MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-65 — Liability Caps, Indemnification & Insurance

Bounded, insured financial exposure, including security-tool-specific liability language.

MCM-65 — Liability Caps, Indemnification & Insurance

← Back to Legal & Compliance Readiness overview

As Legal Counsel,
I want defined liability caps, indemnification terms, and confirmed cyber liability / technology errors & omissions insurance,
so that MCM's financial exposure from a customer claim — including one arising from a security-tool failure — is bounded and insured before any customer deployment.

Acceptance Criteria

  • The standard contract defines a liability cap (e.g., tied to fees paid) with carve-outs clearly enumerated — gross negligence, IP infringement, and confidentiality breach at minimum.
  • IP indemnification is included, covering claims that the platform — including any third-party or open-source component identified in the SBOM (see MCM-62) — infringes a third party's IP.
  • Security-tool-specific liability language is reviewed by Legal Counsel: exposure from a missed finding (e.g., an undetected misconfiguration) contributing to a customer security incident is addressed with an explicit exclusion or cap, not left silent.
  • Cyber liability and technology errors & omissions insurance policies are active, with coverage limits reviewed against the liability caps offered in customer contracts.
  • Insurance certificates are available to provide to a customer's procurement or vendor-risk team on request.

Technical Design

The security-tool exclusion language has to reconcile with what the platform actually claims to do: governance and secops findings are advisory until a human applies a remediation (see MCM-60), and the indemnification carve-out should reflect that fact rather than assume guaranteed detection.

On this page