ConceptDiscovery layer

Liability Ceiling

Liability Ceiling is the maximum exposure an agency accepts when it sells security as an outcome rather than as a process.

By InnovaAI ResearchPublished Updated

What is Liability Ceiling?

Absolute security promise → unbounded agency liability

Process-based scope keeps liability bounded; outcome guarantees push it toward the breach total

Liability Ceiling is the maximum exposure an agency accepts when it sells security as an outcome rather than as a process. Every retainer that promises "we will keep you secure" converts an evolving attack surface into a contractual obligation the agency cannot fully control. The framework asks one question before signing: what is the worst-case dollar figure if this control fails, and who pays it? Agencies that sell detection, monitoring, and documented response steps cap their exposure at labor and tooling cost. Agencies that sell guarantees inherit the breach. A documented case from September 2026 shows a vibe-coded client app with exposed API keys generating a $4,000+ unauthorized usage bill, small enough to absorb but proof that the failure mode is financial, not theoretical. Set the ceiling in the statement of work: name the controls in scope, the review cadence, and the response time, then price the retainer against that scope instead of against an outcome you cannot underwrite.

security-tools