The Coverage Memo

Errors and Omissions Insurance for SaaS Startups

Coverage gaps in the fine print can cost a startup millions once a client sues.

Senior Writer · · 11 min read
Cover illustration for “Errors and Omissions Insurance for SaaS Startups”
Tech and Product Liability · September 16, 2026 · 11 min read · 2,511 words

Errors and omissions insurance is the coverage that actually matches how SaaS companies fail. A bug in production, a botched implementation, a system outage that costs a client real money: these are the failures Tech E&O is built to address, and general liability doesn't touch any of them. Knowing what the policy covers, what it costs, and when to buy it has become a real precondition for closing enterprise deals, one that has to be met before the contract gets signed. Founders keep treating Tech E&O like a checkbox insurers hand them off a template, and that's the wrong way to think about it. The gaps sit inside the fine print, and a client only finds them once it's already suing.

Tech E&O coverage and its boundaries

General liability was built for a different century of business risk: someone slips on a wet floor, a contractor's crane clips the building next door. Bodily injury, property damage. None of that describes what goes wrong at a software company. Tech E&O borrows its structure from the professional liability model that architects and accountants have carried for decades to cover design errors or bad financial advice, rebuilt for code and service delivery instead.

The policy responds to claims alleging that a company's software or technology services caused a third party financial harm. That's the core test, and it covers a specific set of situations: software defects that crash a client's systems or corrupt their data, flawed implementations that miss agreed requirements and force expensive rework, outages that breach an SLA and cost a customer revenue, bad configuration advice from a solutions team, missed deadlines tied to a covered failure, and losses a client suffers by relying on a report or output the software generated.

Take a financial reporting SaaS platform with a bug in its calculation engine. Say the bug runs undetected for two quarters, quietly producing wrong numbers, and clients make real decisions off those numbers before anyone catches it. The claims that follow land squarely in Tech E&O territory. GL has nothing to say about it: no bodily injury occurred, no property was damaged. Without Tech E&O, that company pays defense costs and any settlement entirely out of pocket. Per Hotaling Insurance, just defending a contested tech liability claim commonly runs $150,000 to $500,000 before a single dollar of settlement changes hands.

The policy pays defense costs, settlements, and judgments up to whatever limit was bought. But it draws hard lines around what it won't touch: intentional wrongdoing or fraud, issues the company already knew about before the policy started, pure breach-of-contract claims with no underlying covered allegation attached, bodily injury and property damage (still GL's job), and privacy or security incidents, which fall to cyber coverage even though the two lines overlap more than most founders expect. Fines and penalties that are uninsurable by law stay uninsurable no matter what the policy says.

One structural detail follows from how the policy gets written. Tech E&O is typically written on a claims-made basis, so a claim has to be reported while the policy is active for coverage to apply. And the contract itself sets the real ceiling on what the policy can do. If an MSA includes a broad warranty or an unlimited liability clause, the company has already promised more than any insurance policy is built to back up. No underwriter fixes that after the fact.

Three coverage gaps that policies often leave open by default

Diagram: The SaaS Insurance Stack: Costs at a Glance. Visualizes: Show the full annual insurance cost breakdown a mature SaaS company carries, as four distinct cost bands stacked by line of coverage.

Three gaps appear repeatedly in standard Tech E&O forms, and all three follow the same pattern. The exclusion sits quietly in the policy language, the client sues anyway, and the company only learns about the gap once the claim has already landed.

The first is third-party cloud infrastructure. Some policies exclude losses caused by failures at underlying providers. That sounds reasonable on paper, since the SaaS company didn't cause the outage. But the client doesn't sue the infrastructure provider. The client sues the vendor it has a contract with, which is the SaaS company. Buyers need to confirm with the underwriter, in writing, that losses stemming from third-party infrastructure failures fall inside the policy's scope, because plenty of standard forms leave that question unanswered.

The second is the retroactive date. Claims-made Tech E&O policies tie coverage to when the policy is active, which means incidents from before the policy's retroactive date are excluded. A company that launched well before buying its first policy may have no coverage for earlier failures. Negotiating the retroactive date back to the company's founding or its product launch is the standard way to close that hole.

Third: dependent business interruption. Base Tech E&O policies almost universally exclude losses caused by a third-party vendor's failure. If a service the company relies on goes down and it costs the company revenue or extra cost to recover, the base form simply doesn't respond. That has to be added as an endorsement, and it's the cheapest fix on this list: The Coyle Group prices it at roughly $200 to $500 a year, which is nothing set against the size of the exposure it closes.

Tech E&O pricing for SaaS companies and its price drivers

Pricing swings a fair amount depending on how a company buys it. TechInsurance's 2025 customer data puts standalone E&O at around $91 a month, with cyber alone running higher at about $153 a month. Bundle the two into a combined Tech E&O and cyber package, and Insureon's June 2026 median comes to $126 a month, or $1,516 a year, cheaper than buying the two lines separately.

Early-stage companies face different math, and most of them are wasting money if they buy too early. Pre-revenue or pre-customer, coverage often isn't worth it because insurers apply minimum premium requirements no matter how small the company is. Once there's a product in market, $2,500 to $4,500 a year is the floor most startups run into. Smaller software firms cost $807 to $1,094 a year at minimum, per Anvo Insurance, though Anvo notes the number that actually drives price is usually the limit required by customer contracts, commonly a range spanning several million dollars, rather than the size of the company buying the policy.

Zoom out to the full insurance stack a SaaS company eventually carries. Hotaling Insurance (July 2026) puts the total range at $15,000 to $75,000 a year, split roughly into Tech E&O at $5,000 to $25,000, cyber at $3,000 to $15,000, D&O at $5,000 to $20,000, and GL at $1,000 to $5,000. That range scales with ARR, headcount, and how sensitive the data is that the company handles.

A handful of factors actually move the number, and revenue isn't the biggest one. The limit required in the company's largest customer contract sets the real floor, whatever the founder's own sense of "enough" would otherwise suggest. Security posture counts for a lot too: Companies with documented controls and contractual liability caps generally pay meaningfully less than identically sized peers without them. Data sensitivity pushes prices up sharply for this category specifically, with SeedPod putting tech and SaaS companies at 40 to 88% above the national SMB average for cyber coverage. SOC 2 Type II certification earns a real discount, 10 to 20% according to Hotaling Insurance, because the audit itself proves the security controls underwriters would otherwise have to take on faith.

The underwriting application itself works like a free security audit. Questions about multi-factor authentication, endpoint detection, backup procedures, incident response plans, and vendor management expose gaps that should get fixed whether or not the company ends up buying the policy.

Required coverage limits set by clients, not by the startup

Startups don't get to pick their own limits in any meaningful sense. Clients pick them, through the MSA, and the founder's job is to meet the number, not negotiate it down. The Coyle Group breaks the tiers down clearly: SMB clients typically ask for $1 million to $2 million combined across Tech E&O and cyber, mid-market clients in the $10 million to $100 million revenue range ask for $2 million to $5 million, and enterprise clients at the Fortune 500 level ask for $5 million to $10 million.

Most companies follow a predictable path: a combined limit in the low millions at Series A, stepping up to roughly double or more as ARR grows and customer concentration increases, per Hotaling Insurance. Enterprise vendor onboarding tends to require a specific bundle of coverages, with the customer named as an additional insured and minimum limits spanning a range in the low millions. Those thresholds usually map directly onto the customer's own vendor risk policy and SOC 2 expectations.

The practical rule is simple: look at the largest current customer contract and let its requirements set the baseline. The policy has to meet the MSA. Feeling adequately covered doesn't matter if the contract language says otherwise, and if the MSA already promises unlimited liability or an unusually broad warranty, no insurance program can retroactively cover what's already been given away at the negotiating table. That's why enterprise procurement checklists name Tech E&O specifically, with a stated limit, rather than just asking for "an insurance certificate." That one line item can stall or unlock a deal.

SaaS companies with AI features facing coverage that no longer clearly applies

For 2026 renewals, insurers are deciding how AI risk gets allocated across policies, instead of letting it sit quietly inside coverage that was never written with AI in mind. Fenwick (June 2026) describes the result as fragmentation, not clarity: AI-related claims risk falling between the cracks of traditional coverage lines, or getting caught between competing exclusions across different layers of a company's insurance tower.

Part of the pressure comes from the ISO generative AI exclusion added to CGL policies, effective January 2026, which excludes bodily injury, property damage, and personal or advertising injury tied to generative AI. That exclusion pushes AI exposure over toward Tech E&O and cyber. But not every Tech E&O form has caught up, and this is where the mistake happens. The practical requirement is clear: any SaaS product using AI to generate recommendations, analysis, or content that clients act on needs explicit confirmation from the underwriter that AI-related professional liability sits inside the policy's scope. Assuming it's covered because the product is "just software" is the wrong call, and it's the one most founders still make.

The failure modes here are genuinely new, not faster versions of old bugs. Hallucinations produce outputs that are confidently wrong and get acted on anyway. Model drift degrades accuracy gradually, with no discrete bug event to point to. Algorithmic bias can produce discriminatory outputs, particularly dangerous in hiring, lending, insurance, and healthcare, where it can trigger regulatory investigation and class action exposure. Non-explainable outputs make it hard for anyone, including the company being sued, to reconstruct why the model made a given call, which complicates negligence claims in ways older policy language never anticipated. All of this needs affirmative wording in the policy itself, rather than reliance on forms written before generative AI existed.

The Air Canada case from 2024 is the clearest illustration of why this isn't theoretical. The airline's chatbot hallucinated a bereavement fare policy that didn't exist, offering a retroactive discount to a grieving passenger. When the passenger tried to actually claim it, Air Canada argued it couldn't be held responsible for information its own chatbot provided, treating the bot as if it were a separate entity accountable for its own conduct. The tribunal wasn't persuaded. Per Insurance Thought Leadership, the case shows liability tied to automated decision-making has already moved past hypothetical, and any company still treating "the AI said it" as a legal shield is arguing a case it will lose.

For companies built heavily around automated models, treating a traditional E&O policy as a complete substitute for coverage tied specifically to how a model behaves is where the gap opens up, and it's the single most avoidable mistake in this entire piece.

Current insurance market conditions for buyers in 2026

Claims are climbing while prices are falling, and that combination is why 2026 favors the buyer, not the seller, of this coverage. One market report found cyber and Tech E&O incidents rose 38% in 2025, driven by ransomware severity, AI-related claims, and the steady expansion of privacy regulation. Pricing moved the other direction anyway: all-layer rates fell 4 to 5% across 2025, according to SomainSure, with more than 90 insurers competing for placements. That much competition keeps capacity abundant and hands buyers real leverage at the negotiating table.

The cyber market grew fast in 2025 specifically. Fitch Ratings found direct written premium rose almost 11% after two straight years of decline, driven by roughly a 34% jump in policies in force, meaning the growth came from more companies buying coverage for the first time, not existing buyers paying more.

Ransomware drives a lot of this. The CISA Joint Ransomware Task Force recorded a 9% rise in attacks on technology-sector businesses in 2024, and per The Coyle Group, the business interruption claims that follow, filed by clients against their technology vendors for service failures, frequently end up triggering Tech E&O coverage rather than cyber alone.

None of that means buyers should get sloppy about it. A company shopping for coverage in 2026 has genuine pricing leverage, but it still needs to read policy language on AI, cloud infrastructure, and retroactive dates more carefully than ever, precisely because insurers are actively rewriting forms in response to everything above.

Policy timing across stages and how funding requirements shape the sequence

The trigger for Tech E&O and cyber is operational, tied to the moment a company signs its first paying customer or lands an enterprise contract, because most MSAs demand proof of coverage right then. Before that point, pre-revenue and pre-customer, coverage is usually a bad financial trade anyway, since minimum premium requirements at many insurers make early purchase cost-inefficient. Once there's a real product with real customers, $2,500 to $4,500 a year is the floor most companies land on.

D&O insurance runs on an entirely different clock, set by investors rather than customers. At pre-seed and seed, it's usually not required, though Beancount.io notes that some term sheets include a loosely enforced clause requiring "customary" D&O coverage without specifying much. That changes hard at Series A. Beancount.io calls it effectively mandatory at that stage: most institutional VCs require a D&O policy with minimum limits set at a substantial multi-million-dollar threshold within 60 to 90 days of the round closing. Cost for a startup at that stage runs $4,000 to $7,000 a year, scaling upward as the company raises more capital.

Put together, the sequence stacks several distinct triggers on top of each other. Customer contracts force Tech E&O and cyber first. Investor term sheets force D&O second. The limits on both keep climbing as the largest customer contract and the most recent funding round each raise the bar. Treating any one of these as optional until it feels urgent is how a company finds out, the hard way, what its policy doesn't cover.

Sources

  1. SaaS Business Insurance: Get A Free Quote | TechInsurance
  2. Software as a Service (SaaS) Company Insurance Costs | Insureon
  3. Tech E&O Insurance. The Complete Guide
  4. hotalinginsurance.com
  5. seedpodcyber.com
  6. anvo-insurance.com
  7. somainsure.com
  8. fenwick.com

More in Tech and Product Liability