Published
By Utshab Chakraborty, Founder & CEO, NextGen Coding Company · Technically reviewed by Dan Steinberg, Full-Stack Engineer
What is the fastest way to vet a software development company?
The fastest way to vet a software development company is to bypass sales reps and request an unscripted technical session with the lead engineers assigned to your build. Ask them to open an anonymized production repository, explain their CI/CD pipeline, and walk through how they resolved a major outage on a recent engagement.
If a vendor cannot show you real code or will not put senior engineers on a call without an account executive managing the conversation, drop them. Sales engineers are hired to close deals; staff engineers are hired to build software.
When you evaluate a software development company in the US, skip the standard questionnaire and focus on three immediate proof points:
- Production code samples: Ask to see anonymized pull requests, architectural decision records (ADRs), and database migration scripts. Look for clean commits, comprehensive inline documentation, and strict linting rules.
- Test coverage metrics: Inquire about their standard coverage thresholds. Teams that ship production software maintain unit test coverage above 80% and run automated end-to-end integration tests on every pull request.
- Deployment frequency: Ask how often they ship to production. High-performing engineering teams deploy multiple times per day using automated trunk-based pipelines, not once a month via manual FTP uploads or messy weekend releases.
How do you test a software agency's technical competence?
You test a software agency's technical competence by staging a mandatory technical review of your current architecture or product specification. Give their principal engineer a real problem—such as a failing PostgreSQL query, an API rate-limiting bottleneck, or an LLM context window cost challenge—and evaluate their live diagnostic process and data modeling logic.
Do not hand out take-home coding tests or generic whiteboard puzzles. Senior engineers reject contrived assignments, and weak agencies outsource them to junior developers off-contract. Instead, run a 90-minute working session structured like an internal engineering RFC (Request for Comments) review.
Step 1: Give them real system constraints
Provide a sanitized architecture diagram and a list of your actual operational headaches. This could be a legacy Monolith with 12-second database queries, an unmaintainable React codebase, or an AI feature that costs $4.00 per user invocation in OpenAI API calls.
Step 2: Debate the architectural tradeoffs
Listen closely to how they defend their choices. A junior team suggests rewriting everything in the latest framework. A senior engineering firm asks about your data volume, team structure, current AWS bill, and business runway before suggesting a single line of code. Look for teams that favor pragmatic patterns like modular monoliths over microservices overengineering.
Step 3: Inspect their observability standards
Ask how they monitor systems post-launch. A competent software partner sets up Datadog, OpenTelemetry, or Prometheus out of the box. They define structured logging conventions, alert on 99th-percentile latency spikes, and write runbooks for production incidents. If their monitoring strategy is "the user emails us when it breaks," walk away.
What red flags mean you should walk away from a dev shop?
You should walk away from a software vendor if they promise fixed-price contracts on open-ended scopes, refuse to name the engineers working on your account, lack automated CI/CD pipelines, or swap senior leads for junior contractors after contract signing.
The software development industry relies heavily on margin arbitrage: selling you senior US strategy at $180/hour while delegating execution to $25/hour offshore junior developers who have never deployed a system to production.
Watch out for these four operational red flags during procurement:
- The "Bait-and-Switch" staffing model: The engineers present during sales pitches are not the engineers working on your codebase. Require contract clauses that explicitly name your core developers and dictate minimum seniority levels.
- Fixed-price estimates for unbuilt software: Software requirements change the moment real users interact with a feature. Agencies that offer rigid, fixed-price contracts on broad requirements build to the baseline spec, ignore edge cases, and hit you with change orders for basic stability fixes.
- No automated test infrastructure: If an agency tells you that manual QA testing is faster or cheaper than writing automated Jest, Cypress, or PyTest suites, they are shifting technical debt directly onto your balance sheet.
- IP and repository hostage tactics: Your contract must state that all intellectual property, git repositories, deployment keys, and cloud infrastructure belong to you from Day 1. Never allow a vendor to host your code in their private GitHub organization or manage your AWS instance under their corporate account.
Fixed-price vs. time-and-materials: which contract structure protects your budget?
Time-and-materials (T&M) with capped sprint budgets and bi-weekly milestone sign-offs protects your budget better than fixed-price contracts. Fixed-price contracts incentivize vendors to write the absolute minimum amount of code required to pass superficial acceptance criteria, sacrificing maintainability, speed, and test coverage to protect their margins.
Fixed-Price Risk Loop:
Scope Creep -> Contract Dispute -> Vendor Cuts Code Quality -> Broken Software Released
For software projects budgeted between $120,000 and $500,000, structure your contract using these financial safeguards:
- Two-week sprint billing: Pay against delivered, working software at the end of each 14-day cycle. If sprint delivery stalls or code quality drops, you pause the contract immediately without burning six figures.
- Defined team composition: Require fixed weekly rate cards based on dedicated engineering hours (e.g., 2 Senior Full-Stack Engineers + 0.5 Staff Architect + 0.5 Lead QA).
- Early termination clauses: Ensure you can terminate the contract for any reason with a maximum of 14 days' written notice while retaining all code and assets produced up to that hour.
Software vendor evaluation matrix
Use this operational matrix to score agencies during your procurement calls:
| Evaluation Criteria | Red Flag (Walk Away) | Yellow Flag (Proceed with Caution) | Green Flag (Hire) |
|---|---|---|---|
| Code Ownership | Code released only after final payment invoice | Hosted in vendor's private repo during dev | Full ownership in your repo from Commit #1 |
| Team Staffing | Named staff replaced without approval notice | Mix of named seniors and unvetted juniors | Dedicated named staff engineers tied to SOW |
| Testing Standards | Manual QA testing preferred over automation | Basic unit tests without integration suite | CI/CD automation with >80% test coverage |
| Billing Model | Rigid fixed-price with strict change fees | Open T&M with zero budget visibility | T&M with bi-weekly capped sprints & demos |
| Architecture | Recommends total rewrites on Day 1 | Uses default framework starter templates | Conducts data-driven RFC & trade-off audit |
| Post-Launch | Hand-off via zip file or shared drive | Retainer required for basic bug fixes | Open Telemetry setup, IAC, & clear runbooks |
The 4-stage engineering evaluation framework
To eliminate risk when spending six figures on outside developers, run candidates through this four-stage vetting process. It separates high-performing software partners from low-tier agency body shops within two weeks.
Stage 1: Code Review --> Stage 2: Architecture RFC --> Stage 3: Legal & IP --> Stage 4: Paid Sprint 0
Stage 1: The anonymized code walk (60 Minutes)
Require the vendor's senior engineer to screen-share a production codebase they built for a previous client (sanitizing sensitive data). Have your internal lead or a trusted advisor ask:
- "Why did you choose this database ORM over raw SQL queries?"
- "Show us your error-handling middleware and logging setup."
- "How do you handle schema migrations when pushing zero-downtime updates?"
Stage 2: The RFC architectural trial (2 Hours)
Draft a short 2-page document detailing a feature or migration you need executed over the next 6 months. Ask the vendor to submit a short RFC outlining their proposed stack choices, database schema models, security boundaries, and API designs. Evaluate whether they ask smart questions about your scaling limits, user roles, and business goals.
Stage 3: Legal and IP verification
Before discussing final numbers, verify their operational terms. Inspect their standard Master Services Agreement (MSA) for clear IP transfer rights, robust non-disclosure terms, zero non-compete restrictions on your domain, and standard 30-day warranty coverage on production bugs.
Stage 4: Paid "Sprint 0" trial (2 Weeks)
Never commit $300,000 to an untested vendor based on conversations alone. Fund a 2-week paid "Sprint 0" engagement ($10,000–$25,000). Use this sprint to:
- Complete system discovery and finalize architecture diagrams.
- Set up local development Docker environments and CI/CD pipelines.
- Build and deploy one real, non-trivial feature to a staging environment.
If the vendor delivers clean code, communicates transparently in Slack, and ships on time during Sprint 0, commit to the full project scope. If they fail, you cut ties having lost only two weeks and a small fraction of your budget—and you keep all the design artifacts and repository setup.
What this means for your team
Vetting a software development company comes down to verifying technical execution over sales promises. You do not need an agency with an expensive office, a flashy award portfolio, or a 50-page presentation deck. You need senior engineers who write clean code, communicate early when trade-offs arise, and treat your capital like their own.
By insisting on live code reviews, named senior developers, automated testing, and a paid Sprint 0 trial, you insulate your business from scope blowouts and unmaintainable technical debt.
If you have a critical AI product, legacy system modernization, or custom web platform to build and want to see how senior US software engineers operate, reach out to our engineering team. We will jump straight into code, architecture, and timeline math without sales fluff.
Frequently asked
- What is the biggest red flag when vetting a software agency?
- The biggest red flag is a bait-and-switch staffing model where senior engineers pitch the account but unvetted junior offshore contractors write the code. Always insist on named engineers and minimum seniority clauses in your Statement of Work.
- Should I use a fixed-price or time-and-materials contract?
- Time-and-materials with capped two-week sprints protects your budget better than fixed-price contracts. Fixed-price deals incentivize vendors to rush execution, cut test coverage, and charge steep fees for minor scope changes.
- What is a Sprint 0 engagement?
- A Sprint 0 is a short, paid two-week trial engagement designed to validate a vendor before signing a multi-month contract. During Sprint 0, the engineering team sets up CI/CD pipelines, finalizes system architecture, and ships one production-ready feature.
- How do I test an agency's technical competence without coding tests?
- Stage a 90-minute architecture review using real operational bottlenecks from your system rather than generic whiteboard puzzles. Ask their principal engineer to walk through past production pull requests, schema migrations, and observability setups live.
- Who should own the code repository during development?
- Your company must own the code repository, deployment keys, and cloud infrastructure from the first commit. Never allow a software vendor to host your intellectual property inside their private repository or corporate cloud account.
Related questions
- Software Development Company Contracts: SOW Mechanics, Acceptance Gates, and Risk Allocation ($120k–$500k Pro…
- Software Development Company Comparison Matrix: Scoring Rubrics, Rate Auditing, and SOW Benchmarks for Engine…
- How to Choose a Custom Software Development Company: Technical Vetting, SOW Audits, and Risk Allocation for $…
- US Software Development Company Rates: Hourly Benchmarks, Blended Ratios, and Budget Allocation ($120k–$500k)
- How to Choose a Custom Software Development Company: Technical Vetting Framework and Red Flags for Engineerin…
More answers in Insights or see AI development services, or hire U.S.-based developers.

