Industry VerticalsChapter 5022 min read

Technology, the industry where the program is built around what the company sells, not where it operates.

Technology insurance is built around the product or service the company sells. SaaS, hardware, services, marketplaces, fintech, healthtech, and AI companies all carry technology E&O combined with cyber and (depending on stage) D&O. Programs evolve through the funding lifecycle: seed-stage tech companies carry minimal coverage, Series A and B add D&O and cyber, IPO-stage companies carry full management liability stacks. The AI-driven products of the current cycle have introduced new exposure categories that carriers and insureds are working through together.

§ 01

The mental model

Technology insurance is built around what the company sells. The product or service is the source of the largest exposures. A SaaS company faces customer claims when the platform fails to perform as represented. A hardware company faces products liability claims and warranty claims. A marketplace platform faces user claims and regulatory exposure. A fintech faces financial services regulatory exposure layered on technology exposure. An AI company faces emerging exposure categories that are still being defined.

The other defining feature of technology insurance is the funding lifecycle. Tech companies often follow a predictable insurance evolution: bootstrap and seed-stage carry minimal coverage (basic tech E&O, basic cyber, GL); Series A and B add D&O reflecting board governance and investor protection needs; growth-stage adds expanded cyber, IP coverage, EPLI, fiduciary; pre-IPO and post-IPO add full public-company D&O including dedicated Side A coverage. The right program for a tech company depends substantially on stage and structure. The third feature: tech companies often operate across jurisdictions in ways that traditional industries do not, with customers in many countries, employees in distributed locations, and product distribution that is global from launch. The insurance program reflects this geographic and structural complexity.

Anchor concept

Tech insurance evolves with the company. A seed-stage SaaS company and an IPO-stage SaaS company are different insurance buyers, even if they sell similar products. The underwriting questions, the coverage purchases, the limit decisions, and the carrier selection all shift with stage. Carriers that specialize in tech build practice areas around the lifecycle.

§ 02

The technology segment landscape

Technology spans a wide range of business models with distinct insurance profiles.

Software-as-a-Service (SaaS)

Cloud-delivered software with subscription business models. Programs emphasize tech E&O, cyber, D&O, and (for enterprise SaaS) substantial cyber limits to support customer contractual requirements. Customer indemnification obligations often drive coverage limit decisions.

Enterprise software and on-premises

Software delivered to customer environments, including legacy enterprise software, ERP, CRM, and infrastructure software. Tech E&O focused on integration and implementation; cyber for the company's own systems; products liability considerations for software embedded in physical products.

Hardware and IoT

Computers, networking equipment, consumer electronics, IoT devices, smart home, wearables, automotive electronics. Programs combine technology E&O with products liability, recall, and (for connected devices) cyber and privacy coverage.

Tech services and consulting

IT services, system integration, managed services providers, IT consulting, cybersecurity services. Tech E&O is the foundational coverage; cyber for the services provider's own systems and for customer-affecting incidents.

Internet platforms and marketplaces

Marketplaces, social media, content platforms, sharing economy. Programs include tech E&O, cyber, content liability (Section 230 considerations), and platform-specific user liability.

Fintech

Payments, lending, neobanks, robo-advisors, crypto exchanges, blockchain platforms. Programs combine tech coverage with financial institution coverage. Regulatory complexity is substantial; coverage allocation between tech E&O and FI E&O requires careful structuring.

Healthtech and digital health

Telehealth, digital therapeutics, healthcare AI, EHR systems, healthcare analytics. Programs combine tech coverage with healthcare professional liability and HIPAA-driven cyber. Crosses with healthcare insurance (Chapter 39).

Edtech, govtech, climatetech, biotech

Vertical-specific tech segments with sector-specific exposures. Each carries the core tech program plus sector-specific coverage components.

AI companies

Foundation model developers, AI applications, AI infrastructure, AI consulting. Programs are evolving rapidly with carriers developing AI-specific endorsements and exclusions.

§ 03

Technology E&O

The foundational tech industry coverage. Technology E&O (sometimes called Tech E&O, Tech Errors and Omissions, or Information Technology liability) responds to customer claims arising from failure of the technology product or service.

Coverage scope

Tech E&O typically covers:

  • Negligent acts in technology services. Errors in implementation, integration, customization, configuration, or operation of technology services.
  • Failure of technology products to perform. Software not performing as represented, hardware failure, service unavailability.
  • Breach of contract claims. Failure to meet contractual performance obligations.
  • Misrepresentation. Performance representations that turn out to be inaccurate.

Combined tech E&O and cyber

Modern tech E&O policies typically combine technology E&O with cyber liability into integrated forms. The combined form addresses the natural overlap between technology service failure and cyber events; a security breach in a tech company's product affects both customers (tech E&O exposure) and the company itself (cyber exposure). Combined forms simplify coverage allocation but require careful sub-limit structures.

Customer contract requirements

Tech E&O limits are often driven by customer contract requirements. Enterprise customers frequently require their tech vendors to carry minimum coverage limits, name them as additional insureds, and provide certificates of insurance. The contract requirements drive minimum limits regardless of the tech company's perception of its own risk.

SLA-driven exposure

Service Level Agreements (SLAs) define the tech vendor's performance obligations. Failure to meet SLAs generates customer credits and (for substantial failures) breach claims. Tech E&O coverage of SLA-driven exposure varies by form and is often a focus of underwriting and contract negotiation.

IP infringement

Tech E&O typically covers customer claims that the tech vendor's product infringes third-party IP, with the vendor having indemnified the customer. Direct first-party IP infringement claims are usually addressed in separate IP coverage rather than tech E&O.

Customer indemnification obligations

Tech vendor contracts typically include indemnification obligations to customers for various exposure categories: IP infringement, data breach, product failure. Tech E&O programs are designed to back these indemnification obligations, with carrier coordination on indemnification language increasingly common.

§ 04

Cyber for tech companies

Tech companies face cyber exposure both as targets of attacks and as providers of cyber-related services to others.

First-party tech company cyber

Tech companies face cyber exposure to their own operations, similar to other industries:

  • Customer data breach.
  • Operational disruption from ransomware or other attacks.
  • Funds transfer fraud.
  • Cyber extortion.
  • Third-party vendor incidents affecting the tech company.

Third-party tech company cyber

Tech companies frequently have third-party cyber exposure that other industries do not:

  • Customer breach affecting end users. A SaaS provider whose platform suffers a breach faces claims from the customer's end users (employees, partners, consumers) whose data was exposed through the SaaS platform.
  • Service availability. Cyber events affecting service availability generate customer breach-of-contract claims.
  • Customer regulatory exposure. Customers facing regulatory action because of cyber events at their tech vendors pursue the vendors for indemnification.

Notification volume

Tech companies hosting customer data face high notification volumes after breach events. A SaaS platform serving thousands of customer organizations may face notification obligations to millions of end users in a single breach event. Notification cost is a significant cyber loss component.

Regulatory exposure

  • U.S. state breach notification laws. All 50 states; sector-specific overlays in healthcare, financial services, and education.
  • GDPR. Personal data of EU residents, including by U.S. tech companies serving EU customers. Substantial penalties (up to 4% of global revenue) for major violations.
  • State privacy laws. CCPA/CPRA (California), CDPA (Virginia), CPA (Colorado), and additional state laws creating compliance overhead and potential class action exposure.
  • SEC cyber disclosure rules. Public tech companies subject to 4-day material incident disclosure rules.

Tech company cyber program structure

Tech company cyber programs vary widely by stage and customer base. Pre-revenue startups may carry $1M-$5M cyber. Mid-stage SaaS companies typically carry $10M-$25M. Enterprise SaaS providers and major tech platforms carry $100M+. Major hyperscale platforms carry $500M+ in cyber limits across multi-tower programs.

§ 05

D&O across the funding lifecycle

Tech company D&O coverage evolves substantially through funding stages.

Seed and Series A stage

Pre-revenue or early-revenue tech companies. D&O coverage at this stage is often basic, with limits in the $1M-$3M range. Coverage focuses on:

  • Founder and director protection in early shareholder disputes.
  • Basic securities exposure for private placement disclosures.
  • Basic regulatory exposure.

Series B through growth-stage

D&O coverage expands with funding rounds, typical limits $5M-$15M. Coverage focus shifts to:

  • Investor disputes and shareholder derivative actions.
  • Down-round and recap-driven litigation.
  • M&A activity (acquisitions for technology, talent, or market position).
  • Employment-related D&O exposure.
  • Increasing regulatory exposure as the company grows.

Pre-IPO and IPO

Companies preparing for or completing IPO require dedicated public-company D&O coverage. The coverage transition is a major program event:

  • IPO-specific coverage. Section 11 liability for the IPO registration statement; specific transactional coverage for the offering.
  • Run-off of private-company D&O. Tail coverage for pre-IPO acts, with discovery period extending into post-IPO periods.
  • Public-company D&O. Higher limits ($25M-$100M+), Side A coverage, broader form scope.
  • SPAC considerations. Companies going public via SPAC face specific D&O complexities through the SPAC structure and post-merger litigation.

Public-company D&O

Public tech companies face the standard public-company D&O exposure (Chapter 14) plus tech-specific dimensions:

  • Stock drop class actions following product issues, customer concentration loss, or financial misstatement.
  • Securities class actions following SEC cyber disclosure non-compliance.
  • M&A litigation for acquisitions and target-company shareholder disputes.
  • Going-private transactions and dual-class share structure disputes.
  • Founder-related governance disputes.

Side A and DIC coverage

Side A only coverage protects individual directors and officers when the company cannot indemnify them (insolvency, indemnification prohibition). Difference-in-Conditions coverage extends Side A to address coverage gaps in the underlying primary D&O. Both are common in tech D&O, particularly for late-stage and public companies.

§ 06

IP and media liability

Tech companies face concentrated IP exposure both as IP owners and as alleged IP infringers.

IP infringement defense

Coverage for the cost of defending claims that the tech company's products or services infringe third-party patents, copyrights, or trademarks. Patent infringement defense is among the most expensive litigation categories; typical defense costs run $1M-$10M+ per major case. Coverage scope:

  • Patent defense. Major segment, with patent litigation increasingly concentrated in tech.
  • Copyright defense. Software and content copyright disputes.
  • Trademark defense. Brand and product name disputes.
  • Trade secret defense. Often involves former employee or contractor disputes.

IP infringement enforcement

Coverage for the cost of enforcing the tech company's own IP rights against infringers. Coverage is less common than defense; enforcement coverage typically requires specific endorsement and is priced higher. Major IP-rich tech companies sometimes purchase enforcement coverage to support their IP strategy without exposure to enforcement litigation costs.

Patent troll litigation

Non-practicing entity (NPE) litigation, often called patent troll litigation, is a sustained tech industry exposure. NPEs assert patents through litigation with no operating business beyond the litigation. Settlement-driven economics create predictable litigation patterns that tech companies and carriers price into IP coverage.

Media liability

For tech companies producing or distributing content (publishers, streaming platforms, social media, marketing platforms), media liability covers:

  • Defamation claims.
  • Privacy violations.
  • Right-of-publicity claims.
  • Copyright infringement in content.
  • Errors and omissions in content.

Section 230 and platform liability

Section 230 of the Communications Decency Act provides substantial liability protection for internet platforms hosting third-party content. The protection has been narrowed by FOSTA-SESTA and continues to be challenged in legislation and litigation. Platform liability exposure outside Section 230 protection is a sustained exposure for marketplaces, social media, and content platforms.

§ 07

EPLI and the talent-driven workforce

Tech companies have specific employment exposures that distinguish their EPL programs.

Tech industry EPL exposures

  • Discrimination and harassment. Tech industry has had sustained class action exposure on gender and race discrimination. Major settlements have reshaped EPL underwriting in the segment.
  • Wage and hour. Misclassification of employees as exempt, classification of contractors as employees, expense reimbursement disputes (especially in remote-work contexts).
  • Non-compete and trade secret disputes. Heavy litigation around departing employees and competitive activity. State-level variation in non-compete enforceability creates compliance complexity.
  • Equity disputes. Disputes over stock options, vesting, RSUs, and equity exits. Common in venture-backed companies undergoing M&A or IPO.
  • Whistleblower retaliation. Sarbanes-Oxley and Dodd-Frank exposure for public tech companies; California specific whistleblower protections.
  • Layoff-related class actions. WARN Act class actions, severance disputes, and discrimination claims following layoffs.

Remote and distributed workforce

Tech companies frequently operate distributed workforces across many states and countries. The EPL implications:

  • State-by-state employment law compliance, with material variation in classification, paid leave, accommodation, and discrimination protections.
  • International employment exposure for offshore contractors and employees.
  • Tax implications of employee location creating nexus issues.
  • Wage and hour compliance across multiple states with different rules.

H1-B and immigration

Tech industry's reliance on visa-sponsored employees creates specific EPL exposures around visa application support, layoff-related visa transitions, and discrimination claims involving visa-sponsored workers.

§ 08

AI as an emerging exposure category

AI has introduced a new category of exposure that carriers and tech insureds are working through together.

AI exposure categories

  • AI hallucination and accuracy. Generative AI producing inaccurate outputs that customers or end users rely on. Tech E&O exposure when customers face harm from inaccurate AI outputs.
  • IP infringement in training and outputs. Copyright and other IP infringement claims arising from training data use and AI-generated outputs.
  • Discrimination and bias. Algorithmic decision-making producing discriminatory outcomes; particularly consequential in employment, lending, healthcare, and housing applications.
  • Privacy and data protection. Training data privacy issues, AI-driven inference of protected attributes, and AI-driven privacy violations.
  • Defamation and harmful content. AI-generated content causing reputational harm, including deepfakes and AI-generated defamatory content.
  • Critical decision failures. AI-driven decisions with high consequences (medical, legal, financial, safety) producing harm when the AI fails.

Coverage form responses

Carriers are responding to AI exposure through several mechanisms:

  • AI-specific endorsements. Some carriers have added AI-specific endorsements to tech E&O and cyber forms, defining coverage for AI-related exposures.
  • AI exclusions. Other carriers have added AI-specific exclusions, limiting coverage for AI-driven exposures pending more certainty about loss profiles.
  • AI-specific products. Specialty markets have begun offering AI-specific coverage products addressing the exposure category directly.
  • Underwriting questions. Tech E&O underwriting now routinely includes AI-specific questions about training data, deployment, customer disclosure, and governance.

Regulatory environment

  • EU AI Act. Comprehensive AI regulation creating compliance obligations for tech companies operating in the EU.
  • U.S. state AI laws. Several states have enacted AI-specific laws addressing automated decision-making, employment AI, and consumer protection.
  • Federal sectoral AI guidance. Sector-specific federal guidance from FTC, EEOC, FDA, CFPB, and other agencies addressing AI in their domains.
  • EEOC guidance on AI in employment. Specific guidance on disparate impact in AI-driven employment decisions.

The structural challenge

AI exposure crosses many existing coverage forms (tech E&O, cyber, D&O, EPLI, media liability, products liability) without sitting clearly in any single form. The structural challenge for tech insureds and carriers is determining which exposures sit where, which require dedicated AI coverage, and how policies coordinate when an AI event implicates multiple coverage forms simultaneously.

§ 09

Where IDP earns its keep

Tech company submissions are document-heavy, especially for late-stage and public companies. Investor pitch materials, financials, customer concentration data, contract templates, security documentation, employee count and compensation data, IP portfolios, M&A pipeline disclosures, AI model documentation. The variety creates IDP opportunity, particularly for the security and compliance documentation that has expanded substantially.

1
Intake
Tech submissions arrive with company financials, customer data, security documentation, employee data, IP portfolios, AI documentation.
2
Classify
Identify segment (SaaS, hardware, services, platform, fintech, healthtech, AI), funding stage, geographic operations.
3
Extract
Revenue and customer concentration, security control attestations, employee counts by location, IP portfolio summaries, AI use cases.
4
Validate
Cross-check financial data against pitch decks, verify security control attestations against frameworks, reconcile employee counts.
5
Triage
Generate normalized tech profile: segment, stage, customer profile, security posture, AI exposure, regulatory complexity.
6
Underwriter
Underwriter receives tech-ready data with stage and exposure flags surfaced.
Indico use cases for technology

Tech submissions include extensive structured documents: SOC 2 reports for security underwriting, ISO 27001 certifications, NIST framework attestations, penetration test reports, vendor questionnaire responses (often 100+ pages), security architecture documentation, AI model documentation, customer contract templates with insurance and indemnification terms, employee data exports for EPL underwriting, IP portfolio summaries, M&A diligence materials. Cyber submissions in particular generate consistent document categories that are heavy IDP targets. Late-stage and public tech companies also have public disclosure documents (10-K, 10-Q, S-1) that flow into D&O underwriting through structured extraction.

Chapter 50 · Industry Verticals · 22 min read

Technology — Cheat Sheet

Technology insurance is built around the product or service the company sells. SaaS, hardware, services, marketplaces, fintech, healthtech, and AI companies all carry technology E&O combined with cyber and (depending on stage) D&O. Programs evolve through the funding lifecycle: seed-stage tech companies carry minimal coverage, Series A and B add D&O and cyber, IPO-stage companies carry full management liability stacks. The AI-driven products of the current cycle have introduced new exposure categories that carriers and insureds are working through together.

The mental model: Tech insurance evolves with the company. A seed-stage SaaS company and an IPO-stage SaaS company are different insurance buyers, even if they sell similar products. The underwriting questions, the coverage purchases, the limit decisions, and the carrier selection all shift with stage. Carriers that specialize in tech build practice areas around the lifecycle.

Key terms

Tech E&O · Technology Errors and Omissions liability
Combined form · Integrated tech E&O and cyber liability form
Side A coverage · D&O coverage protecting individuals when company cannot indemnify
DIC · Difference-in-Conditions D&O coverage
NPE · Non-Practicing Entity (patent troll)
Section 230 · Communications Decency Act platform liability protection
EU AI Act · Comprehensive EU artificial intelligence regulation

If you remember three things

Tech insurance is built around what the company sells and evolves through funding stages, with seed-stage carrying minimal coverage and IPO-stage carrying full public-company D&O stacks. Technology E&O combined with cyber forms the foundational coverage, with customer indemnification obligations and contract requirements driving limit decisions. AI has introduced new exposure categories that cross multiple existing coverage forms and continue to evolve through carrier endorsements, exclusions, and emerging dedicated AI products.