Software developers
If you build bespoke software, apps, integrations or platforms for clients, your biggest professional exposure is simple to state and expensive to carry: the code you write fails to work, misses the agreed specification, slips past the go-live date, or carries a defect that costs the client money. Professional indemnity insurance — for software firms usually written as technology errors & omissions (tech E&O) — is the cover that responds when a client claims your work fell short and looks to recover its loss from you.
Part of: Technology professional indemnity
In short
Professional indemnity insurance — written for software firms as technology errors & omissions, or tech E&O — pays to defend and settle a client’s claim that your software failed: that it did not work, did not meet the agreed specification, was delivered late, or contained a defect that caused the client a financial loss. It is the defining cover for a bespoke software house, because the defining exposure is your work itself going wrong once a client relies on it. A tech E&O policy typically covers negligent acts, errors and omissions in the services you provide, the legal cost of defending the allegation, and the damages or settlement you become liable to pay, alongside related exposures such as intellectual-property infringement and breach of a duty of confidence. Professional indemnity is written on a claims-made basis, so the policy in force when the claim is made responds — not the one in force when you wrote the code.
Professional indemnity for a software developer answers one blunt question: when a client says the software you built let them down and wants their money back, who pays to argue the point and who pays if the client is right? A tech E&O policy is built around exactly that. It responds to an allegation of a negligent act, error or omission in the work you were engaged to do — the design, the code, the integration, the configuration, the advice — and it funds both the defence and any damages or settlement you are legally liable to pay.
For a bespoke software house the triggering events are familiar: a build that does not function as promised, a release that misses the agreed specification, a go-live that slips and disrupts the client’s operation, or a defect in production that corrupts data, stops transactions or causes a financial loss. The loss a client pursues is rarely the fee you charged; it is the cost of the consequences — remediation, lost revenue, a failed launch, a third party the client must in turn compensate. Even a claim with no merit has to be investigated and answered by solicitors, and it is that defence cost which most often makes an uninsured developer wish they had the cover.
| Typical claim against a software developer | What a tech E&O policy generally responds to |
|---|---|
| Software does not work, or repeatedly fails in production | Defence costs and the client’s financial loss where it flows from a negligent error or omission in your work |
| Delivered build does not meet the agreed specification | Responds to the negligence allegation; an absolute promise that it would meet the spec may not (see below) |
| Missed go-live or late delivery causing the client loss | Covered where the delay results from negligence, not from an uninsured penalty clause or liquidated-damages warranty |
| A bug corrupts or loses the client’s data | Your liability for the consequences of the error — distinct from a breach of your own systems (see cyber, below) |
| Infringing a third party’s intellectual property in the code you ship | Usually the intellectual-property-infringement section of a tech E&O wording (see below) |
| Breach of a duty of confidence over client information | Commonly included within the professional-services cover |
The precise trigger, the definitions and the exclusions differ between wordings, and the limit of indemnity is driven by your contracts rather than by any rule of thumb, so the detail of the policy matters as much as the headline that you are “covered”.
A professional indemnity policy insures a particular legal standard: the duty to exercise reasonable skill and care in the services you provide. That is, in practice, the standard the law implies into a contract for professional services in any event — you are judged against what a reasonably competent developer would have done, not against perfection. If your code was written to that standard, a bug or a shortfall is not automatically a breach, and your insurer defends you on precisely that footing.
The trap lies in the words of the development contract. Client-drafted terms and master services agreements often ask you to promise far more than reasonable skill and care: that the software will meet the specification, will be free of defects, will be fit for the client’s particular purpose, or will go live by a fixed date on pain of liquidated damages. These are absolute obligations — fitness-for-purpose and specific-performance warranties — and they are not measured against what a competent developer would do. They are either met or breached, however carefully you worked.
This is the same trap construction professionals meet with fitness-for-purpose clauses, transposed to code. A PI or tech E&O policy generally responds to liability arising from negligence; it does not make your insurer answerable for an outcome you contracted to deliver absolutely. A liability you take on by contract that you would not have had at law — an uninsured warranty, an indemnity wider than negligence, a penalty for delay — can fall outside the cover entirely. The practical discipline is to keep your contractual liability anchored to reasonable skill and care, to resist absolute warranties where you can, and to have a specialist broker read the assumed-liability position against the policy before you sign.
Modern software is assembled as much as it is written. A single delivered build may pull in open-source packages, commercial libraries, sample code, framework components and work carried over from earlier projects. Each of those is a route to an intellectual-property claim: an open-source licence whose conditions you did not meet — a copyleft obligation that would require you to release source you intended to keep proprietary — a commercial component used beyond its licence, code copied from a previous client or employer, or a design, name or algorithm that infringes a third party’s copyright, database right, trade mark or patent.
Most tech E&O wordings include cover for unintentional infringement of a third party’s intellectual property arising from your work, together with the legal cost of defending such an allegation. Where your work also involves content — marketing copy, imagery, user-facing material — a media liability section can extend to infringement, defamation and similar publishing risks. The common thread is that the cover contemplates an innocent or negligent breach, not a deliberate one: knowingly shipping code you had no right to use, or passing off another party’s product as your own, sits outside any wording.
Two practical points follow. First, keep a clear record of the third-party and open-source components in what you deliver and the licences they travel under — a software bill of materials is the plainest form — because you can neither present the risk to an insurer fairly nor defend a claim well without it. Second, check how the contract allocates intellectual property: who owns the delivered work, what you warrant about its originality, and whether you have indemnified the client for infringement more widely than your policy would respond.
The single most useful distinction for a software developer to hold clearly is the line between tech E&O and cyber insurance, because they answer different questions and a developer usually needs both.
Tech E&O — your professional indemnity — is about your work. It responds when something you designed, built or advised on fails and causes your client a loss: the defective release, the integration that corrupts the client’s records, the advice that proves wrong. The claimant is the client, or someone standing in the client’s shoes, and the allegation is professional failure.
Cyber insurance is about your own systems. It responds when your environment is breached, encrypted or disrupted — a ransomware attack on your network, a compromise of your source-code repository, stolen credentials, a breach of the personal data you hold. It funds the incident response: forensic investigation, restoring systems, legal and notification costs, the regulator-facing work under UK GDPR and the Data Protection Act 2018, interruption to your own business, and extortion handling.
The boundary is the cause and the victim, not the technology. A bug you wrote that loses a client’s data is a professional failure — tech E&O territory. An attacker breaking into your servers and stealing that same data is a security incident — cyber territory. The awkward cases live in between, such as a vulnerability you negligently coded that a third party then exploits against the client, which is exactly why software firms commonly carry both — ideally arranged so the two wordings meet rather than leave a gap between them. A specialist broker can map your contracts and operations across the two policies so that a claim does not fall into the space in between.
It is worth asking us to re-market your cover when:
We would rather say so than waste your time. We are probably not for you if:
Yes. Technology errors & omissions (tech E&O) is the form professional indemnity takes for technology and software firms — the same core promise to defend and settle a claim that your professional work was negligent, with definitions and extensions tuned to how software is built and sold. You may see either name on a wording; what matters is that the cover reaches the services you actually provide.
Generally yes, where the client’s loss flows from a negligent error or omission in your work rather than from a promise that the software would be flawless. The policy funds the cost of defending the allegation as well as any damages or settlement you are liable to pay. Whether a particular loss is covered turns on the wording, the facts and how your contract framed your obligations.
Those are absolute warranties, not the reasonable-skill-and-care standard a PI policy is built around, and liability you accept under them can fall outside your cover. A tech E&O policy responds to negligence; it does not make your insurer answerable for an outcome you contracted to deliver absolutely. The safer course is to keep your contractual liability anchored to reasonable skill and care and to have the terms read against your policy before you sign.
Most software firms need both, because they answer different questions. Tech E&O responds when your work fails and causes a client a loss; cyber responds when your own systems are breached, encrypted or disrupted, and funds the incident response. Arranged together, the two wordings should meet rather than leave a gap between a coding failure and a security incident.
Most tech E&O wordings cover unintentional infringement of a third party’s intellectual property arising from your work, together with the cost of defending the allegation. Deliberate infringement — knowingly using code you had no right to — is not insurable. Keeping a clear record of the third-party and open-source components you ship, and the licences attached to them, both supports a defence and lets you present the risk to insurers accurately.
Professional indemnity is written on a claims-made basis, so the policy that responds is the one in force when the claim is made against you — not the one in force when you wrote the code or delivered the project. This makes the retroactive date important and is why continuous cover matters, and it is also why run-off cover is worth arranging if you wind the business down, since claims about old work can surface years later.
Under the Insurance Act 2015 you owe a duty of fair presentation: you must disclose, clearly and accessibly, every material circumstance you know or ought to know — the nature of your work, your largest and most business-critical projects, the contracts and warranties you sign, any circumstance that might give rise to a claim, and your claims history. A fair presentation at the outset is what keeps the cover dependable when you come to rely on it.
Tell us what you build, the contracts and warranties you work under and the limits your clients require, and a specialist broker can help you put professional indemnity and technology errors & omissions in place — with cyber alongside it where you need it — matched to how your software house actually operates. Or call 0117 325 0027.
Get a quote Request a callbackApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.