
For a SaaS company, your product is your exposure. Customers rely on your platform to run their own operations, and when it fails, their losses can quickly become your problem.
Two policies sit at the centre of a technology company's insurance program: technology errors and omissions (tech E&O) and cyber. They are often confused, and many companies have one but not the other.
What tech E&O covers
Tech E&O responds when a customer claims your technology products or services caused them a financial loss. Examples include:
- An outage or bug that interrupts a customer's operations
- A failed implementation or migration
- A feature that doesn't perform as promised in your contract or documentation
- A data integration error that corrupts a customer's records
- Missed service level commitments that lead to a claim for damages
It's professional liability built for technology, and it usually includes defence costs, which can be significant even when you did nothing wrong.
What cyber covers
Cyber responds to security and privacy incidents. For a SaaS company, that includes:
- Your own costs: forensics, legal advice, breach notification, data restoration and ransomware response
- Business interruption: your lost revenue while your platform is down because of an attack
- Liability: claims from customers and regulators after personal or confidential data is exposed
You can read more in our guide to what cyber insurance covers.
Where the two overlap
Consider a ransomware attack that takes your platform offline for two days:
- Your forensic, recovery and lost-revenue costs fall under cyber.
- Customers who claim your outage cost them money may bring claims that fall under tech E&O, cyber liability, or both, depending on the wording.
If the policies are placed with different insurers and written on different terms, there's room for gaps and for disputes about which policy responds. That's why many technology companies buy a combined tech E&O and cyber policy from one carrier, with shared definitions and a single claims process.
What your contracts require
Enterprise and public sector customers increasingly include insurance requirements in their master service agreements, often specifying minimum limits for both tech E&O and cyber. Procurement teams may ask for certificates before signing. If your limits are too low, you can lose time in a sales cycle or have to accept uninsured contractual risk.
Also look closely at your limitation of liability and indemnity clauses. Insurance and contracts need to work together. Agreeing to uncapped liability for data breaches, for example, can expose you well beyond your policy limits.
Underwriters will ask about
- Your product, customers and the industries they operate in
- Revenue, customer concentration and contract values
- Uptime commitments and how you handle incidents
- Security controls, including MFA, EDR, backups and access management
- Your standard contract terms, especially limitation of liability
How Summit can help
We place tech E&O and cyber for Canadian SaaS and technology companies, often alongside D&O as they raise capital. We review your contracts, benchmark limits against your customer requirements and compare combined and standalone options. If you're raising a round, see our guide to D&O insurance for startups.