FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

SaaS providers

Professional indemnity for SaaS companies

Professional indemnity and technology errors & omissions cover sits at the heart of any software-as-a-service business. Unlike a one-off software build, a SaaS provider sells a continuing, subscription-based service that many customers rely on at the same time — so when the platform underperforms, breaches its service-level agreement or mishandles data, the claims can arrive together. This page explains, in plain terms, what tech E&O does for a SaaS firm and where its defining exposures lie.

In short

Professional indemnity / technology errors & omissions insurance protects a SaaS provider against claims that its service caused a customer a financial loss — through a defect, an error, a missed service level or negligent advice — covering defence costs and the damages the business becomes legally liable to pay. The defining exposure for SaaS is not a single botched delivery but a continuing service many customers depend on at once: if the platform fails, degrades or drops data, multiple clients can claim together, and a single root cause can aggregate into one large loss. Because the service is sold under a subscription with a service-level agreement, what the contract promises shapes what can realistically be insured. Cover is almost always written on a claims-made basis, so the policy in force when a claim is made responds, and the Insurance Act 2015 duty of fair presentation applies when you buy and renew.

Why SaaS cover differs from one-off software development

Traditional software errors & omissions cover was built around project work: you design and deliver a system, hand it over, and the exposure crystallises around that deliverable. SaaS is structurally different. You are not selling a product once; you are selling a continuing service, hosted by you and consumed by many customers at the same time under rolling subscriptions.

That changes the risk in three ways. First, the relationship is ongoing — every day the service runs is a day it can underperform, so exposure is continuous rather than tied to a single sign-off. Second, many customers rely on the same platform simultaneously, so a defect is rarely contained to one client. Third, and most importantly for insurance, a single underlying failure — a faulty release, a configuration error, an outage — can trigger claims from a whole customer base at once. This is aggregation: many individual claims flowing from one root cause, potentially eroding a single policy limit together.

The table below sets out common SaaS exposures and the cover that typically responds.

SaaS exposureWhat typically responds
Software defect or coding error that causes a customer financial lossProfessional indemnity / tech E&O
Failure to meet a contractual service level, such as availability or performanceTech E&O, subject to how the SLA and liability cap are drafted
Negligent implementation, configuration or professional adviceProfessional indemnity / tech E&O
Outage causing customers’ business interruptionTech E&O for the third-party loss; your own lost income sits with cyber or business-interruption cover
Security breach of your platform and the response to itCyber insurance
Infringement of third-party intellectual property, or defamatory contentMedia and intellectual property cover, often added as an extension

Service levels, service credits and contractual liability

The contract you sign with each customer does more than set the price — it defines the promises an insurer is being asked to stand behind. For SaaS, the service-level agreement (SLA) is central: it commits you to a standard of availability, performance and support, and it usually sets out what happens when you fall short.

Two contractual mechanisms matter most for insurance. Service credits — the refunds or discounts you give a customer when you miss an SLA — are generally treated as a commercial rebate, a cost of doing business, rather than an insurable third-party loss, so they are typically excluded or simply not something a tech E&O policy is designed to pay. Liability caps and exclusions, by contrast, work in your favour: a well-drafted cap limits what a customer can recover from you, which in turn limits what the insurer may have to pay.

The risk runs the other way too. If you assume liabilities you would not otherwise have had at law — for example by accepting uncapped liability, agreeing to broad indemnities, or promising specific outcomes — you may create exposure that your policy’s contractual liability terms do not cover. Most tech E&O wordings respond to your legal liability for negligence; they are not designed to underwrite every promise you choose to make. In short, what you sign shapes what you can insure. It is worth reviewing demanding customer contracts against your policy before you commit, and disclosing unusual terms to your insurer — the Insurance Act 2015 duty of fair presentation expects a fair picture of the risk.

Downtime, outage and handling customer data

Two exposures define day-to-day SaaS risk: the service going down, and the data flowing through it.

Downtime and outage. When a SaaS platform is unavailable or degraded, the harm is not confined to you. Your customers may be unable to trade, serve their own clients or meet their own deadlines, and they can look to you for the resulting business interruption losses. Because they all depend on the same platform, one outage can generate many simultaneous claims — the aggregation problem again. Tech E&O is the cover most likely to respond to a third-party claim that your service failure caused a customer a financial loss; your own lost revenue during the outage is a different matter, usually addressed under cyber or business-interruption cover rather than professional indemnity.

Data. A SaaS provider typically processes large volumes of customer and end-user personal data, which brings duties under the UK GDPR and the Data Protection Act 2018. Getting data handling wrong — losing it, corrupting it, or failing to process it as agreed — can cause customers loss and attract regulatory attention. Claims arising from professional failings in how you handle data can touch tech E&O, but a security breach of the platform itself, and the regulatory and notification response that follows, is core cyber territory. The distinction is worth understanding before you need it.

Remember that cover is written on a claims-made basis: it is the policy in force when the claim is made, or when a circumstance is notified, that responds — not the policy in force when the work was done. Continuity of cover therefore matters, and any circumstance that might give rise to a claim should be notified promptly.

Tech E&O versus cyber: where the line sits

This is the distinction that causes the most confusion, so it is worth making crisp.

Tech E&O and professional indemnity answer for your service. This cover responds when something you did, or failed to do, in delivering the service causes a customer a financial loss: a defect, an error, a missed service level, or negligent advice or implementation. The trigger is a third-party claim alleging your professional failure.

Cyber answers for your platform. It responds to a security incident affecting you — a breach, ransomware, a hack — and funds the response: forensic investigation, incident management, customer and regulator notification, and your own business interruption while systems are down. The trigger is an attack on, or failure of, your security, not a professional error.

The reason a SaaS business typically needs both is that a single event often has both faces. Picture an outage caused by a security breach: the breach response, your notification duties and your own lost income sit with cyber, while customers’ claims that your unavailable service caused them loss sit with tech E&O. Neither policy alone covers the whole picture, and the gaps between the two are where uninsured losses hide — which is why the two wordings should be read together rather than bought in isolation.

Many SaaS providers also carry media and intellectual property cover, often as an extension, for claims that their content, branding or code infringes a third party’s rights or is defamatory. A specialist broker can help map your contracts and platform against these covers so the boundaries line up. As ever, buy and renew on the basis of a fair presentation of the risk, and treat the claims-made trigger as a reason to keep cover continuous.

How Apex places professional indemnity for SaaS companies

Why SaaS companies move their PI to Apex

When it is worth getting a second quote

It is worth asking us to re-market your cover when:

When we are not the right broker

We would rather say so than waste your time. We are probably not for you if:

Related guides

Frequently asked

What is the difference between professional indemnity and technology E&O for a SaaS business?

In practice they overlap heavily. Professional indemnity covers claims that your professional work or advice caused a client a financial loss; technology errors & omissions extends that idea to technology products and services, including software defects and service failures. For a SaaS provider the cover is usually written as a combined professional indemnity / tech E&O wording, so that both advice-led and product-led claims are addressed in one place.

Does tech E&O cover my service-level agreement?

It can respond to a claim that a failure to meet your SLA caused a customer a financial loss, but the detail matters. How your SLA is drafted, whether liability is capped, and whether the shortfall stems from negligence all affect the outcome. Service credits you hand back for missing targets are generally treated as a commercial rebate rather than an insurable loss. Reviewing demanding contracts against your policy before you sign is sensible.

What happens if my platform goes down and many customers claim at once?

This is the aggregation scenario SaaS insurers think hardest about. If one root cause, such as an outage or a faulty release, triggers claims across your customer base, those claims can be treated as linked and may erode a single policy limit together. It is one reason the limit you choose, and how your policy defines a single claim, deserve careful thought rather than a quick decision.

Do I need cyber insurance as well as tech E&O?

Most SaaS businesses do. Tech E&O answers for your service causing a customer loss; cyber answers for a security breach of your own platform and the response to it — investigation, notification, and your own downtime. A single incident can involve both, and the gaps between the two policies are where uninsured losses tend to sit, so it is wise to read the two wordings together.

What does a claims-made basis mean?

It means the policy that responds is the one in force when a claim is made against you, or when you notify a circumstance that might lead to one — not the policy in force when you did the work. For SaaS, where a defect might surface long after a release, this makes continuity of cover important, and it makes prompt notification of potential problems a duty worth taking seriously.

How does handling customer data affect my cover?

A SaaS provider usually processes significant volumes of personal data, which brings duties under the UK GDPR and the Data Protection Act 2018. Claims arising from professional failings in how you handle that data can touch tech E&O, while a breach of the platform’s security and the regulatory response that follows are core cyber matters. Understanding which policy does what before an incident is far easier than afterwards.

What do I need to disclose when I buy or renew?

Under the Insurance Act 2015 you owe a duty of fair presentation: you must give the insurer a fair picture of the risk, including material facts a prudent underwriter would want to know. For SaaS that typically means your contract terms, any unusual liabilities you have accepted, your security posture, and any known issues or circumstances. A fair presentation protects your right to claim, so it is worth doing thoroughly.

Get SaaS tech E&O cover that fits your contracts

Your customer agreements, service levels and data duties are unique to your platform, so your cover should be shaped around them rather than bought off a generic list. Talk to a specialist broker about professional indemnity, tech E&O and cyber cover that works together for your SaaS business. Or call 0117 325 0027.

Get a quote Request a callback

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.