The indemnity clause in a SaaS agreement under the United States law

Indemnity clause guidance for US SaaS agreements: standard allocation, IP carve-outs, negotiation tactics, and enforceability under state contract law.

Standard Position

In US SaaS agreements, indemnity clauses protect each party from third-party claims arising from the other party's breach, negligence, or infringement. The vendor typically indemnifies the customer against IP infringement claims related to the software itself, while the customer indemnifies the vendor for claims arising from customer data, customer use cases, or customer breach of the terms. This allocation reflects the principle that each party controls its own domain of risk.

Vendors customarily exclude indemnification obligations for claims arising from the customer's modification of the software, combination with non-vendor products, use outside documented parameters, or compliance with customer specifications. Customers typically carve out the vendor's indemnity for claims related to the vendor's own negligence or willful misconduct, and sometimes for claims based on the vendor's use of customer data beyond the scope authorized.

Legal Basis

US law does not mandate indemnity clauses in SaaS agreements, but the principle is rooted in contract law: parties may allocate foreseeable risks by mutual consent. The Uniform Commercial Code (UCC) Article 2 applies to sales of goods and does not directly govern SaaS (which involves services and access rights), but state courts sometimes apply UCC principles by analogy to digital products and hybrid SaaS models. State contract law governs the enforceability of indemnity clauses, including requirements of consideration, clarity, and reasonableness.

A critical constraint is public policy: many states limit indemnity for a party's own gross negligence or willful misconduct (sometimes called "anti-indemnity" statutes), particularly in construction, transportation, and regulated industries. While not universal in commercial contracts, courts construe indemnity clauses strictly against the indemnitee, meaning ambiguities favor the indemnifying party. Additionally, an indemnity clause does not survive if it requires one party to indemnify the other for breach of the indemnifying party's own contractual obligations (that would be penalty-like and disfavored).

Drafting and Negotiation

The vendor's indemnity for IP infringement is the most heavily negotiated element. Vendors should insist on narrow triggers: the claim must allege that the unmodified software infringes a third party's patent, copyright, or trade secret under US law. Vendors should carve out claims based on combinations, modifications, open-source components disclosed in writing, or use inconsistent with documentation. If the customer modifies the software, the vendor's indemnity should not apply unless the modification was made by the vendor.

Customers should negotiate a cap on the vendor's indemnity obligation and a defined procedure for the vendor to control defense and settlement. Some customers demand an expanded indemnity covering claims that the software violates non-US IP rights, though vendors typically limit this to major jurisdictions (EU, Canada, Japan) at higher cost.

The customer indemnity is often less contentious but should be carefully scoped: claims arising from customer data, customer systems, unauthorized use, or breach of the acceptable-use policy. The customer should not indemnify the vendor for the vendor's own infringement or data misuse. Mutual carve-outs for each party's gross negligence and willful misconduct are standard.

Both parties should require notice, control of defense, and cooperation conditions. A common pitfall is silent on whether indemnity survives termination; best practice is to state it survives for claims asserted within a defined tail period (typically 12 to 24 months post-termination).

Common Pitfalls

Vendors often neglect to carve out third-party open-source or licensed components, creating unexpected indemnity exposure. Customers frequently omit a notice requirement, losing the opportunity to mitigate early. Both parties may draft indemnity without a governing law statement specific to the indemnified claim (e.g., "claims under US law only"), leading to disputes over scope. Finally, failure to tie indemnity to the limitation-of-liability clause can create tension: if indemnity is uncapped but direct damages are capped, the indemnity becomes the true remedy, defeating negotiated risk allocation.

Sample language

Vendor shall indemnify Customer from third-party claims that the unmodified Software infringes any US patent, copyright, or trade secret, provided Customer (i) promptly notifies Vendor in writing, (ii) grants Vendor sole control of defense and settlement, and (iii) provides reasonable cooperation. Vendor shall have no obligation if the claim arises from Customer modification, combination with non-Vendor products, use outside Documentation, or compliance with Customer specifications. This indemnity does not apply to claims arising from Vendor's gross negligence or willful misconduct.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

Does US law require an indemnity clause in a SaaS agreement?
No. Indemnity clauses are contractual risk-allocation tools and not mandated by US law. However, they are market-standard in SaaS agreements and strongly recommended to allocate IP infringement risk, data breach risk, and breach-of-use claims. Absence of an indemnity clause may leave one party exposed to third-party claims without contractual recourse.
Can I indemnify the vendor for claims arising from the vendor's own negligence?
No, generally not in most US states. Courts construe indemnity clauses strictly against the indemnitee and disfavor provisions requiring indemnification for a party's own gross negligence or willful misconduct as against public policy. You should always carve out the vendor's own gross negligence and willful misconduct from the customer indemnity.
What should I do if the vendor refuses to indemnify for open-source software components?
This is common and reasonable: vendors typically require the customer to accept open-source license terms directly. You can negotiate a middle ground: the vendor discloses all open-source components in writing and indemnifies against claims arising from the vendor's breach of those license terms, but the customer accepts open-source licenses for the component itself. Alternatively, require the vendor to implement a code-scanning practice and disclose findings.
How long does the indemnity obligation last after the contract ends?
The contract should specify a tail period (typically 12 to 24 months post-termination) during which indemnification survives for third-party claims asserted within that window. Without an explicit survival clause, courts may imply that indemnity survives at least for claims based on breach or infringement occurring during the contract term, but the scope is ambiguous and litigation-prone.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira