Technology leadershipChecklist3 min readUpdated September 2026

Questions to Ask a Dev Agency Before You Sign

Before hiring a dev agency, ask who will do the work, who owns the code, how you'll see progress and how you can leave. Good agencies answer those four clearly and in writing. Vague answers on any of them are the strongest warning sign.

The questions below are grouped by the risk they protect against. For each, the note says what a solid answer sounds like, so you can judge without being technical.

Who will actually build it?

Agencies often sell with senior people and staff with juniors. Ask directly:

  • Who are the named people on my project, and how many hours a week is each on it? Good answers give names and roles. Watch for 'the team' with no names.
  • Are any of them subcontractors, and where are they located? Subcontracting isn't wrong, but you should know, and it affects security and time zones.
  • What happens if a key person leaves mid-project? Look for a documented handover process, not reassurance.
  • Can I speak to two past clients whose projects were similar in size? Call them and ask what went wrong, not only what went well.

Ask to meet the person who will lead the technical work, not just the salesperson.

Who owns the code, data and accounts?

This is the area where founders lose the most, so get it in the contract, reviewed by your attorney. The answers you want:

  1. Code ownership. All work product is assigned to you on payment, with any third-party or agency-owned components listed and licensed for your use.
  2. Repositories. Code lives in a repository under your organization, from the first day, not in the agency's account.
  3. Cloud and vendor accounts. Hosting, domains, app store listings and analytics are registered in your name, with the agency invited as a user.
  4. Open-source use. The agency tells you which open-source licenses it uses and confirms none creates obligations that conflict with your business.

If an agency wants to keep the repository until final payment, treat that as a negotiating position you can decline, not a fact of life.

How will you see progress and control scope?

Ask how they work day to day. Strong agencies show working software every one to two weeks, in an environment you can click through, not slide decks about progress. Ask to see the project board, how changes get approved and how they estimate.

For pricing, understand the tradeoff. A fixed price protects your budget but resists change, so a small scope shift becomes a change order. Time and materials keeps you flexible but needs tight oversight. For example, say you're building a first version with uncertain requirements: a fixed-price discovery phase followed by time-boxed build phases often balances both.

Also ask what 'done' means for a feature. Good answers include tests, review by a second engineer and deployment to a staging site you can verify.

What are their security and quality practices?

You don't need to be an expert to ask sensible questions:

  • How do you handle secrets and customer data during development? Real customer data shouldn't sit on laptops or in shared chat.
  • Do you run automated tests, and can I see the results? Ask for a sample.
  • How do you handle vulnerabilities in the libraries you use? Look for an answer that includes scanning and a fix process. CISA's federal directives required agencies to patch critical vulnerabilities on internet-facing systems within 15 days1, and an agency with no timeline of its own is worth a follow-up question.
  • Do you carry professional liability and cyber insurance? Ask to see the certificate.

If you'll handle regulated data such as health or payment information, tell them up front and ask how they've handled it before.

How do we leave if it isn't working?

Plan the exit before the start. Ask what the handover package includes: repositories, architecture notes, deployment instructions, environment and credential lists, and a walkthrough call. Ask what it costs and how long it takes.

Also ask about the termination clause: notice period, payment for work in progress and what happens to source code and accounts on termination. A good agency will answer without defensiveness, because they expect to be judged on the work.

Finally, decide who will check their work. If you have no technical lead, a part-time reviewer is worth having before the contract begins. See fractional CTO vs technical co-founder for how to choose that person, and use the build vs buy framework to decide which parts of your product an agency should build at all.

Executive Capability Standard

What Good Looks Like

You own the code and accounts, you can see working software every couple of weeks, and you can hand the project to someone else within a month if you need to.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read your draft contract for ownership, termination and payment terms and write down every point where the agency keeps control.
2. Do Manually:Interview two agency references yourself and ask each what went wrong and how it was handled.
3. Delegate:Hire a part-time technical reviewer to join weekly demos, read pull requests and challenge estimates on your behalf.
4. Automate:Have the agency deploy through a pipeline you own, so every change runs tests and appears in a repository you control.
5. Buy:Move recurring build work in-house or to a dedicated team once the product is stable and the agency's cost outweighs the flexibility.

How to Get Started

Frequently Asked Questions

Should I choose a fixed-price or hourly agency contract?

It depends on how clear your requirements are. Fixed price works for a well-defined scope but makes changes costly. Hourly or time-and-materials suits uncertain scope but needs close oversight. Many founders start with a fixed-price discovery phase, then move to time-boxed build phases.

How can I tell if an agency's code is any good?

Ask a neutral senior engineer to review a sample: the test suite, how the code is organized and whether a new developer could set it up from the instructions. Also check that the agency can deploy to a staging site on request. Working demos are better evidence than promises.

Who should own the repository and cloud accounts?

You should, from day one. Create the repository and cloud accounts under your company and invite the agency as users. This avoids a standoff at the end of the project and lets you revoke access instantly if the relationship ends.

What are red flags when hiring a dev agency?

Common ones include no named team members, refusal to put ownership terms in writing, no working demos until late, and pressure to sign quickly. Another is an agency that cannot say what it has declined or reversed for past clients.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Security patch remediation SLAs (CISA federal mandates, used as industry norm). CISA Binding Operational Directives 19-02 and 22-01 (CISA briefing hosted at NIST CSRC), 2022.

Related Guides