review should do more than identify that a clause is "market" or "not market."
The more useful question is whether the risk allocation makes sense for the particular company and transaction.
SaaS and IT Contract Drafting and Review
Delta Law advises SaaS, software and technology companies on the drafting, review and negotiation of commercial contracts.
Our software and IT contract services include:
software contract review;
IT contract review;
Master Services Agreement drafting and negotiation;
Statements of Work;
software licensing agreements;
Service Level Agreements;
customer and vendor technology agreements;
limitation of liability negotiations;
indemnification provisions; and
SaaS and IT contract modernization.
We work with businesses to understand not only what a liability clause says, but how it interacts with the economics of the transaction, the company's operational obligations and the broader contract structure.
Looking for an IT Lawyer to Review a SaaS or Software Contract?
If your company is preparing, reviewing or negotiating a SaaS, software or IT agreement, understanding the limitation of liability provisions is an important part of assessing the overall contractual risk. Delta Law assists technology companies with IT contract drafting, SaaS agreement review, software contract negotiation and contract modernization.
Frequently Asked Questions About Limitation of Liability in SaaS Agreements
What is a limitation of liability clause in a SaaS agreement?
A limitation of liability clause establishes contractual limits on the amount or types of damages that may be recovered if a party breaches the agreement or another covered claim arises.
What is a liability cap?
A liability cap establishes a maximum monetary amount that may be recoverable for claims covered by the limitation. The cap may be based on fees paid under the contract, a fixed amount or another negotiated formula.
What is a supercap in a SaaS agreement?
A supercap is a higher liability limit that applies to specified categories of claims while the ordinary liability cap continues to apply to other claims. For example, the parties may negotiate a separate cap for certain security, confidentiality or intellectual property claims.
What does uncapped liability mean?
Uncapped liability means the claim is not subject to the contractual monetary limitation. Technology companies should carefully identify which obligations, if any, are excluded from the liability cap.
Are indemnification obligations subject to the liability cap?
It depends on the agreement. Some contracts expressly subject indemnification to the general cap. Others apply a separate cap or exclude indemnification obligations from the limitation entirely. The provisions need to be read together.
What is a common liability cap in a SaaS agreement?
SaaS agreements frequently calculate liability by reference to fees paid or payable during a specified period, but there is no universal cap appropriate for every transaction. The appropriate structure depends on factors including contract value, risk, bargaining power and the services being provided.
Should data breach liability be unlimited?
There is no universal answer. The appropriate allocation depends on factors such as the data involved, contractual security obligations, insurance coverage, the nature of the service and the parties' respective risks. Alternatives to unlimited liability can include separate or higher caps for specified data and security claims.
Can an IT lawyer review only the limitation of liability clause?
A lawyer can advise on a particular provision, but limitation of liability should generally be considered together with indemnification, warranties, security obligations, SLA remedies and other provisions that may create or modify liability.
Can a software contract lawyer negotiate a customer's MSA?
Yes. Technology companies frequently receive MSAs and procurement agreements from enterprise customers. Legal counsel can review the proposed agreement, identify contractual exposure and assist with negotiating revisions.



