Contract Risk Analysis
Software Development Services Agreement — SaaS Platform Build
About this sample. This is one example of what a successful Resolvix Contract Risk Analysis looks like. Your engagement will reflect your specific agreement, industry, and priorities — the structure, emphasis, and findings will vary. What stays consistent: every material clause reviewed, every high risk flagged with proposed redline language, and a clear negotiation playbook before you sign. All company names, figures, and clause language in this sample are illustrative.
Executive Summary
Overall Risk Rating
Top 3 risks:
- IP ownership is ambiguous. Section 8.2 grants the vendor a perpetual license to the work product "for portfolio and derivative use" — which could allow them to reuse your codebase for competitors.
- Liability cap is set at fees paid in the prior 30 days — on a project with a $120K total fee, this could mean your recovery is capped at $10K if the vendor delivers unusable work in month 3.
- No acceptance testing period. The contract deems deliverables "accepted" after 5 business days of silence — with no defined criteria for what constitutes acceptance.
The IP and liability clauses are the non-negotiables. Everything else on this list is worth pushing on, but the vendor likely won't walk away over IP cleanup — this language appears to be boilerplate that agencies use with clients who don't push back.
1. Clause-by-Clause Risk Register
| Clause | What It Says (Plain Language) | Risk | Priority |
|---|---|---|---|
| §3.1 — Payment Terms | 50% upfront, 50% on final delivery. No milestone payments. | Medium | Should |
| §4.3 — Change Orders | Any scope change requires a written change order. Vendor can pause work if a change order is disputed. | Low | Nice |
| §5.1 — Acceptance | Deliverables deemed accepted after 5 business days of silence. No defined acceptance criteria. | High | Must |
| §6.2 — Warranties | Vendor warrants work will conform to specifications for 30 days post-delivery. Silent on latent defects. | Medium | Should |
| §7.1 — Liability Cap | Vendor's total liability capped at fees paid in the prior 30 days. | Critical | Must |
| §7.3 — Consequential Damages | Vendor not liable for lost revenue, lost data, or indirect damages. | High | Must |
| §8.1 — IP Ownership | All custom work is work-for-hire; client owns it on final payment. | Low | — |
| §8.2 — Vendor License | Vendor retains perpetual license to work product for "portfolio and derivative use." | Critical | Must |
| §9.1 — Confidentiality | Standard mutual NDA, 2-year term, standard exclusions. | Low | — |
| §10.2 — Termination for Convenience | Either party can terminate with 30 days notice. Client pays for all work completed to date. | Medium | Should |
| §11.1 — Governing Law | Delaware law; disputes resolved by binding arbitration in Wilmington, DE. | Low | Nice |
2. High-Risk Clauses — Deep Dive
§8.2 — Vendor Portfolio License (Critical)
Exact language: "Notwithstanding the work-for-hire assignment in §8.1, Client hereby grants Vendor a perpetual, royalty-free, non-exclusive license to use, display, and create derivative works from the Work Product for Vendor's portfolio, marketing, and internal development purposes."
Why this is critical: "Derivative works" is the danger phrase. This clause allows the vendor to take the architecture, UI patterns, and logic you paid to build and use them as the foundation for work they do for your competitors. "Portfolio" is fine; "derivative works" is not.
Fallback if they resist: Add "provided that Vendor shall not display or license any portion of the Work Product to any company that competes with Client in [define your market] without Client's prior written consent." This limits the damage without requiring a full deletion of the clause.
§7.1 — Liability Cap (Critical)
Exact language: "Vendor's aggregate liability to Client shall not exceed the total fees paid by Client to Vendor in the thirty (30) days immediately preceding the event giving rise to the claim."
Why this is critical: On a $120K project paid as $60K upfront + $60K on delivery, if a catastrophic failure occurs in month 3 (after the upfront payment is 90+ days ago), your recovery cap could be $0–$10K. This cap needs to be the total contract value, not a 30-day slice.
Fallback: Accept "the total fees paid by Client in the six (6) months preceding the claim" — still limited but protects you on a $120K project where you've paid $60K+ within 6 months.
§5.1 — Silent Acceptance (High)
Exact language: "Each Deliverable shall be deemed accepted by Client upon the earlier of: (a) Client's written approval; or (b) five (5) Business Days following Vendor's written notice of delivery, if Client has not provided written objection."
Why this is high risk: There are no acceptance criteria defined anywhere in the contract. "Acceptance" triggered by silence means you could be contractually bound to have accepted work that doesn't function correctly, simply because you were too busy to respond in 5 days.
The absence of defined acceptance criteria is as dangerous as the silent-acceptance timer. Attach a clear specification exhibit and a defect severity matrix before signing — this protects you regardless of what happens to the clause language.
3. Missing Protections
| Missing Clause | Why It Matters | What to Request |
|---|---|---|
| Key person clause | No guarantee that the team members you evaluated will actually work on your project. | Require written approval for any substitution of named personnel; right to terminate if key person leaves. |
| Source code escrow / delivery | Contract requires source code delivery on final payment, but no escrow if vendor becomes insolvent mid-project. | Add milestone-based source code commits to a shared repo; or source code escrow with release triggers. |
| Third-party component disclosure | No obligation to disclose open-source or third-party libraries used — creates potential license compliance risk. | Require a bill of materials (BOM) for all third-party components, with license types disclosed. |
| Non-solicitation (employees) | Nothing prevents vendor from hiring your team members who interact with them during the project. | Add a 12-month mutual non-solicitation of employees clause. |
4. Negotiation Playbook
Must-Have Changes (Non-negotiable)
- Strip "derivative works" from §8.2. Use the redline above. This is the most important change.
- Raise the liability cap to total contract value (§7.1). The 30-day cap is indefensible on a $120K engagement.
- Add acceptance criteria to §5.1. Attach a specification exhibit before signing; silence acceptance is only safe with defined criteria.
Should-Have Changes
- Add milestone payments (3–4 milestones vs. 50/50) to align payment with progress.
- Extend warranty period from 30 to 90 days, covering latent defects.
- Add key person clause for the lead architect and PM.
Nice-to-Have
- Change arbitration venue from Wilmington, DE to your local jurisdiction.
- Add third-party component BOM requirement.
- Add mutual non-solicitation of employees.
Trade-Off Strategy
If the vendor pushes back on the liability cap, offer to meet in the middle: cap at 6 months of fees rather than 30 days. In exchange, you can accept their preferred arbitration venue. The IP clause is the one item not worth trading — if they insist on keeping "derivative works," that's a walk-away signal.
5. Action Steps
| # | Action | Owner | Time |
|---|---|---|---|
| 1 | Send redlines for §8.2, §7.1, and §5.1 to vendor's legal contact | You / Your attorney | This week |
| 2 | Draft specification exhibit (Exhibit A) and defect severity matrix (Exhibit B) to attach to §5.1 fix | You + Vendor PM | Before signing |
| 3 | Request milestone payment schedule (suggest: 25% signing, 25% design complete, 25% development complete, 25% acceptance) | You | With redlines |
| 4 | Identify and name key personnel in an exhibit; add to contract | Both parties | Before signing |
| 5 | If vendor accepts all must-haves, execute agreement | You | Post-negotiation |
Every clause reviewed. Every high risk flagged with proposed language. A negotiation playbook you can execute without a law degree. This is what a Resolvix Contract Risk Analysis delivers — every time.