Web Designer and Software Developer Insurance
Nothing in this work can fall on anybody or catch fire, which is exactly why the insurance for it looks nothing like a trade policy and why so many developers carry the wrong one.
Nothing Breaks, And It Still Costs Them
The claims are financial. A project that ran months late and cost the client a launch. A site that went down during their busiest trading week. A platform you built that was breached, with their customers' data in it. An image, a font or a block of library code used without the right licence. In every case nothing was physically damaged and the client is out of money, which is professional indemnity territory rather than public liability.
This page is for the people who build: web design, web development, software, apps and integrations. If you advise on systems and strategy rather than building them, that is IT consultancy and it has its own page.
What Web Designer & Developer Insurance Covers
Professional indemnity
The core cover. Answers a claim that your work was negligent and cost the client money: a failed project, a site that did not do what was specified, a performance problem, or advice that turned out to be wrong. It pays the defence as well as any settlement.
Cyber and data breach
Two separate exposures. Your own, where you are compromised and client work or credentials are taken. And theirs, where a site or platform you built is breached and their customers' personal data is exposed, which brings a UK GDPR dimension as well as a contractual one.
Intellectual property infringement
Images, fonts, music, stock assets and library code used beyond their licence. It is one of the commonest claims in this trade and it is usually inadvertent, which makes no difference to the rights holder.
Breach of contract and project overrun
Worth checking specifically, because a straightforward failure to deliver on time is a contractual breach rather than negligence, and some policies respond to it while others do not.
Employers' liability
Compulsory from the first employee at a £5 million statutory minimum, which catches agencies the moment they take on a second person. Contractors you direct may count.
Public liability and contents
Small beside the rest and still needed if you have an office, clients visit, or you work on client premises. Covers the laptops and equipment too.
Run-off cover
Because professional indemnity is claims made, closing the business without run-off leaves every project you ever delivered unprotected.
Where The Cover Stops
Wordings differ between insurers, so treat these as the usual position rather than as universal fact. Where one of them matters to you, it is worth checking on your own schedule before you need to.
Claims made, not when you built it
The policy in force when the claim is made responds, not the one in force when the project shipped. A gap in cover can leave a claim about a two year old build with nothing behind it, and the retroactive date on a new policy may exclude everything before it.
Guaranteed uptime and performance promises
Professional indemnity covers negligence. A contract promising a specific uptime percentage, a load capacity or a search ranking is a warranty rather than a professional standard, and warranties sit outside most cover.
Third party platforms and dependencies
When a host, a payment provider, a plugin or an API causes the loss, your policy is not usually the right route and your contract may still put the client's loss with you. The gap between those two positions is worth closing in the contract.
Open source licence conditions
Using copyleft licensed code in a client's proprietary product can create an obligation nobody intended. It is a licensing failure rather than a defect, and cover for it varies.
Fines and penalties
Regulatory fines are frequently uninsurable as a matter of law. Where a data breach on a site you built leads to enforcement against your client, your exposure is the loss they suffer rather than their penalty.
Work on a client's live systems
A deployment that takes down a production system is a realistic incident and the loss is their trading, not your code. Check how business interruption suffered by a client is treated, because it is often sub-limited.
The Specification Is The Only Defence
Almost every dispute in this trade is a disagreement about what was promised, and the party without a written scope loses it.
Projects in this work change constantly, which is normal and healthy, and it means the thing delivered is rarely the thing first discussed. Where the scope was a conversation and an estimate, a client who is unhappy months later has a straightforward story: this is not what I asked for. Where it was a written specification with change requests signed off as they arose, the same client has a much harder argument.
So keep the paper. A written scope, a change log, the sign offs, and a record of what the client declined on cost grounds. It is also worth being explicit about what you are not doing: who hosts it, who maintains it, who is responsible for updates and backups after handover. Silence on those is how an abandoned site becomes your problem two years later.
Their Data Breach, Your Build
This is the exposure that has grown fastest and that most developers have thought about least.
If you built or maintain a site holding customer records, orders or payment details, a breach of it is first your client's problem and very quickly your conversation. They will ask whether the vulnerability was in your code, your configuration, a component you selected or an update you did not apply. Where you host or maintain, the question sharpens considerably: an unpatched content management system on a server you manage is difficult to argue about.
Practically, that means being precise in the contract about who is responsible for updates, patching and backups after launch, and keeping evidence that you did what you took on. It also means having cyber cover that reaches the client's loss rather than only your own, because professional indemnity and cyber overlap here and the gap between them is where these claims fall.
Intellectual Property Is The Quiet One
Nobody expects the claim to arrive from a stock photo agency, and a surprising number do.
The failure modes are mundane. An image used beyond its licence or carried over from a mock-up into the live site. A font licensed for desktop use embedded on a web page. Library or template code used in a commercial product outside its terms. A client's competitor's copy pasted in as placeholder and never replaced. None of it is deliberate and all of it is actionable, and the demand often arrives from a rights enforcement business rather than the creator.
Keep the licences with the project files, not in somebody's inbox. Where a client supplies assets, get written confirmation they have the rights, because the usual answer is that they found them online. And on open source, know which licences are in what you ship, since copyleft code inside a client's proprietary product creates an obligation they did not agree to.
Freelancers, Agencies And Who Carries It
Much of this work moves through chains: a client appoints an agency, the agency uses freelancers, a freelancer uses a specialist. Each link assumes somebody else is insured.
If you are a freelancer working through an agency, do not assume their policy covers you. It protects them, and your contract with them frequently passes liability down and sometimes includes an indemnity in their favour. A great many agencies now require freelancers to hold their own professional indemnity at a stated limit before they will place work, which tells you how the agencies themselves see it.
If you are the agency, take copies of the freelancers' certificates and check the dates against the project, for the same reason a main contractor checks a subcontractor's. And look at the limit your client contracts require before you accept them, because enterprise and public sector clients commonly specify figures well above what a small studio carries by default.
How To Choose A Broker As A Web Or Software Developer
This is widely quoted and largely misunderstood: plenty of policies are sold to developers as office cover with a professional indemnity section bolted on. We are an FCA regulated broker and will not tell you we are the best choice. These are the questions that decide it.
Does it answer a breach of a system you built, not just your own?
Two different exposures get conflated constantly. Your own compromise is one thing; a client's customers' data exposed through a site you built is another, and a cyber policy written for your own office may not reach it.
Is intellectual property infringement included?
One of the commonest claims in this trade, usually inadvertent, and frequently absent from a policy sold as professional indemnity. Ask directly rather than assuming.
How is a project overrun treated?
A plain failure to deliver on time is contractual rather than negligent, and policies differ on whether they respond. Given how many disputes here are about delay, it is worth establishing.
Did they explain claims made and the retroactive date?
The policy that responds is the one in force when the claim is made, not when the project shipped, and a new policy may exclude everything before the retroactive date. A broker who has not raised it has not explained the cover.
Does the limit meet your client contracts?
Enterprise and public sector clients commonly specify limits well above a small studio's default. Worth checking before you sign the contract rather than after you win the work.
Will somebody read a client contract or an MSA?
Uptime guarantees, uncapped liability and indemnity clauses in favour of the client are where avoidable exposure enters an agency. All amendable before signature.
Factually, here is what we do against those questions. We separate your own cyber exposure from a breach of something you built and make sure both are addressed, we check that intellectual property infringement is actually included rather than assumed, we tell you how your policy treats delay and overrun, we explain claims made and check the retroactive date carries across when cover moves, and we will read a client contract or master services agreement before you sign it. We are a broker, so it goes to several insurers rather than one.
If your work is advising on systems and strategy rather than building them, our IT consultants page is the better fit, and we will say so rather than quoting the wrong product.
What Moves The Price
Every policy is priced on the business behind it. These are the things that move the premium:
- The limit of indemnity your client contracts require
- Annual fee income and the size of your largest project
- Whether you host or maintain what you build
- Whether any work involves payment processing or health data
- Ecommerce and platform work against brochure sites
- Whether contracts include uptime or performance guarantees
- The retroactive date and how many past years are covered
- Claims, complaints and any notified circumstances
We are a broker, so we take it to several insurers rather than quoting one. Call 02382 000820 for a quote.
What We Need To Quote
- What you build: websites, software, apps, integrations, platforms
- Whether you host, maintain or patch after handover
- Annual fee income and your largest client and project by fee
- Whether you handle payment, health or other sensitive data
- The limit of indemnity required, and who requires it
- Whether you use freelancers, and whether they hold their own cover
- The retroactive date on your current policy
- Any claims, complaints or circumstances in six years
Cover that often goes with this
The gaps we most often find sitting next to this policy.
- IT consultantsAdvising on systems rather than building them.
- Cyber insuranceYour own breach, and a breach of what you built.
- Professional indemnityHow claims made works, and the retroactive date.
- Insurance for professionalsThe wider hub, including run-off.
- Legal expensesRecovering unpaid fees, which indemnity does not cover.
- Talk to a brokerSend us a client contract or MSA before you sign it.
Common questions
What insurance do web designers and developers need?+
Professional indemnity first, because the claim that happens is financial: a project that overran, a site that did not do what was specified, or advice that was wrong, with nothing physically damaged. Then cyber, and in two directions rather than one: your own compromise, and a breach of a site or platform you built where your client's customers' data is exposed. Add intellectual property infringement, which is one of the commonest claims here and often inadvertent. Employers' liability is compulsory from the first employee at a £5 million statutory minimum, and public liability and contents if you have an office or visit clients.
Am I liable if a website I built gets hacked?+
Possibly, and it depends heavily on what you took on. The first questions will be whether the vulnerability was in your code, your configuration, a component you chose, or an update that was not applied. If you host or maintain the site, your position is harder: an unpatched content management system on a server you manage is difficult to argue about. If you handed over at launch and the client took on maintenance, the exposure is much lower, provided that is what the contract says. Which is the point: be explicit in writing about who is responsible for updates, patching and backups after handover.
Do I need professional indemnity as a freelance web developer?+
In practice yes, and increasingly you cannot get work without it. Do not assume an agency's policy covers you: it protects them, and the contract between you frequently passes liability down and sometimes contains an indemnity in their favour. A great many agencies now require freelancers to hold their own professional indemnity at a stated limit before placing work, which tells you how they read the risk. Check the limit the agency or end client specifies rather than buying the smallest available, because enterprise and public sector contracts often require considerably more.
Does my insurance cover using an image or font without a licence?+
It should, under intellectual property infringement cover, but check it is actually included because it is frequently absent from policies sold as professional indemnity. These claims are mundane and common: an image used beyond its licence, a font licensed for desktop embedded on a page, template or library code used outside its terms, or a client's supplied asset they did not actually own. Keep licences with the project files, and get written confirmation from clients that they hold the rights to anything they supply, because the honest answer is usually that they found it online.
Who insures web designers and software developers in the UK?+
It is widely available and widely misunderstood: a good deal of what is sold to developers is office cover with a professional indemnity section attached, which leaves the real exposures uncovered. Several insurers write it properly and many are reached through brokers rather than direct. What separates placements is whether cyber reaches a breach of something you built rather than only your own systems, whether intellectual property infringement is included, how delay and overrun are treated, and whether the limit meets the contracts you want to sign.
Is this the same as IT consultant insurance?+
Related but not the same, and it is worth landing on the right one. This page is for people who build: web design, development, software, apps and integrations, where the claim is that what you made did not work or did not arrive. IT consultancy is advisory work, where the claim is that the advice or the system selection was wrong, and we cover that on our IT consultants page. Plenty of businesses do both, in which case the schedule needs to describe both rather than letting one stand in for the other.
What if a client says the project was late and refuses to pay?+
Two separate things, and it is worth separating them. Recovering your fee is a legal expenses matter rather than a professional indemnity one. Their counterclaim that the delay cost them money may be professional indemnity, or may not: a plain failure to deliver on time is a contractual breach rather than negligence, and policies differ on whether they respond to that. Given how many disputes in this trade are about delay, establish which yours does before you need it. What decides the outcome is almost always the paperwork: a written scope, a change log and signed-off change requests.
More food, drink and leisure we cover
What our customers say on Google
5.0average from 169 Google reviews
