FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

App developer insurance: the cover a UK mobile app business actually needs

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: Most UK app developers build their programme around technology professional indemnity (tech PI/E&O), which responds if a coding error, missed brief or faulty release causes a client financial loss, plus cyber cover for the data and systems you handle. Add public liability for client-site work, and employers' liability if you hire anyone. Clients usually require these by contract.

Whether you build native iOS and Android apps for agency clients, ship a subscription product of your own, or take on fixed-scope contract work, you sit on a specific kind of risk. You are trusted with someone else's idea, their users' data, and often their revenue, and you are judged on whether the thing you shipped works. When a build slips, a payment flow breaks on launch day, or a data field ends up somewhere it shouldn't, the money at stake is rarely yours alone. That is exactly the gap insurance is designed to fill, and this guide walks through the covers that matter for an app development business and, more importantly, why each one earns its place.

What are the real risks of building mobile apps for clients?

App development is a professional service with a technical product bolted on, and the risks come from both halves. On the professional side, you are giving advice and delivering work to a specification. If your code contains a defect, if an integration you built mishandles transactions, if you miss a requirement the client insists was agreed, or if a release introduces a bug that takes their app offline, the client's loss is financial: lost sales, emergency remediation, a delayed launch, reputational damage they blame on you. They may argue you were negligent and seek to recover that from your business.

On the technical side, you routinely touch personal data and connect to systems: user sign-ups, payment tokens, location data, health or fitness metrics, push notification services, third-party APIs and the client's back end. That exposure is a magnet for cyber incidents, from a compromised developer account to malware in a dependency to a misconfigured cloud bucket. And because you often work on client premises or attend on-site workshops, there is an old-fashioned physical risk too. Understanding which cover answers which scenario is the whole game, so let's take them in turn.

Why is technology professional indemnity the core cover for a developer?

Technology professional indemnity, often called tech PI or technology errors & omissions (tech E&O), is the same product under two names, E&O simply being the term the US market uses. It is the cover that responds when a client alleges your work, your advice or your software caused them a financial loss, and it funds both your legal defence and any damages or settlement. For an app developer this is not a nice-to-have sitting at the edge of the programme; it is the centre of it.

Picture the everyday claims. A retailer's app you built double-charges customers during a sale and they demand you cover the refunds and the fix. An agency says your delivery was late and defective, missed their client's launch window, and they withhold payment while claiming damages. A start-up alleges the API layer you wrote lost order data and cost them a funding milestone. Whether or not the allegation is ultimately fair, defending it costs money, and tech PI is what stands between that dispute and your own bank balance. Good technology PI wording is written with software work in mind, so it contemplates things like breach of contract, negligent advice, and problems arising from the code itself, rather than the narrower professional-services template designed for accountants or surveyors.

It is worth being precise about status here. Professional indemnity is not a statutory legal requirement for IT firms; there is no Act that forces an app developer to hold it. In practice it is very close to unavoidable because it is a contractual requirement: agencies, enterprise clients and public-sector buyers routinely make a stated PI limit a condition of the contract, and no certificate means no work. You can read more in our guide to technology professional indemnity insurance.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Winning a contract that names a specific PI or cyber limit? Send us the wording and we'll make sure your cover matches what the client actually requires.

Get a tailored quote →

Do app developers need cyber insurance as well as PI?

Yes, and the two are not interchangeable. Tech PI answers claims about the quality of your work; cyber insurance answers what happens when your own systems, or the data you are custodian of, are attacked or breached. As an app developer you hold source code, signing keys, client credentials, staging environments and, very often, real user data. A compromised laptop, a phished account or a supply-chain attack through a package you depend on can hand an attacker the keys to all of it.

The value of cyber cover is mostly in the response, not just the cheque. A strong policy gives you immediate access to incident response specialists, IT forensics, legal support and breach notification help at the moment you need them, when the priority is containing the incident and working out who has to be told. It can also fund business interruption if you are locked out of your own tooling and cannot bill, and third-party liability if a client or their users bring a claim because data you held was exposed.

One point to be careful about, because it is widely misunderstood: whether a UK regulatory fine under UK GDPR or the Data Protection Act 2018 can be paid by insurance is legally uncertain, and such fines are frequently excluded or restricted. Do not buy cyber cover in the belief it will settle an Information Commissioner's Office (ICO) penalty for you, because it may not be insurable at all. Think of cyber as funding breach response, business interruption and third-party liability, and treat any question of fines as separate. Our explainer on cyber insurance goes deeper, and if you want to see how the two covers divide up responsibility, professional indemnity vs cyber insurance for tech companies lays it out side by side.

Should I buy a combined technology policy instead of separate covers?

For most app development businesses, yes, and it is usually the neatest way to buy. Because tech PI and cyber overlap at the edges, and because a data incident can easily trigger both a service complaint and a breach response, many insurers bundle them into a single combined technology policy. That arrangement tends to reduce gaps and arguments about which section responds, and it lets you add public liability and other covers under one schedule and one renewal date. It also usually makes the admin of proving cover to clients simpler, since you have one certificate to point to.

A combined policy is not automatically the right answer for everyone, and the sensible limits for each section depend on your contracts and the size of the clients you serve. Illustrative options run from around £1m up to £5m or £10m, but the right figure is the one your contracts demand and your exposure justifies, not a number picked off a shelf. This is where a conversation beats a checkout, so it is worth talking it through with an Apex technology specialist who can size it against the work you actually do. Our overview of a combined technology insurance policy covering tech PI and cyber explains how the sections fit together.

What about public liability and working on client sites?

Public liability covers injury to other people or damage to their property arising from your business activities, and it becomes relevant the moment your work leaves your own screen. If you attend a client's office for discovery workshops, run on-site testing, present at their premises, or have clients visit you, public liability is the cover that responds if someone is hurt or something is damaged in connection with your business. It is a small, inexpensive part of a developer's programme, but clients frequently ask to see it before they let you through the door, and site-access agreements sometimes state a required limit.

If you are a solo developer working almost entirely from home with no client visits, your exposure here is genuinely low, and it is fair to weigh whether you need it as a standalone line. But if there is any face-to-face element to your work, it is usually included at modest cost within a combined technology or business package, and it removes a common contractual sticking point.

Do I need employers' liability if I take on staff or contractors?

This one is a legal duty, not a judgement call. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are generally required to hold employers' liability insurance, with only narrow exceptions such as certain family-only or genuinely single-director companies. It covers claims from employees who are injured or fall ill because of the work they do for you. The moment you hire your first developer, tester or admin, this stops being optional.

The grey area for app businesses is the freelancer. Whether someone you engage counts as an employee for these purposes depends on the working arrangement rather than the job title on the invoice, and labour-only subcontractors are often treated as employees for insurance. If you regularly bring in contract developers to hit deadlines, it is worth checking your position rather than assuming a contractor sits outside the requirement. If you are unsure, tell us how you engage your people and we will help you work out what applies.

When do media and intellectual property risks come into play?

App work carries content and IP exposure that pure back-office software does not always share. You handle icons, imagery, copy, fonts, music, brand assets and third-party libraries, and you make decisions about how they are used. If a competitor alleges your app infringes their intellectual property, or a client says your build used assets or code you had no licence to, that is a media and IP liability question. Many technology PI and combined policies include an element of intellectual property infringement and defamation cover, but the scope varies a great deal between insurers, so it should never be assumed.

This matters most if you publish your own-brand products, reuse code and design assets across clients, or build apps with a strong content or social element. If that describes you, it is worth checking the IP wording specifically rather than trusting that a standard policy has you covered. A broker who reads the exclusions for a living will spot where a policy quietly narrows this cover.

A quick word on IR35 — because insurance does not touch it

If you contract through a limited company, you will have run into IR35, and it is worth being clear about what it is and is not. IR35, the off-payroll working rules, is a tax matter about your employment status for tax on a given engagement. Holding insurance does not change, improve or determine your IR35 status, and no policy can make an inside-IR35 engagement outside, whatever anyone implies. Insurance and IR35 are simply different questions. For your actual status and how to handle it, speak to a qualified accountant or tax adviser; for the cover that protects the work itself, that is where a broker comes in. If you work independently, our IT contractor insurance guide is a good next read.

What does a sensible programme look like for an app developer?

Pulling it together, a typical app development business builds its cover in a clear order of priority:

The right limits and the right combination depend entirely on the contracts you sign and the work you do, which is why a five-minute conversation is worth more than a generic quote. For the wider picture of how these covers fit an IT business, see what insurance an IT company needs.

Apex arranges technology insurance for app developers, contractors and product businesses across the UK. Tell us how you build and who for, and we'll shape cover that fits the contracts you're chasing.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →