How to vet a development partner: ten questions before you sign
Ten questions to put to any supplier before you sign, with what a good answer and a bad answer sound like. We answer all ten about ourselves too, including where being small works against us.
Article contents
Why these ten questions
Projects rarely fail because the hourly rate was wrong. They fail because nobody agreed in writing who owns the code, who writes it, and what happens when it ends.
The classic number here is worth quoting carefully rather than loosely. Flyvbjerg and Budzier's 2011 study of 1 471 large enterprise IT programmes found an average cost overrun of 27%, with one in six overrunning by 200%. Those were big public and corporate programmes, not a 6,000 euro website, so read it as a warning about unmanaged scope, not as a prediction for your project.
If you use this list and then hire somebody else, it has done its job.
The ten questions
1. Who owns the code, and who owns the repository?
Ask both halves, because they are different things. A supplier will confirm you own the finished website while the repository sits in their own account, which means you own something you cannot reach.
A good answer names the licence, names when it takes effect, and offers repository access. A bad answer is „of course it is yours“ with no document, or a zip file at the end.
Ours: once the price is paid in full you get an exclusive, unlimited licence to the custom design, text and code, including the right to have another company modify it. Our terms also commit us to handing over the source code and access to the repository with its history once the price is paid, and they state plainly that until full payment neither the licence nor the handover happens. One limit worth knowing: the general components we reuse across projects are handed over inside the code, but they carry a non-exclusive licence, not an exclusive one.
2. What happens the day we stop working together?
The test is simple: could a different firm pick this up next week without talking to us?
A good answer covers who holds the credentials, where the deployment instructions live, and what must be handed over contractually. A bad answer treats the question as an insult, or relies on goodwill rather than a clause.
Ours: the licence explicitly covers having someone else modify the work, so copyright does not lock you in, and we set up domain, hosting and third-party accounts in your name or hand you the access to them. The other side: for business clients our liability is capped at the price of the service concerned. Normal at our size, but it is not an enterprise indemnity and you should price that in.
3. Is this a template or is it custom?
Ask what you are paying the custom rate for. Paying a custom rate for work in a website builder is a classic trap, and what the market difference between those two rates is we give in our article Why we do not build on templates.
You do not have to take anyone's word for it. Put the supplier's own portfolio sites through our free audit: it names the system each site runs on, the theme and the plugins it can recognise. If a studio selling custom development has a portfolio of marketplace themes, that shows up in about a minute.
A good answer is specific about what is bespoke, what is off-the-shelf and what is third-party software, and is comfortable showing you the code. A bad answer is the word „custom“ beside a demo that is visibly a purchased theme with new colours.
Ours: we write the websites, portals and applications ourselves rather than reselling a template. The honest caveat: nobody builds from nothing. We use open source libraries and our own reusable components, and on those you get a non-exclusive licence, not ownership.
4. Who exactly writes the code, and are they employees or subcontractors?
Ask for names and roles, not a headcount. What matters is whether the people in the sales meeting will do the work, and who reviews it.
Testing discipline is worth asking about in the same breath. Tricentis's 2026 survey of software and QA professionals reported that 60% of respondents' organisations deploy code without fully testing it, and that AI generated code nobody can properly review was among the reasons given. It is a vendor survey of a self-selecting audience, so treat it as a prompt for your question rather than as a measurement of the industry.
Ours: the studio is the founder and a small team, and the people who design your project build it. For specific areas we bring in specialists we have worked with for years, such as a Linux administrator in Denmark and a software analyst in Japan. They are long-standing contractors, not an anonymous bench. We use AI as a tool; the design, the code and the decisions are ours.
5. What does handover actually look like?
Ask to see a real handover from a finished project, client name removed.
A good answer includes repository access, deployment instructions, credentials in your own accounts, and a named person who answers questions after launch. A bad answer is „we will send you the logins“.
Ours: we hand over by launching on your domain, giving you the access and the files, and transferring the repository or handing over an archive with the source code and instructions for running it, which is the method written into our terms. A two-week website does not come with a fifty page runbook. If an internal IT team needs formal documentation, say so at the quotation stage so it is in the price.
6. How are changes priced?
Ask for the mechanism, not a rate. A published hourly number tells you little: one analysis found five sources quoting Poland's rate in a single year at anything from 29,30 EUR to 93 EUR per hour, because four different things get published as „the rate“.
A good answer explains what counts as a change, who decides, and whether you approve the cost before work starts. A bad answer is an hourly rate with no change process.
Ours: a fixed price for an agreed scope, with add-on work priced as hours times a published rate, so you can check the arithmetic. Our terms put the change rule in writing and it runs in both directions. If the actual scope turns out smaller than the quote assumed, we charge less and do not invoice the difference, and you do not have to ask. We raise the price in two cases only: you expanded the scope, or you did not supply the agreed materials and we had to produce them so the work could continue. In both cases we tell you in advance, say how many hours it is, and apply the increase only after you agree in writing. Two caveats that are also in the terms: the indicative timelines in our price list are not binding, and the schedule extends while we wait for your materials or feedback.
7. What is your real response time?
Ask for the number in working hours in your time zone, and ask what happens at 2am. Suppliers often quote a contractual complaint deadline and let you read it as a support promise.
A good answer separates three cases: a normal question, a bug, and the site being down. A bad answer is „24/7 support“ from a team too small to staff a night shift.
Ours: we are in Slovakia, on Central European Time, UTC+1 in winter and UTC+2 in summer. Against a nine to five day that is roughly seven hours of overlap with London, about two with New York, and effectively none with San Francisco. We answer on working days and do not offer 24/7 on-call, because we are not large enough to do it honestly.
Two things our terms do give you, and they are worth separating from support. There is a warranty: six months on the work, or twelve months if your registered office is outside Slovakia and Czechia, and it covers defects that appear after browser and operating system updates. And there is a complaints deadline: we confirm a reported defect and resolve it without undue delay, at the latest within 30 days. That 30 days is a legal backstop, not a service level, and you should read it as the outer limit rather than the plan.
8. Where will our data live?
Ask for the hosting provider, the region and the sub-processor list, in writing.
The short version of the law: under Chapter V of the GDPR, sending personal data to a country outside the EEA needs a legal basis such as an adequacy decision or standard contractual clauses, plus an assessment where adequacy is missing. The European Commission has recognised adequate protection for a limited list of countries and territories, which excludes many popular offshore destinations. The enforcement risk is real: the largest GDPR fine so far, 1,2 billion EUR against Meta in 2023, concerned transfers.
Ours: Slovakia is an EU member state and we host inside the EU by default, so the Chapter V question does not arise for the hosting itself. Two honest qualifications rather than one. First, „no transfer“ depends on where the data is actually accessed from, not only on where the supplier is registered, so ask every supplier the same question about their own subcontractors, including ours. Second, avoiding a Chapter V transfer does not remove your other obligations: you still need a processor agreement under Article 28 and a sub-processor list, and you should ask us for both rather than assume an EU address settles it.
9. Which law governs the contract, and where would a dispute be heard?
Ask what law applies and, separately, whether a judgment would be enforceable where the supplier's assets are.
A good answer states the governing law plainly and will negotiate it. A bad answer is silence, or terms in a language you cannot read.
Ours: our terms are issued in Slovak and in English and both versions are binding. We conclude the contract in whichever of the two we agree on, and where the versions differ, the language the contract was concluded in decides, so neither side is bound by text in a language it did not contract in. The default governing law is Slovak and the default forum is the Slovak courts, and the terms say in writing that with a business customer we can agree a different governing law and a different way of resolving disputes, including arbitration, provided it is written into the contract. Raise it early rather than at signature.
Contracting inside the EU helps with enforcement. Under the Brussels I bis Regulation a judgment given in one member state is recognised in the others without any special procedure and is enforceable without a declaration of enforceability, although the defendant can still apply to refuse enforcement on limited grounds. UK buyers gained a treaty route when the 2019 Hague Judgments Convention entered into force for the UK on 1 July 2025. US buyers have no equivalent, so at this size your real protection is staged payments and your own repository, not litigation.
10. How do I verify a reference?
Do not accept a logo wall. Ask to speak to a named client, and ask the supplier for one project that went badly and what changed afterwards.
On review platforms, check how the review was verified. Clutch requires the reviewer to log in with LinkedIn, Google or a company email, runs automated checks on their digital footprint, and has an editor check every submission before granting a Verified badge.
On the call, ask three things: who actually did the work, what changed in scope and how it was priced, and whether handover happened without chasing. A reference who cannot name the people who built their product is a bad sign.
Where we are small, and what that means
We are a small studio founded in 2021. That has consequences you should price in.
We have no bench: if somebody falls ill the deadline moves, and we will not staff a twenty-person programme. On language, the safe claim is written briefs and code review, not presenting at native-speaker level. The sub-scores of the language index this rests on we give in our article What a custom website costs in the West.
Do not buy on country branding either. Slovakia ranks 57 of 69 economies in the IMD World Digital Competitiveness Ranking 2025 and 48 of 139 in the WIPO Global Innovation Index 2026. Those numbers argue for judging the specific people rather than the flag.
Our own prices deserve the same scrutiny, and you can test that question on us. In our price list every package also states the number of hours, so the arithmetic can be worked out rather than taken on trust. The export prices, and what makes up such a rate, we cover in our article What a custom website costs in the West.
We do not add VAT to our invoices, but for a company registered for VAT in the European Union that is not a discount; why not, we explain in our article What a custom website costs in the West. Ask about what is not in the price too: third-party fees for the domain, hosting, payment gateways and licences you pay directly, and the content is yours unless you order it from us.
How to use this list
Send these ten questions to three suppliers in writing and compare the written answers. The answers you cannot get in writing are the answer.
Did the article help you? Send it to a colleague or to whoever looks after your website.
FAQ
Questions on this topic
What is the single most important question to ask a nearshore supplier?
Who owns the repository, not just who owns the code. Ownership of the deliverable means little if the code lives in an account you cannot reach, so ask for repository access and get the licence wording in writing.
Almost every other problem on this list is easier to fix later than this one.
How do I check whether a supplier really builds custom, or resells templates?
Put two or three of their portfolio sites through a website audit. Ours is free and names the system each site runs on, the theme and the plugins it can recognise, which takes about a minute per site.
A studio selling custom development whose portfolio is marketplace themes is answering the question for you.
Does hiring inside the EU remove my GDPR obligations?
No. It removes the Chapter V transfer question for data that stays in the EEA, which is the hardest part of the paperwork. You still need a processor agreement under Article 28, a sub-processor list and the usual security measures.
Ask for both documents before signing, from any supplier, including an EU one.
What should I ask about response times?
Ask for three separate numbers in your own time zone: a normal question, a bug, and the site being down. Then ask what the contract actually commits to, because a complaints deadline measured in days is a legal backstop, not a support promise.
Separate the warranty from the support arrangement as well, because they are different things.
Is a fixed price better than an hourly rate?
Neither is better on its own. What matters is the change mechanism: what counts as a change, who approves it, and whether you see the price before the work starts.
Ask whether the price can go down as well as up, and get the answer in writing.
You will find more answers in the section FAQ.