Fundraising7

What My Tech E&O Policy Actually Covered When a Client Sued Us Over a Bug

A client's SLA claim after our export bug taught me the difference between what a tech E&O policy promises and what it actually pays out.

Table of contents

  • The bug that started it
  • The claim letter
  • What the policy paid for
  • The clause that almost sank the claim
  • What I checked before the next renewal
  • Frequently asked questions

Eleven months after we signed our biggest enterprise contract, a scheduled export job silently failed for six days and the client's finance team closed their books on numbers that were wrong. They sent a claim letter before they sent an email asking what happened. That's when I found out what my tech E&O policy actually covered, and what it didn't.

The bug that started it

We'd shipped a change to a nightly export job that fed our client's reconciliation system. A timezone conversion bug meant the job silently skipped a batch of records instead of failing loudly. Nobody on our side noticed because the job reported "success" either way. Nobody on their side noticed until their monthly close was off by a number large enough to trigger an audit review.

By the time their controller found the gap and traced it back to our export, six days of records were missing and their finance team had already reported numbers up to their board. Their outside counsel sent a letter two weeks later. It didn't ask for an apology. It asked for the cost of the re-audit, the cost of restating the numbers to their board, and a reservation of rights to pursue "further damages."

The claim letter

I'd bought tech E&O insurance eighteen months earlier because our first enterprise MSA required it, the same way most founders end up buying it: a procurement checklist item, not a considered decision. I'd never actually read past the declarations page.

The first thing I learned is that tech E&O is written on a claims-made basis, which means the policy that matters is the one active when the claim is reported, not the one active when the bug shipped. I reported the letter to my broker the same day it landed, which turned out to matter more than anything else in the process. Tech E&O policies almost always require "as soon as practicable" notice, and a carrier can deny a claim purely for late reporting even if the underlying facts would otherwise be covered.

Within a week the insurer assigned defense counsel, a firm I'd never spoken to, paid for entirely under the policy. That's the part nobody explains to founders ahead of time: your first real interaction with your E&O policy usually isn't a check, it's a lawyer.

What the policy paid for

The claim settled four months later, well short of trial. Here's what the policy actually paid for, in order.

Defense costs from day one. Every hour of outside counsel's time, from the first response letter through settlement negotiation, came out of the policy's defense limit, not my pocket, and didn't require me to front the cost and get reimbursed later.

The settlement itself. The client's demand covered the direct cost of the re-audit and the cost of restating the reported numbers. Both fell squarely inside "damages arising from a failure of the insured's professional services to perform as represented," which is the core insuring clause on almost every tech E&O form.

What it explicitly did not touch: the client's initial demand also included a line for "reputational harm to our finance function," essentially a claim for embarrassment in front of their board. That line got dropped in negotiation, not because the policy would have paid it if it survived, but because it was never going to hold up as a quantifiable damage in the first place. Tech E&O covers financial loss the client can show a number for, not how bad the bug made them look.

The clause that almost sank the claim

The MSA we'd signed with this client included an indemnification clause I'd agreed to without pushing back, the kind every enterprise legal team asks for as boilerplate. It obligated us to cover the client's losses from our own negligence, uncapped, separate from whatever liability we'd owe them anyway.

My insurer's coverage counsel flagged this clause almost immediately. Standard tech E&O covers what you'd owe a client under ordinary professional negligence rules. It does not automatically cover liability you voluntarily took on by signing an indemnification clause that goes beyond that baseline, unless you specifically bought a contractual liability endorsement. I hadn't.

We got lucky here in a narrow, specific way: the claim as it was actually pursued fit within ordinary negligence liability, so the indemnity clause never had to be tested. If the client's counsel had structured the demand around the contract's indemnity language instead of a straightforward negligence claim, my insurer's obligation to pay would have been a real fight, and possibly a losing one. I didn't understand that distinction existed until coverage counsel explained it to me mid-claim, which is the worst possible time to learn it.

What I checked before the next renewal

At renewal, three months after the claim closed, I went through the policy line by line with my broker instead of forwarding the certificate request like I had every year before. Three things changed.

  1. We added a contractual liability endorsement so the indemnification language in our current MSAs is actually backed by the policy, not just assumed to be.
  2. We confirmed our retroactive date carries over from our original policy, so switching carriers at renewal doesn't quietly wipe out coverage for work done before the switch.
  3. We raised our per-claim limit. The settlement in this claim came in under our old limit, but the defense costs alone ran higher than I'd budgeted for, and defense costs erode the same limit that pays the settlement on most policies.

None of these cost much to fix in advance. All three would have cost a great deal to discover for the first time during an active claim, which is exactly how I found out about the first two.

Frequently asked questions

Does tech E&O insurance cover a lawsuit from a client?

Yes, when the claim alleges your product or service failed to perform as represented and caused the client financial loss. It covers both defense costs and settlement or judgment amounts, subject to your policy's limits and exclusions.

How fast do I need to report a claim to my E&O insurer?

Immediately, or "as soon as practicable" per your policy's language. Tech E&O is claims-made coverage, and late reporting is one of the most common reasons carriers deny claims that would otherwise be covered.

Will tech E&O pay for a claim tied to an indemnification clause in my contract?

Not automatically. Standard policies cover liability you'd owe under ordinary negligence, not liability you voluntarily assumed by signing an indemnity clause, unless you've added a contractual liability endorsement.

Do defense costs count against my coverage limit?

On most tech E&O policies, yes. Defense costs and the settlement or judgment draw from the same limit, so a long, expensive defense can leave less available to actually resolve the claim.

What's the one thing to check on my policy before I ever need to file a claim?

Whether your contractual liability is actually endorsed to match the indemnification language you've signed in client contracts. It's the gap that surfaces at the worst possible time, and it's inexpensive to fix before you need it.

The certificate of insurance your enterprise clients ask for confirms a policy exists. It says nothing about whether that policy actually backs the promises you made in the contract next to it. Read your indemnification language and your E&O policy side by side before you need them to agree with each other, not after.

Read enough.
Ready to grow?

19 spots in the cohort. Applications open now.