Viewee
Start free
Pricing
Sign in
← Legal and assurance

Decision brief - 16 September 2026

Bottom line

Viewee should buy a combined technology professional indemnity (tech PI / technology E&O) and cyber policy before any live pilot receives identifiable care-sector feedback, not wait for the first paid customer. The policy should cover both Viewee's own breach response costs and third-party claims arising from security, privacy, software or service failure. For the first pilot, ask for quotes at £1m tech PI and £1m cyber. Treat £500k as a fallback only if the pilot customer accepts it. £2m may be needed when a larger care group's contract requires it.

Care-sector feedback is not automatically special-category data, but free text can reveal health, disability, ethnicity, religion or sexual orientation. Underwriters should therefore be told that Viewee may process identifiable feedback that includes health and safeguarding-related information. Do not describe the dataset as generic survey data.

ItemRecommended starting positionWhy it matters
StructureCombined tech PI / E&O plus cyber, preferably one coordinated wordingReduces gaps and disputes when a software failure causes a privacy incident
Tech PI limit£1m each claim; quote £2m as an optionCovers client financial loss from errors, outages, failed implementation, breach of contract/confidentiality and negligent service, subject to wording
Cyber limit£1m aggregate; quote £2m as an optionGives meaningful headroom for incident response, legal advice, notification, restoration, interruption and third-party privacy/network claims
ExcessCompare £500, £1,000 and £2,500A higher excess may reduce premium but must remain affordable during a crisis
Incident response24/7 hotline; insurer-funded forensic, legal, PR and notification support from discoveryThe ICO reporting clock can be 72 hours, so immediate expert access matters
Business interruptionInclude cloud/system interruption and dependent-provider interruption if availableViewee depends on hosting and other cloud services
Privacy liabilityInclude regulatory defence/investigation and civil claims; check treatment of fines "where insurable by law"Fines are not the main reason to buy; defence, investigation and response costs are more dependable benefits
Contract fitWorldwide territory/jurisdiction as needed, defence costs wording, subcontractors, IP/media, confidentiality and retroactive dateThese are common areas where a certificate's headline limit can hide gaps
Security representationsOnly state controls that are actually operating and documentedNCSC warns inaccurate security information can jeopardise a claim

1. What cover matters and where cyber and tech PI overlap

Cyber liability

Cyber should pay Viewee's first-party costs after an incident: forensic investigation, containment, data/system restoration, specialist legal advice, notification and affected-person support, PR/crisis management, cyber extortion response where covered, and business interruption. It should also cover third-party liability: defence and damages arising from privacy breaches, loss of personal data, or failure of network security.

This matters before revenue. An incident can create forensic and legal costs even when no customer has paid and no one sues. The ICO says a reportable personal-data breach must be reported without undue delay and within 72 hours of discovery. NCSC says cyber insurance can support recovery, legal/regulatory action and incident-response services, but is not a substitute for basic security.

Professional indemnity / technology E&O

Tech PI protects against a customer alleging that Viewee's software or professional service caused financial loss. For Viewee this includes defects, inaccurate or unavailable outputs, failed implementation, missed specifications, negligent advice, breach of confidentiality, and some IP/media claims where included. Ordinary consultant PI can be too narrow. The activity description and wording should expressly cover SaaS/software development, hosting or provision, data processing and professional services.

The overlap

The same event can trigger both. Example: a software defect exposes resident feedback. Viewee incurs forensics and notification costs (cyber), while the care group claims breach of contract, confidentiality and business loss (cyber third-party liability and/or tech PI). A combined wording with one insurer or coordinated broker placement is preferable because it can reduce arguments over which section responds. Check whether the policy has one shared aggregate limit. A £1m + £1m certificate may still provide only £1m total if the limits are shared.

2. Credible UK options for an early-stage tech company

These are a shortlist for quotations, not endorsements. Compare actual wording and insurer security rating, not just the broker's website.

OptionRouteBest use for VieweeEvidence status
PolicyBeeUK small-business broker with online quote routeFast baseline quote; publishes SaaS-specific PI and cyber examplesVerified from provider pages
SuperscriptUK broker / digital platform with advised serviceStartup-friendly route and useful when contract requirements need advice rather than a simple online purchaseVerified from provider page
Marsh CommercialUK commercial broker with a technology practiceUseful second advised quote, especially when larger client limits and contract review matterVerified from provider page
CapsuleUK specialist broker focused on high-growth businessesWorth asking for a combined tech/cyber placement that can scale with investment and enterprise customersVerified as specialist provider; exact Viewee terms require quote
Get IndemnityUK digital commercial insurance brokerHas a SaaS / technology E&O package; useful for comparing combined wordingVerified from provider page
CFCSpecialist cyber/technology insurer, usually accessed through a brokerStrong cyber specialism and incident-response proposition; ask brokers whether CFC will quote at Viewee's stageVerified as market option; eligibility/price unverified until quote
CoalitionSpecialist cyber insurer offering UK technology/cyber coverage through brokersUseful comparison for active cyber monitoring and coordinated tech E&O/cyber coverVerified from provider pages; eligibility/price unverified until quote
Hiscox UKDirect insurer / broker channelRecognised direct-market comparison for cyber and data cover; test wording against specialist combined optionsVerified from provider page

Suggested quote process: ask PolicyBee and Superscript for quick benchmarks, then ask one specialist broker (Capsule, Get Indemnity or Marsh Commercial) to compare combined wordings including CFC/Coalition where available. Use the same completed fact sheet for every quote.

3. Premium and cover benchmarks

Verified published anchors

Viewee planning estimates

Stage / limitWorking annual budgetConfidence
Minimal £100k PI + £100k cyberRoughly £225+ at advertised floorsVerified floor, but likely inadequate for care-group due diligence and not a Viewee quote
Pre-revenue / pilot, £500k each£700-£1,500Estimated
Pre-revenue / pilot, £1m each£1,000-£2,500Estimated; recommended quote target
Early paid customers, £2m each£1,800-£5,000+Estimated; depends heavily on contracts, data and controls

The estimates deliberately sit above mass-market advertised floors because Viewee may process identifiable care-sector free text that reveals health or safeguarding information. Actual prices may fall outside these ranges. Only broker/insurer quotations can verify the premium.

What pushes price up

Before quoting, document MFA, least privilege, encryption, backups, logging, vulnerability/patch process, secure development, incident response, retention/deletion, staff training, subcontractors, hosting location, expected record volumes and whether feedback is identifiable. Cyber Essentials can help with both underwriting and buyer confidence, but does not replace insurance.

4. What care-group due diligence will typically ask

There is no single care-group questionnaire. The list below is a practical synthesis of public-sector supplier assurance, NHS supplier guidance and common contract onboarding. The insurance section usually asks:

  1. Insurer, policy number, renewal/expiry date and certificate.

  2. Tech PI/professional indemnity, cyber, public liability and employers' liability limits.

  3. Whether limits are each claim or aggregate; whether defence costs sit inside or outside the limit.

  4. Excess/deductible and material sublimits, especially notification, forensics, interruption, ransomware and regulatory costs.

  5. Territorial and jurisdiction cover, retroactive date and how long PI cover will be maintained after the contract.

  6. Whether SaaS, software development, hosting, data processing, subcontractors and breach of confidentiality are within the insured business description.

  7. Claims, incidents or circumstances in the last three to five years.

  8. Whether the insurer can meet a proposed £1m or £2m contractual minimum and provide evidence before go-live.

The broader security and data questionnaire will still ask for evidence that insurance cannot answer: UK GDPR roles, data-processing agreement, subprocessor list, hosting/data locations, special-category lawful basis and Article 9 condition where relevant, DPIA support, retention/deletion, access controls and MFA, encryption, backups, penetration/vulnerability testing, secure development, incident response, breach notification times, business continuity/disaster recovery, staff training, Cyber Essentials/ISO 27001/DSPT status, audit rights and flow-down to suppliers.

NHS England's DSPT supplier guidance expects organisations to manage suppliers contractually and assess their data-security arrangements. The NHS supplier cyber charter also focuses on cyber standards and incident response. A certificate of insurance is therefore supporting evidence, not a substitute for a security pack.

Policy wording questions to answer before purchase

Ask the broker to answer these in writing:

5. When to buy

Buy before live-data pilot

For Viewee, the sensible trigger is before a pilot accepts identifiable or real resident/family/staff feedback. The risk starts when Viewee stores or processes the data, not when an invoice is issued. Buying before live processing also avoids a customer procurement delay and ensures an earlier retroactive date for claims-made PI/cyber wording.

A policy can wait only while the product uses synthetic, fully anonymised test data, has no external users, gives no advice/service under contract, and no pilot or customer requires a certificate. Even then, obtain indicative quotes early so security gaps or exclusions are found before go-live.

Practical sequence

  1. Now: prepare one accurate underwriting fact sheet and request matched £500k/£1m/£2m quote options.

  2. Before signing the pilot or receiving live identifiable data: bind £1m tech PI + £1m cyber unless the pilot terms support a different limit.

  3. Before the first larger care-group contract: compare the required limits and contractual liability cap against the policy; increase to £2m if required.

  4. At every material change and annual renewal: tell the broker about new data categories, record volumes, services, countries, large contracts, incidents and controls.

Do not let a contract promise broader liability than the insurance covers. Insurance requirements, indemnities, liability caps and exclusions should be reviewed together.

Caveats

Sources

  1. National Cyber Security Centre, "Cyber insurance guidance" (updated 28 July 2026): https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance

  2. Information Commissioner's Office, "72 hours - how to respond to a personal data breach": https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/72-hours-how-to-respond-to-a-personal-data-breach/

  3. ICO, "What is special category data?": https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/

  4. PolicyBee, "Insurance for SaaS developers": https://www.policybee.co.uk/insurance-for-saas-developers

  5. PolicyBee, "Cyber insurance": https://www.policybee.co.uk/cyber-insurance

  6. Marsh Commercial, "Technology company insurance": https://www.marshcommercial.co.uk/for-business/technology.html

  7. Superscript, "Startup insurance": https://gosuperscript.com/business-insurance/business-type/startup-insurance/

  8. Capsule, company and product overview: https://capsulecover.com/

  9. Get Indemnity, "SaaS insurance & technology E&O package": https://getindemnity.co.uk/saas-insurance

  10. CFC, cyber insurance overview: https://www.cfc.com/en-gb/products/cyber/

  11. Coalition, technology industry cyber cover: https://www.coalitioninc.com/en-gb/industry/technology

  12. Coalition, coverage overview: https://www.coalitioninc.com/en-gb/coverages

  13. Hiscox UK, cyber and data insurance: https://www.hiscox.co.uk/business-insurance/cyber-and-data-insurance

  14. Insure24, "How much does software company insurance cost in the UK?" (8 December 2025): https://www.insure24.co.uk/blog/how-much-does-software-company-insurance-cost-in-the-uk/

  15. UK Government, Cyber Security Model Supplier Assurance Questionnaire Level 1: https://assets.publishing.service.gov.uk/media/69aff1f4c78869bf8eb8a5bc/CSM_SAQ_Level_1_for_GOV.UK.pdf

  16. NHS England Digital, "Cyber security charter for suppliers to the NHS": https://digital.nhs.uk/cyber-and-data-security/guidance-and-resources/cyber-security-charter-for-suppliers-to-the-nhs

  17. NHS England Digital, DSPT guide, "Your suppliers and contracts": https://digital.nhs.uk/cyber-and-data-security/guidance-and-assurance/data-security-and-protection-toolkit-assessment-guides/guide-10---accountable-suppliers/your-suppliers-and-contracts/