Skills / Closing the deal / Security vendor contract norms

What limitation-of-liability can a security vendor accept when our failure could cause their breach?

Their lawyers were told your failure could be their breach. They are not wrong.

security-vendor-contract-norms

SKILL.md · 1,334 words

Verified Sept 2026

Download the folder
What your agent reads.
name
security-vendor-contract-norms
description
Contract terms for a seed-stage security vendor whose failure could cause the customer's breach: limitation of liability and the super-cap for data breach, indemnities, the consequential-damages waiver and its carve-outs, warranties that the product performs as documented rather than prevents breaches, the security addendum with notification windows and subprocessor lists, audit and escrow asks, most-favored pricing, termination for convenience, assignment on change of control, and why redlines track the buyer's urgency, not the paper. Use when a founder is negotiating a first enterprise agreement, is asked for unlimited liability, is stuck in procurement after the technical win, or is choosing a standard agreement to start from. Counsel drafts; this is what has decided the negotiation. Also written as the MSA, the DPA, the LoL clause, or the liability cap. Not for the questionnaire (security-questionnaires), SOC 2 (soc2-when-it-blocks-a-deal), or insurance (cyber-insurance-stack).
title
Security vendor contract norms
question
What limitation-of-liability can a security vendor accept when our failure could cause their breach?
subtitle
Their lawyers were told your failure could be their breach. They are not wrong.
summary
You set the liability cap by what your product touches and by your insurance limit, and you warrant that the product performs as documented, never that it prevents breaches. Redlines move with the buyer's urgency rather than the quality of your paper, so forecast to countersignature, decide in advance which blocking clauses you will trade, and never trade most-favored pricing.
group
close
verified
2026-09-09
order
56

996 / 1024 characters

This is the top of the SKILL.md file, exactly as it downloads. Your agent reads the description field to decide when to load this skill. The rest of this page is for you.

You are negotiating a contract with a buyer whose lawyers have been told that your failure could be their breach, and they are right. Counsel drafts the paper. What follows is what we have watched decide the negotiation, which is rarely the paper.

Contracting is a stage, not cleanup.

You will treat legal review and procurement as paperwork that follows the decision. They are a separate process with their own duration and their own ways of failing, and sales activity does not speed them up. Each gate has a different owner with no reason to hurry, and the clock runs regardless of what you do. Blend them into your late-stage pipeline and your forecast is wrong in exactly the periods you need it right. Report deals in procurement as their own line from your first board meeting, and forecast to countersignature, the buyer's authorized signature after yours. A deal rushed to close at the end of a period gets papered as a letter of intent, which turns urgency into a document that is not revenue.

Redlines track urgency, not paper.

You will invest in better paper and a friendlier standard agreement to reduce redlines, and the redlines will not care. In our portfolio the deals that closed with no redlines at all were the ones signed while the buyer was worried. Redlining depends on how much latitude the buyer's legal team feels it has to take its time. When the executive sponsor is genuinely worried, legal's leverage disappears and terms you were told were non-negotiable move. When the sponsor is merely interested, no drafting on your side speeds anything up. The blockers at the end of your largest deals are real, and they can be negotiated down, but only if you make the customer choose between the term and the timeline.

The cap is really about privilege.

The liability question sounds legal, and it is a question about what your product touches. An agent running inline with privileges inside the customer's environment is a different risk from a read-only dashboard, and the buyer's counsel knows it. Price the cap to how the product deploys. Set a general cap at the fees paid, and say whether that means the whole term or the prior twelve months, because a buyer reads it as the second and you will discover the difference in year three. Set a higher cap, a multiple of fees, for a data breach caused by your negligence. Accept carve-outs for confidentiality, intellectual property, and gross negligence, which every buyer insists on and every vendor should accept. Keep the mutual waiver of consequential damages, and expect the buyer to carve your data-breach cap, confidentiality, and indemnity obligations out of it. That carve-out is standard, and refusing it marks you as a vendor who has not done this before.

When counsel asks for unlimited liability, the honest answer is your insurance limit. That is the real number in the room, and it is the reason to buy the policy before the first enterprise contract rather than after the redline cycle it would have ended.

Warrant that it performs, never that it prevents.

Buyers ask you to warrant that the product prevents breaches. No security vendor can, and the ones that do are either lying or uninsured. Warrant that the product performs as documented, that you will fix material defects, that you hold the certifications you claim, and that you will give notice within a defined window. Nothing more. A security product is a control, not a guarantee, and the contract should say what the control does.

The buyer is underwriting your survival.

Every serious review asks what happens to the customer if you are acquired, shut down, or run out of money. That question is why source-code escrow and assignment clauses appear, and treating them only as clauses to trade misses what the buyer is afraid of. Cheap answers exist and they work: a written wind-down commitment, data export in a documented format, a termination-for-convenience right on their side, and your runway disclosed under NDA. Offer those before the escrow request arrives, because the escrow ask is usually satisfiable without escrow.

Know which clauses actually block.

The negotiation gets spent on the cap and the deal gets lost on something else. The clauses that have actually stalled our companies' deals are unlimited indemnity for third-party claims, audit rights over your source code, source code escrow, most-favored pricing, termination for convenience with a refund, and assignment on a change of control, which an acquirer reads before anything else in your data room. Decide before the negotiation which of those you will trade and for what. Escrow and audit rights can often be traded for a higher cap. Most-favored pricing cannot be traded for anything, because it follows you into every future deal.

The security addendum is engineering.

The security addendum reads as an appendix, and regulated buyers write your questionnaire answers into it. Notification windows, subprocessor lists, penetration test schedules, encryption standards, and the right to scan you are each real operational obligations with dates on them, and a breach of the addendum is a breach of the contract. Read it as an engineering commitment and staff it that way.

You are not going to sue this customer.

You are not going to sue your first customers, and they know it. Whatever the agreement says, a buyer who is unhappy stops paying and leaves, and the remedy you negotiated is a lawsuit you will never file against a logo you need on your website. That is the honest position at the first ten deals: the contract describes the relationship, it is not a lever you will pull.

So do not spend weeks on terms. You have no leverage — you are the unknown vendor and they are the reference — and the weeks cost more than any clause you would win. Hold the line only where a term could end the company, and concede the rest quickly. Conceding fast is worth something on its own: a buyer's counsel who finds you easy to work with says so to the next one.

Start from standard paper, and keep a log.

You ask whose paper first. Many enterprise buyers have an agreement they prefer to use, and the fastest deal is usually the one on paper their legal team already knows. Ask how they like to do deals before you send anything. If they have no preference, start from an open standard vendor agreement rather than bespoke paper, and make it friendly — a first contract that reads as though a large company wrote it gets marked up like one. Then change it clause by clause with counsel, and keep a log of every term you conceded and to whom. Most-favored clauses read that log. An acquirer's diligence reads that log. And your own next negotiation reads it, because the term you gave one buyer is the term the next one has heard about.

Working the question.

  1. Put deals in procurement on the forecast as their own line, and forecast to countersignature.
  2. Buy the liability and cyber policy before the first enterprise contract. The limit is your cap.
  3. Price the cap to how the product deploys: fees paid in general, a multiple for a breach caused by your negligence, the standard carve-outs, and a mutual waiver of consequential damages with the breach cap carved out of it.
  4. Warrant performance as documented, never prevention.
  5. Decide in advance which blocking clauses you will trade, and never trade most-favored pricing.
  6. Read the security addendum as an engineering commitment, and keep the concession log.

Working with an agent.

Give your agent the last security addendum a customer sent you. Ask it to rewrite the document as a list of engineering commitments, each with an owner and a date. Everything you signed is on that list, and someone on your team is now responsible for it.

Install the skill.

You are reading the skill itself — this page and the download are the same files. Unzip it into ~/.claude/skills/ (or a project’s .claude/skills/) and Claude Code loads it when the question comes up; so does any agent that reads Agent Skills.

mkdir -p ~/.claude/skills && cd ~/.claude/skills && curl -sLO https://techoperators.com/skills/security-vendor-contract-norms.zip && unzip -oq security-vendor-contract-norms.zip && rm security-vendor-contract-norms.zip

security-vendor-contract-norms/SKILL.md

No terminal? Download security-vendor-contract-norms.zip and drop into your assistant’s project files.

Kevin Skapinetz

Tell us what you see.

Whether you’re thinking about starting a company, building one in stealth, or raising a round: send Kevin or Dan what you see on LinkedIn, in your words.