Back to Insights
// // insight

What questions should you ask a software agency before signing?

Before signing with a software development company, ask five core technical and operational questions: Who specifically writes the code, when do you get repository admin access, how are change requests priced, what is the test coverage standard, and what are the exact termination terms? Force vendors to detail engineering workflows, staff tenure, and IP ownership mechanics.

Published

By Utshab Chakraborty, Founder & CEO, NextGen Coding Company · Technically reviewed by Chris Masi, Delivery Manager

Before signing with a software agency, ask five technical and operational questions: Who specifically writes the code, when do you get repository admin access, how are change requests priced, what is the automated test coverage standard, and what are the exact contract termination terms? Skip generic process questions and force the agency to explain real daily engineering workflows, developer seniority, and IP ownership mechanics.

How do you verify who is actually writing your code?

To verify who writes your code, require named resumes, perform a technical interview with the actual team assigned to your project, and add a contract clause requiring written approval before replacing key staff. Software agencies frequently pitch projects using staff engineers and then pass execution to junior contractors. Direct access to your assigned engineering team eliminates middle-management filtering and prevents classic agency bait-and-switch tactics.

Most sales presentations feature the agency's VP of Engineering or a brilliant principal architect. Once the contract is signed, that architect disappears to close the next enterprise deal. You are left with two mid-level generalists and three offshore interns learning PostgreSQL on your budget.

Ask these exact sub-questions during technical due diligence:

  • Can we interview the specific engineers assigned to our repository before signing the SOW?
  • What is the average tenure of the engineers who will work on our project?
  • What percentage of your team is comprised of full-time employees versus 1099 sub-contractors?
  • What happens if a core developer leaves the project midway through execution?

If an agency claims their team is fluid and resources are swapped based on sprint capacity, walk away. Context switching kills complex software builds. You need a dedicated, named squad that stays on your codebase until the release criteria are met.

What technical questions reveal how an agency manages infrastructure and security?

Ask how deployment pipelines are configured, who holds root cloud keys, and how automated tests block broken builds. A professional software development company in the USA should hand over AWS, GCP, or Azure root access on day one and deploy to production through automated CI/CD pipelines from the very first sprint.

Never wait until week twelve to see where your application is hosted. If an agency runs code exclusively on their private infrastructure or developer laptops during construction, you inherit massive deployment risk at launch.

To evaluate technical discipline, ask the team to walk through their deployment checklist:

  1. Repository Access: Will our team hold organization-admin permissions on GitHub or GitLab from day one?
  2. Infrastructure as Code: Are environment provisions written in Terraform or Pulumi, or is someone clicking buttons in the AWS Console?
  3. Automated Testing: What is your target unit and integration test coverage percentage, and does a failed Playwright or Jest run automatically block a pull request merge?
  4. Secrets Management: How do you handle API keys and credentials across local, staging, and production environments?

If the answer to secrets management is a shared .env file over Slack, their security posture is nonexistent. Demand HashiCorp Vault, AWS Secrets Manager, or Doppler integrations from day zero.

How much does software agency pricing vary by contract model?

Software agency pricing varies from $100 to $250 per hour per developer depending on contract structure, developer seniority, and engagement risk. Fixed-price models carry a 20% to 40% risk premium baked into the total bid, while Time and Materials (T&M) shifts scope risk to the client in exchange for transparent hourly rates and lower friction on changing requirements.

Most custom engineering engagements fall between $120,000 and $500,000 depending on legacy system complexity, security requirements, and team size. The table below outlines how common contract models compare across financial risk, flexibility, and operational overhead.

Engagement ModelHourly EquivalentScope FlexibilityRisk Premium Baked InBest Used For
Fixed Price$175 - $250 / hrVery Low (Requires Change Orders)30% - 50%Small, tightly scoped MVPs under $75k with zero ambiguity.
Time & Materials (T&M)$140 - $210 / hrHigh (Adjust sprint backlog weekly)0%Modernization projects, complex web apps, evolving products.
Dedicated Team (Retainer)$120 - $185 / hrMaximum (Full backlog control)0%Long-term roadmap execution, scaling internal capacity.

Fixed-price contracts look safe on paper to procurement officers, but they destroy software quality. When an agency realizes a fixed-price project is over budget, their incentives flip immediately from building great software to minimizing their financial loss. They stop refactoring, cut test suites, push hard on scope change orders, and rush to sign off.

How long should a software agency project onboarding take before the first release?

Onboarding to an initial production release should take two to four weeks for standard web platforms or legacy modernizations. If an agency requests six weeks of pure "discovery" before committing a single line of working code to a git repository, you are paying for strategic overhead rather than software engineering.

A realistic engineering timeline follows four distinct phases:

  1. Architecture & Environment Setup (Week 1–2): CI/CD pipeline setup, infrastructure provisioning via IaC, repo creation, database schema design, and local Docker configuration.
  2. First Production Deployment (Week 2–3): Deploying a trivial end-to-end "hello world" feature through the automated build pipeline to production hosting. This proves pipeline health early.
  3. Core Feature Sprints (Weeks 4–12): Bi-weekly iterative releases of application features behind feature flags, validated by continuous automated testing.
  4. Hardening & User Acceptance (Weeks 12–14): Penetration testing, load testing with k6 or Locust, user documentation, and final operational handoff.

If an agency cannot ship runnable, testable code to a staging environment by the end of the second sprint, their process is broken. Demand working software early and often.

Fixed price vs time and materials: which contract model protects your budget?

Time and materials protects your budget when requirements are fluid or when modernizing complex legacy systems. Fixed-price contracts only protect your budget if your technical specification is 100% complete and frozen. In practice, fixed-price contracts incentivize agencies to cut corners on code quality to preserve margins when scope expands.

To determine which model fits your internal operating budget, run through this decision evaluation:

  • Is your architecture fully defined? If you have complete OpenAPI specs, Figma design tokens, database schemas, and written business logic, a Fixed Price contract can work.
  • Are you integrating with legacy APIs? Legacy internal systems always harbor undocumented edge cases. Use Time & Materials with a strict weekly cap to avoid massive change order friction.
  • Do you have an in-house VP of Engineering or Tech Lead? If yes, rent raw senior talent via a Dedicated Team retainer and manage the backlog yourself.
  • Is speed to market the primary metric? Time & Materials allows sprint priorities to pivot instantly without pausing work to negotiate scope amendments.

Never sign a T&M agreement without a budget ceiling, burn-rate dashboard, and a notice threshold. Require the agency to alert you in writing whenever cumulative spend reaches 75% of a milestone cap.

What red flags should you look for in agency responses?

Watch out for vague answers about automated testing, reluctance to grant repo access, hidden management fees, and heavy account manager buffers. If you are not allowed to speak to the lead engineer without an Account Executive present, the agency is hiding technical deficits.

Screen out dangerous agency candidates by watching for these four operational red flags:

  • The "Black Box" Delivery Model: They promise to handle everything behind closed doors and present a finished product in three months. This almost always leads to an unmaintainable codebase that fails security reviews.
  • Zero Automated Test Coverage: They manual-test applications using offshore QA teams instead of writing unit, integration, and end-to-end test suites. Manual testing does not scale and leads to severe regressions as code volume grows.
  • Proprietary Framework Lock-In: They insist on using their in-house internal framework or custom CMS instead of standard, open-source tech stacks like React, Node, Python, Go, or standard cloud native tools.
  • Opaque Billing for Idle Time: Their SOW bills full-time rates for senior architects who only spend two hours per week reviewing pull requests.

A great development partner acts like an extension of your existing engineering department. They adopt your tools, write clear documentation, run transparent daily standups, and write clean code your internal staff can maintain long after the contract ends.

What this means for your team

Hiring a software agency is not outsourcing responsibility—it is renting specialized engineering velocity. If you ask superficial questions about process methodologies, you will receive polished sales answers. If you ask deep questions about repo access, CI/CD pipelines, staff tenure, and contract mechanics, you will quickly separate real staff engineers from vendor agencies.

Protect your budget by establishing clear technical boundaries before signing any SOW. Require repository access on day one, insist on interviewing your actual assigned engineers, pick the contract structure that aligns your financial incentives, and force the team to prove deployment health early.

If you are evaluating software partners for a modern application build, AI product, or legacy modernization project, tell us about your platform challenges and speak directly with a staff engineer today.

Related questions

More answers in Insights or see AI development services, or hire U.S.-based developers.

// let's build something

Start your project request

Tell us what you're building — engineering capacity, AI, QA, cloud, or a fixed-scope software engagement. Our NYC team responds within one business day.

// what to expect
  • Response within 1 business day
  • 30-minute discovery conversation
  • Recommended engagement model & pricing
  • NYC-focused — in-person available
Start Project Request

Inbound sales only. All form information is encrypted in transit.