User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.
MCM-65 — Liability Caps, Indemnification & Insurance
Bounded, insured financial exposure, including security-tool-specific liability language.
MCM-65 — Liability Caps, Indemnification & Insurance
← Back to Legal & Compliance Readiness overview
As Legal Counsel,
I want defined liability caps, indemnification terms, and confirmed cyber liability / technology errors & omissions insurance,
so that MCM's financial exposure from a customer claim — including one arising from a security-tool failure — is bounded and insured before any customer deployment.
Acceptance Criteria
- The standard contract defines a liability cap (e.g., tied to fees paid) with carve-outs clearly enumerated — gross negligence, IP infringement, and confidentiality breach at minimum.
- IP indemnification is included, covering claims that the platform — including any third-party or open-source component identified in the SBOM (see MCM-62) — infringes a third party's IP.
- Security-tool-specific liability language is reviewed by Legal Counsel: exposure from a missed finding (e.g., an undetected misconfiguration) contributing to a customer security incident is addressed with an explicit exclusion or cap, not left silent.
- Cyber liability and technology errors & omissions insurance policies are active, with coverage limits reviewed against the liability caps offered in customer contracts.
- Insurance certificates are available to provide to a customer's procurement or vendor-risk team on request.
Technical Design
The security-tool exclusion language has to reconcile with what the platform actually claims to do: governance and secops findings are advisory until a human applies a remediation (see MCM-60), and the indemnification carve-out should reflect that fact rather than assume guaranteed detection.