All prompts
Draft/Featured
Draft a clause in three negotiating positions
Gives you the same provision at three points on the negotiation curve (your ask, the realistic landing zone, and their paper) with the specific levers that separate them and what each one costs.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
Levers this clause turns on
1. Cap basis (fees paid vs. fees payable) and multiple (3 / 12 / 24 months)
2. Which obligations sit outside the cap
3. Whether a data incident gets a super-cap or unlimited treatment
4. Whether the consequential-damages waiver is mutual
5. Whether the cap aggregates across the term or resets annually
Version A: Vendor's ask
"Except as provided in Section 11.3, each party's total aggregate liability arising out of or relating to this Agreement, whether in contract, tort, or otherwise, shall not exceed the Fees paid by Customer to Vendor in the twelve (12) months preceding the event giving rise to the claim. Neither party shall be liable for indirect, incidental, consequential, special, exemplary, or punitive damages, including lost profits, lost revenue, or lost data, even if advised of the possibility. Section 11.3 (Exclusions): the foregoing limits do not apply to (a) Customer's payment obligations, (b) either party's breach of Section 9 (Confidentiality), (c) Vendor's indemnity under Section 12.3 (IP Infringement), or (d) either party's fraud or willful misconduct."
*Concession:* You take unlimited exposure on confidentiality, IP indemnity, and willful misconduct in exchange for a clean 12-month cap and a mutual consequential waiver that keeps lost-profits claims out entirely.
Version B: Likely landing zone
Same structure, with a data-incident super-cap: liability for breach of Section 7 (Security) capped at the greater of $5,000,000 or three times (3x) trailing twelve-month Fees.
*Concession:* You accept a number roughly at your cyber policy limit on security incidents to keep everything else inside the general cap.
Version C: Customer's paper
Unlimited liability for any Security Incident, cap measured on Fees payable over the full Term rather than Fees paid, and a one-way consequential waiver running only in Customer's favor.
*Concession:* You close this quarter and inherit uninsurable tail risk on a breach.
Fallback ladder. (1) Move the cap from 12 to 18 months of fees: cheap, and it looks responsive. (2) Add gross negligence to the carve-outs [UNVERIFIED - under New York law a gross-negligence carve-out is generally required for the cap to be enforceable at all; confirm before treating this as a concession]. (3) Super-cap data incidents at policy limits. (4) Never: cap measured on Fees payable, and never a one-way waiver.
Assumptions I made. "Fees" and "Security Incident" are already defined in the agreement [verify]. Your $5M cyber policy has no sublimit for regulatory fines or PCI assessments [verify - this is the number that decides whether Version B is real]. The mutual consequential-damages waiver is settled [safe - you said so].
Where this is weakest. "Arising out of or relating to" in Version A is broad enough that a court could read the cap to reach the indemnity in Section 12.3 despite the exclusion. Add "Notwithstanding Section 11.1" at the head of 11.3 to close it.
What only you can decide. Where to open. Version A anchors at a clean 12-month cap with no security super-cap and keeps the $5M concession in your pocket for the second turn, but this customer's procurement team never accepts a first redline, so plan on two extra weeks and a reputation for being hard to paper on a $1.2M ARR deal. Version B closes in one turn and gives up the anchor permanently; you will not get the general cap back down once the super-cap is on the page. The second call is a balance-sheet call rather than a legal one: whether $5,000,000 is the right super-cap number at all. It matches your stated cyber limit, which is what makes it defensible in the room, but if that policy carries a sublimit for regulatory fines or PCI assessments, the number you are agreeing to is not the number your insurance actually reaches, and the gap is yours.
What would make this materially better. (1) Your cyber policy declarations page with the sublimits and exclusions: it decides whether Version B is a real fallback or a bluff. (2) The customer's standard limitation-of-liability clause, so Version C is their actual paper instead of my reconstruction of it. (3) Section 12 (Indemnification) as currently drafted, because the exclusion in 11.3 only holds if the indemnity's operative language lines up with it. (4) The order-of-precedence clause, if an order form or a DPA sits above the MSA and carries liability language of its own.
Why this prompt is built the way it is
## Framework
1. **Levers before language.** Name the three to six levers the clause actually turns on before drafting a word. Everything else is style.
2. **Three versions that genuinely differ,** each moving the levers rather than the adjectives, each with one sentence naming what it concedes. "More balanced" is not a concession.
3. **Test enforceability against the governing law, then check the seams.** Caps, indemnities for one's own negligence, liquidated damages, and gross-negligence carve-outs fail differently in different states, and a clause that does not line up with the insurance, indemnity, and precedence provisions does not work at all.
4. **Give the ladder.** The order in which levers get conceded, cheapest first, so the negotiation has a plan instead of a reflex.