Choosing a company to build your software is one of the most consequential business decisions you'll make — and one of the hardest to evaluate, especially without a technical background. The difference between a good partner and a bad one can be the difference between a product that ships and is maintained, and a stalled project you end up paying for twice. This guide summarizes what to ask and the signs that warrant caution.
The Red Flags
Some signals are worth pausing on before you sign anything:
- An unrealistically low price: good development costs money, and the far-cheaper bid is usually recovered later through change fees or low quality.
- Vague promises with no detail: 'we'll build everything for you' with no written scope or clear delivery milestones.
- Refusing to share code ownership or repository access during development.
- No mention of testing, security, or post-launch — as if the project ends at delivery.
- Hard-to-reach or slow to respond during pre-sales — it only gets worse after the contract is signed.
Fixed-Price vs. Time & Materials
There are two common contracting models, and each has its place:
- Fixed-price: suited to projects with a fully defined, well-understood scope. It gives you budget certainty but assumes requirements won't change — and any change becomes a new negotiation.
- Time & materials: you pay for actual effort, best for evolving or not-fully-defined products. It demands more trust and transparency but is more flexible and realistic for most digital products.
Code Ownership and Post-Launch Support
This point is often overlooked until it's too late. Make sure the contract states explicitly that code ownership and intellectual property transfer fully to you upon payment, and that you hold repository and deployment-account access from the start — not at the end of the project. And ask about the post-launch support model: who fixes bugs, with what response time, and at what cost? A product with no maintenance plan is deferred debt.
Questions to Ask
- Do I own the code and IP fully, and when do they transfer to me?
- How do you handle testing and security — is there code review and vulnerability remediation?
- What's the communication cadence: regular reports, meetings, a single point of contact?
- What happens after launch — what are the maintenance, support terms, and response times?
- Can I see past work or speak to former clients?
Looking for a transparent development partner that puts your code ownership and security first? Email us at [email protected] to discuss your project openly and with no obligation.