Did I Just Accept Unlimited Liability to Close My Biggest Enterprise Deal?
The Redline Nobody Flagged
I just landed the enterprise logo my board has been asking about for two quarters. Legal review felt like the last thing standing between me and a signed contract.
The redlines came back mostly clean. One section barely changed: indemnification (my promise to cover the other side’s losses in specific situations).
Nobody flagged that the indemnity language was never tied back to my liability cap. That gap is how a single customer contract turns into a company-ending exposure.
Plain-English Breakdown
Two clauses do very different jobs in this contract, and enterprise buyers know it even when my team doesn’t.
Limitation of Liability vs. Indemnification
- The limitation of liability clause caps total damages, usually at 12 months of fees paid.
- The indemnification clause is a separate promise to cover the other party’s losses from specific claims, like IP infringement or a data breach.
- If indemnification isn’t explicitly written to sit “subject to” the cap, it isn’t covered by that cap at all.
The Carve-Out That Creates Unlimited Exposure
Enterprise paper routinely carves indemnification out of the liability cap on purpose, most often for IP infringement claims against my product, data breach or security incident claims, and confidentiality or data misuse claims.
Once a claim type sits outside the cap, there’s no dollar ceiling on what I owe.
Why This Deal Is Bigger Than It Looks
A small pilot contract with uncapped indemnity is a mistake I can survive. A flagship enterprise contract with the same gap is a different animal entirely. It’s the deal my investors are watching, the one my next funding round’s diligence team will scrutinize line by line, and the one most likely to get triggered, because it runs on real customer data at scale.
Insurance Does Not Automatically Match the Exposure
Most startups carry an E&O or cyber policy sized to their revenue, not to their biggest customer’s risk tolerance. A breach or infringement claim tied to an uncapped indemnity can exceed my coverage by millions, and I personally, not just the company, may be answering to my board about why.
Picture a company carrying a $2 million E&O policy that signed an uncapped indemnity clause to close its largest enterprise contract to date. A data breach triggered a claim under that clause for $8 million in actual damages, and the $6 million gap between the policy limit and the claim came directly out of the company’s own cash.
Common Founder Mistakes
- Reading the Liability Cap as the Whole Story. Founders sign off once they see a liability cap number and assume it protects them everywhere in the contract. It only protects what’s actually subject to it. If indemnification isn’t cross-referenced to the cap, the cap is decorative for those claims.
- Accepting “Any and All Claims” Language. Broad indemnity language is a trap. A clause promising to cover “any and all claims, damages, and losses arising from or related to” is far broader than one limited to “third-party claims that the product infringes a valid patent,” and founders often let it pass because it reads like standard boilerplate rather than a real financial commitment.
- Not Checking Indemnity Against Actual Insurance Limits. Legal review and insurance review happen in separate silos at most startups. Nobody asks whether the policy’s coverage limit actually covers the worst-case indemnity claim in the contract I’m about to sign.
10-Minute Self-Check
Before I sign this enterprise contract, work through this:
- Is the indemnification section explicitly made “subject to” the limitation of liability cap?
- Which specific claim types are carved out of the cap, and why?
- Is the IP infringement indemnity limited to specific, defined claims rather than “any and all”?
- Does my current insurance coverage actually match the size of this customer’s exposure?
- Has my board or investor group seen this specific clause, not just the deal summary?
- Do I have a mutual indemnification structure, or is the obligation one-sided?
If I can’t answer yes to all of these, I’m not ready to sign this contract yet.
Bottom Line
An enterprise contract that grows my revenue can also grow my risk past what my cap, my insurance, or my cash reserves can absorb. The size of the logo doesn’t change the math. Only the language does.
Ready to Get Your Enterprise Contract Reviewed Before You Sign?
Schedule a free 30-minute call with our team to discuss your needs and concerns.
Book here: https://calendly.com/primumlaw/30min
Sources Used
- 2025 Cost of a Data Breach Report, IBM, https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
- Growing Data Breach Disputes Require Sharp Eye on Contract Terms, Bloomberg Law, https://news.bloomberglaw.com/us-law-week/growing-data-breach-disputes-require-sharp-eye-on-contract-terms