10 questions to ask before hiring a software agency
Last updated 2026-09-16
Before hiring a software agency, get answers in writing on ten things: who owns the code and IP, who owns the repository, source code escrow, fixed price versus time and materials, who writes the code, QA, post-launch maintenance, references, the SOW, and subcontracting. Good answers are specific and contractual.
The questions below protect a non-technical owner who is about to spend between twenty-five thousand and a quarter million dollars on custom software. Ask all ten before you sign anything. Under each question you will find what a good answer and a bad answer sound like when the vendor says them out loud. The pattern to watch for is simple: good vendors answer with specifics and put them in the contract, while weak ones answer with reassurance and ask you to trust the relationship. I sit on the owner's side of these conversations for a living, and the gap between those two kinds of answers tells you most of what you need to know.
- OwnershipIP, repository, escrow
- Commercial termsPricing model, exclusions
- Delivery teamWho writes the code, subcontractors
- Quality and supportQA sign-off, maintenance after launch
- Track recordReferences you can call
Who owns the source code and IP when this is done?
You should own all of it, and the contract must say so with a present-tense IP assignment clause. Copyright law often leaves ownership with whoever writes the code, not whoever pays. A good agency hands you full ownership on payment. A bad one keeps rights to "reusable components," which means you cannot leave.
Read the assignment language yourself or have someone read it for you. Watch for the phrase "work made for hire" alone, which is not enough for all categories of work, and insist on an explicit assignment of all intellectual property. Owners in regulated fields feel this hardest, which is why I push insurance brokerage technology decisions toward clean ownership from day one.
Good answer: "You own everything we write for you as each invoice is paid. Any library we reuse is licensed to you permanently, and the contract assigns the rest in plain words."
Bad answer: "You'll own the app. Our reusable components stay ours, and ownership transfers once the final invoice clears."
Who controls the code repository during the build?
You should own the GitHub organization and add the agency as collaborators, not the reverse. When the vendor owns the repository, they own your leverage. A healthy arrangement gives you admin access from the first commit, so you watch the code accrue and can hand it to another team without waiting on a handoff.
- Ask for read access to the repository on day one, not at launch.
- Confirm the code lives in your account, billed to you.
- Check that commits happen regularly, not in one dump near the deadline.
- GitHub organizationYour company as administrator, agency as collaborators
- Apple Developer Program and Google Play ConsoleEnrolled in your company's name
- Cloud hosting and domainBilled to your card, agency added as users
The same rule covers app store accounts. Enroll your company in the Apple Developer Program, which costs $99 a year, and in Google Play Console, which charges a one-time $25 fee, then add the agency as team members. Moving a published app out of an agency's account later is slow, and during a dispute it can stall entirely.
Good answer: "Create the GitHub organization and your Apple and Google developer accounts in your company's name, and add us as members. You'll see our commits from the first week."
Bad answer: "We'll publish under our developer account to keep things simple and hand over the code at launch."
What is source code escrow and do I need it here?
Source code escrow is an arrangement where a neutral third party holds your code and releases it if the agency fails or breaches the deal. It matters most when the vendor hosts the only copy. If you already own the repository and keep your own backups, escrow is usually redundant cost worth skipping.
Good answer: "You'll own the repository, so escrow adds little. If we ever host the only copy, we'll deposit the code with an escrow agent such as Escode and list the release triggers in the contract."
Bad answer: "Escrow isn't necessary, you can trust us."
The bad answer only matters when the vendor also hosts the only copy of your software. In that case, treat it as a reason to walk away.
Fixed price or time and materials for this work?
Fixed price fits a tightly defined statement of work that will not change, and it shifts overrun risk to the vendor. Time and materials fits discovery and shifting requirements, and it stays honest only with weekly hour reports and a spending cap. Most projects split it: a fixed-price discovery phase, then time and materials.
Beware a fixed bid on a vague scope. The agency either pads it heavily or plans to win every change order. Restoration contractors run into this constantly when field workflows get underestimated, so I steer restoration contractor software projects toward a paid discovery phase before any number gets locked.
Whichever model you choose, insist on seeing working software every one or two weeks, such as an iPhone test build installed through Apple's TestFlight. Research by McKinsey and the University of Oxford on more than 5,400 IT projects found large IT projects ran 45% over budget and delivered 56% less value than predicted. Regular demos are the cheapest early warning an owner has.
Good answer: "Discovery is a fixed fee. The build is time and materials against an estimate range, with a report every two weeks showing hours spent next to working features, and we ask before going more than 10% over."
Bad answer: "We're flexible, we'll figure out the changes as we go."
Who actually writes the code on my project?
Ask for the names, roles, and locations of the engineers assigned to you, then ask to meet them on a call. Pitch meetings often star a polished senior team that disappears after signing, replaced by junior developers or undisclosed offshore subcontractors. A straight answer names real people. A dodge talks about "our process" and "the team" without ever naming anyone.
This is also where staff augmentation and a project engagement diverge. Staff augmentation rents you developers who follow your direction. A project engagement sells you an outcome the agency manages. Wealth and asset managers tend to want the outcome model with tight oversight, which is part of what I help wealth management technology buyers structure.
Good answer: "Your lead developer and designer are named in the proposal, along with the share of their time on your project. You can talk to both this week."
Bad answer: "We assign the team after kickoff."
Ask one follow-up about AI coding tools such as GitHub Copilot and Cursor, because nearly every team uses them now. The evidence on speed is mixed: a 2023 controlled experiment found developers using Copilot finished a new, self-contained task 55.8% faster, while a 2025 randomized trial by METR found experienced developers took 19% longer on large codebases they already maintained.
Good answer: "Yes, and every AI-assisted change is reviewed by a second developer and covered by tests before it merges. No customer data goes into outside tools."
Bad answer: "AI makes us twice as fast, so the quote already reflects that."
How do you handle QA and who signs off on it?
A serious agency has a QA function separate from the developers who wrote the feature, plus automated tests and a written acceptance process you approve. Skip this and you become the test team, finding bugs in production. Ask what share of the budget covers testing. If it is near zero, the rework will land on you.
Ask which security checklist the team builds against as well. For a mobile app, a credible agency can name the OWASP Mobile Application Security Verification Standard and explain how it stores passwords, keys, and customer data.
Good answer: "A tester who didn't write the feature checks it on real devices, sign-up and payment have automated tests, and you approve each milestone against written acceptance criteria."
Bad answer: "Our developers test their own work, and you'll do acceptance testing at the end."
What happens after launch and who maintains it?
Launch is the midpoint, not the finish, so settle post-launch maintenance before signing. Software needs security patches, dependency updates, and bug fixes for years. A good agency offers a clear maintenance agreement with response times and rates. A bad one treats launch as the end and bills emergency hours when your app breaks on a new operating system.
Get a few more things in writing up front: a signed NDA covering your data and ideas, a documented handoff so another team could take over, and an exit clause. Property managers learn this when a vendor disappears mid-lease-season, which is why I make property management technology plans assume the relationship will end someday.
Good answer: "Support is a fixed monthly fee covering operating-system updates, security patches, and bug fixes, with a stated response time. If you leave, you get the code, documentation, every credential, and a paid handover call."
Bad answer: "We'll quote support when we get there."
Can you give me references I can actually call?
Ask for two or three clients with projects like yours, then call them and ask about overruns, missed deadlines, and what broke. Useful references describe specific problems and how the agency handled them. A vendor who offers only glowing written testimonials, or stalls on putting you in touch with a real client, is hiding something worth finding before you sign.
Good answer: "Here are three clients, including one whose project ended more than a year ago and one where we missed a deadline. Call any of them."
Bad answer: "Our clients value their privacy, but here are some testimonials."
What exactly does the statement of work exclude?
A statement of work is only as useful as its exclusions list. Every quote leaves something out, such as hosting, content entry, data migration, App Store submission, or post-launch support. Ask the agency to write down everything its price excludes and how each change request is estimated and approved before extra work begins.
Clutch, which collects verified client reviews of agencies, reports that most app development projects cost between $10,000 and $49,999, with an average of $90,780. Unwritten exclusions are how a project priced inside that range ends outside it, one change order at a time.
Good answer: "Hosting, content entry, and store submission are excluded and listed on page four. Every change gets a written estimate in hours and dollars that you approve before we start."
Bad answer: "Everything you need is included."
Do you subcontract any of the work, and to whom?
Many agencies hand design, testing, or whole features to freelancers or offshore partners without saying so. Subcontracting can work, but you need to know who touches your code and customer data, and the agency must stay contractually responsible. Ask for each partner's name and location, and write subcontracting limits into the contract.
Good answer: "Yes, testing goes to one partner named in the contract. They work under our NDA and our liability, and they never get access to production data."
Bad answer: "All our developers are part of our extended family."
Related guides
- What are the red flags in a software development proposal?
- How much does custom software cost? A 2026 reality check
- Build custom software or buy off the shelf?
- Should I hire an agency or a freelancer to build my mobile app?
- Fractional CTO vs technical advisor vs full-time CTO: which do you need?
- OWASP Mobile Application Security Verification Standard
Key takeaways
- Demand a written IP assignment transferring all source code and rights to you on payment, with no carve-outs.
- Own the GitHub repository yourself and add the agency as collaborators, so you keep your leverage.
- Use fixed price for a defined statement of work and time and materials for discovery, never a fixed bid on a vague scope.
- Get the names of the engineers who will write your code, and put subcontracting limits in the contract.
- Settle QA, post-launch maintenance, and an NDA before signing, not after the first production bug.
- Listen for specifics: good agencies answer with names, accounts, exclusions, and prices, while weak ones answer with reassurance.
Frequently asked questions
Who owns the source code when an agency builds my software?
You should, but only if the contract says so in writing. Default copyright law often leaves ownership with the agency that wrote the code. Insist on a present-tense IP assignment clause that transfers all source code, designs, and rights to you on payment, with no carve-outs for reusable components.
What is source code escrow and do I need it?
Source code escrow is a service where a neutral third party holds a copy of your code and releases it to you if the agency goes bankrupt or breaches the contract. It matters most when the vendor hosts the only copy. If you already own the GitHub repository outright, escrow is usually unnecessary.
Should I pay fixed price or time and materials?
Fixed price suits a tightly scoped statement of work where requirements will not move. Time and materials suits discovery work and changing requirements, and it stays honest only with weekly reporting and a spending cap. Most real projects use fixed price for a defined phase, then time and materials for the rest.
How do I know who will actually write my code?
Ask for the names and locations of the engineers assigned to your project, then ask to meet them. Pitch meetings often feature senior staff who vanish after signing, replaced by junior developers or offshore subcontractors. Put the named team and any subcontracting limits into the contract.
What does a good answer from a software agency sound like?
A good answer is specific and ends up in the contract: named developers, accounts in your company's name, a written exclusions list, a priced change process, and a monthly support fee. A weak answer asks for trust instead, with phrases like "we're flexible" or "everything is included" standing in for commitments.
I do this work as an independent advisor across many industries, sitting on your side of the table opposite the vendor. If you want a second read before you sign, see how I work or book a free 20-minute call.