Most founders pick a dev agency the way they'd pick a restaurant in a strange city: a decent website, a warm referral, a confident pitch. Then they hand over their company's future. Here's how to actually kick the tires.
The ten questions
Ask every agency these, in this order. The pattern of answers matters more than any single one.
- "Who exactly will write my code?" If the people pitching you won't be the people building — and they usually aren't — meet the actual team. A bait-and-switch here predicts everything else.
- "Show me something you shipped two years ago that's still running." Anyone can demo last month's project. Longevity is the tell.
- "What happens when you're wrong about an estimate?" Good shops talk about scope negotiation and early warnings. Bad shops say it never happens.
- "Walk me through how you'd hand the project off to an in-house team." If the answer is vague, the lock-in is the business model.
- "What will you push back on?" An agency that has never told a client "no, don't build that" is a feature factory. You're paying for judgment, not just fingers on keyboards.
- "How do you handle security?" You're listening for specifics: secrets management, dependency updates, access control. "We take security very seriously" is not an answer.
- "What's in the repo besides code?" README, deploy docs, environment setup. If a new engineer can't get running in a day, you don't own a codebase — you own a puzzle.
- "Who owns the code, the accounts, and the infrastructure?" The right answer: you, from day one, in writing. Cloud accounts, domains, app-store listings — all in your name.
- "What does 'done' mean?" Tested how? Deployed where? Documented for whom? Vague completion criteria are where budgets go to die.
- "Can I talk to a client whose project went badly?" Every agency has one. The honest ones will make the introduction. That call is worth more than every logo on their homepage.
Red flags that override good answers
- A quote that's dramatically cheaper than everyone else's. You'll pay the difference later, with interest.
- Resistance to giving you repo and cloud-account access during the project.
- Everything is custom. No boring, proven tools anywhere. Novelty is fun to build and expensive to own.
- No questions about your business. A shop that starts talking solutions before understanding the problem will build the wrong thing enthusiastically.
Contract terms that actually protect you
- You own the IP, assigned continuously — not on final payment. If the relationship dies mid-project, you keep what you paid for.
- Weekly deployable increments, not a big-bang delivery. It keeps everyone honest and gives you an exit at any week.
- A defined handoff deliverable: docs, credentials transfer, and a paid transition period with whoever comes next.
- Rates and terms for post-launch work agreed up front — that's when leverage flips to them.
The meta-question
The pattern under all of this: does the agency behave like it expects you to leave someday? Good shops build for their own replacement. Bad shops build moats. You can tell which one you're talking to in a single meeting if you ask the right things — now you have them.