We're considering using Freshservice from Freshworks, but our compliance team is concerned because Freshworks says it does not carry Errors & Omissions or Professional Liability Insurance. They do have Commercial General Liability and Cyber Liability coverage, but apparently that coverage is primarily for Freshworks itself. If a breach or service failure affected sensitive data in our instance and caused financial losses for our company, we may not have any direct insurance protection from the vendor. Are we being overly strict by requiring E&O coverage, or is this a reasonable vendor-risk requirement?
3 Answers
It’s not unreasonable to ask, especially if the platform will handle sensitive information or support important operational processes. However, insurance is only one part of the evaluation. Carefully review the liability caps, indemnification language, breach obligations, security commitments, and exclusions in the contract. The key question is who is financially responsible if the service fails or the vendor’s actions contribute to a loss.
This is ultimately a risk-based business decision. Start by assessing what data and workflows would live in the system, the potential cost of a service failure or breach, and how likely those events are. Then decide whether the exposure is acceptable without vendor E&O coverage or whether you need another control, such as stronger contract terms or additional insurance on your side.
If the vendor cannot meet the insurance requirement, you can either document an exception with approval from the business risk owner or look for an alternative provider whose coverage and contract terms fit your requirements. Don’t waive the requirement automatically—first quantify the exposure and determine whether your own insurance can cover the gap.

Their Commercial General and Cyber Liability policies may protect Freshworks, but that does not necessarily reimburse your organization for losses caused by an incident involving your account. I’d have legal and risk management review the actual policy and contract language rather than relying on the coverage labels alone.