One bad update, and it's on every device at once
You ship to thousands of devices at once, so a mistake doesn't stay small. An update might corrupt local data, a payment bug might hit on the busiest day of the year, or a third-party SDK might leak more than it should. Whatever it costs the client or their users, the developer is where the claim lands. Professional indemnity and cyber cover, built for app development.
Where an app developer actually gets exposed
It's rarely a headline hack. It's the ordinary risk of shipping to every user at once: a bug that reaches the whole install base before anyone notices, or a third-party library that behaves badly with real user data. Standard business insurance doesn't touch it.
The update that corrupted local data
You ship an update to a client's app. A migration bug corrupts locally stored user data on install, with no clean way to recover it.
Reviews turn negative within hours, the client's app store ranking drops, and they hold you responsible for the update.
The payment bug on the busiest day of the year
A rounding error in the in-app purchase flow you built double-charges customers during a client's flagship sales event. Chargebacks, refunds and complaints follow immediately.
The client wears the reputational hit and passes the remediation cost back to you.
The SDK that leaked user data
A third-party analytics SDK embedded in the app you built exposes device and personal data beyond what it should collect. The app is pulled from the store while it's fixed, and under the Privacy Act your client has to notify affected users.
They say your build was the cause and look to you for the response costs.
Who's going to ask you for it
The contract won't start without it
For app developers, cover is usually a condition of the build agreement:
- Agency and brand contracts commonly require $1M–$5M professional indemnity before a build begins.
- Enterprise and franchise clients set minimum PI and cyber limits given the scale of the install base.
- Recruitment and contracting agencies won't place you on a client project without a current certificate of currency.
The exclusion app developers assume is covered
Two things catch developers out. First, "the client is liable to their users, not me": the client's own contract with you usually passes that liability straight back to the developer who built the app.
Second, known vulnerabilities in bundled libraries: if you were already aware an SDK had a flaw and shipped it anyway, a resulting claim is typically excluded, even though you didn't write the vulnerable code yourself.
Common questions
A bug came from a third-party SDK, not my own code. Am I still liable?
Usually yes, contractually. Your client engaged you to deliver a working app, and the client's users don't distinguish between your code and a library you chose to include. If you didn't already know about the flaw, ICT cover responds.
Isn't this just professional indemnity?
PI is the core, but app development carries real cyber exposure. Mobile apps routinely request device permissions and personal data. ICT cover combines professional indemnity with cyber and tech-specific extensions so there isn't a gap between policies.
What limit should I get?
Match it to your contracts. Read the insurance clause in the client's build agreement. It will name a minimum, often $1M–$5M. If you're unsure, we'll read it with you before you buy.
Does it cover an app I built before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's worth having cover in place before a dispute surfaces.
A client wants a certificate of currency. How fast can I get one?
Once you're bound, a certificate is quick to issue. If a build is waiting on it, tell us and we'll prioritise it.