SaaS Indemnity

LinkedIn
X
WhatsApp
Facebook
Email
Print

A SaaS cloud platform under a layered umbrella of insurance policies protecting the data beneath, illustrating SaaS technology and cyber insurance. Aber Law Firm.

Short answer: insurance is a form of indemnity, a way to shift risk by contract. A SaaS company should carry commercial general liability, workers’ compensation, auto, and umbrella coverage, but most important is technology insurance (data breach, bug/glitch, and errors and omissions), because standard policies do not cover intangible losses like data and information.

Every SaaS company should have insurance, like any business. But there are a few differences worth knowing, because the standard policies miss exactly the risks a software business runs.

1. Commercial General Liability.

This protects against claims for bodily injury, property damage, and personal and advertising injury. The catch: it generally covers only tangible property damage. Your CGL policy does not cover intangible loss like data and information, which is most of what a SaaS company actually risks. Get it, but do not expect it to do much for your core exposure.

2. Workers’ Compensation, Auto, and Umbrella.

  • Workers’ compensation: covers on-the-job employee injuries, required by state law, usually not a big issue for SaaS.
  • Auto: covers company vehicles. You know this one.
  • Umbrella: fills gaps and increases the limits of your other policies.

3. Technology Insurance (the One That Matters).

This is where it gets interesting, and where SaaS companies should focus. These products are newer and evolving fast, with little consistency between policies, so read them closely. Three questions to ask:

  • Do you store or process sensitive or personal information (health, financial, Social Security, or driver’s-license data, and do you encrypt in transit and at rest, and who holds the key)? If yes, look hard at data breach insurance. The FTC’s data security guidance is a good baseline for what “reasonable” looks like.
  • Could a bug in your service cause real harm to customers or third parties? If yes, look at coverage for bugs or glitches (it exists).
  • Do you perform professional services (implementation, integration, consulting)? If yes, look at errors and omissions coverage. Note it typically covers services performed by people, not your software itself, though that is changing.

The Insurance Information Institute has a plain-English overview of cyber coverage worth reading before you talk to a broker. What these policies cover, and do not cover, really matters, so do not assume the label tells you the scope.

Making Insurance and Your Contract Line Up.

Buying the right policy is only half the job. The other half is making sure your insurance and your SaaS agreement tell the same story, because a mismatch is where vendors get hurt. Match the cap to the coverage. If your customer pushes your liability cap up to, say, two million dollars for a data incident, your technology policy should carry limits that actually reach that number, or you are personally exposed for the gap. Read the insurance clause the customer hands you. Enterprise buyers often paste in required coverages and limits. Confirm you can actually buy what they demand before you sign; agreeing to a coverage you do not carry is a breach waiting to happen. Watch additional-insured and waiver-of-subrogation requests. These are common and usually fine, but they should track what your broker can deliver. Keep your carve-outs aligned. The losses you exclude from your liability cap (typically your indemnity for IP infringement and your breach of confidentiality) are exactly the ones you want a policy behind. Run the insurance clause and the limitation of liability side by side, ideally with your broker and your lawyer in the same conversation. When the cap, the carve-outs, and the policy limits line up, a covered claim is also a capped one, and that is the whole point.

Frequently Asked Questions.

Does my general liability policy cover a data breach? Usually not. CGL covers tangible property damage and bodily injury, not loss of data or information. For breach exposure you need dedicated technology or cyber coverage.

What technology coverage should a SaaS company prioritize? Data breach coverage if you hold sensitive data, bug/glitch coverage if a defect could cause real harm, and errors and omissions if you sell professional services. Match the policy to your actual risk.

How does insurance relate to the indemnity in my contract? Insurance and indemnity both shift risk. Your contract allocates and caps liability; insurance funds what lands on you. You want them to line up so a covered claim is also a capped one.

Insurance shifts some risk, but the indemnity itself gets drafted and capped in your SaaS agreement, and getting that balance right for the vendor is core to what we do. For the basics, see 4 Things to Know About SaaS Indemnities, and on where indemnity sits against your cap, your limitation of liability. I hope this helps.

Disclaimer:

This post is for informational and educational purposes only, and is not legal advice. You should hire an attorney if you need legal advice, which should be provided only after review of all relevant facts and applicable law.


Discover more from Aber Law Firm

Subscribe to get the latest posts sent to your email.

Free initial Consultaion

Get started with a free initial consultation. Fill out the form below to connect with our experts today!