Every agency's homepage says "we deliver quality on time." That's not a filter. What actually separates a dependable build partner from a source of budget overruns is how they answer a short list of specific questions — before a contract is signed, not after the first invoice.
The questions worth asking
- Is the price fixed to a written scope, or an estimate? An estimate can grow. A fixed price tied to a written spec can't, unless the scope changes — and if it does, that's a documented change order, not a surprise line item.
- What happens if the scope changes mid-project? There should be a clear, pre-agreed process — not a vague "we'll figure it out."
- Who reviews the code before it ships? Especially relevant if AI tools are part of the build process — ask specifically what a human reviews and what they don't.
- What's the security review process? Auth, payments, and user data handling should be checked before launch as a matter of course, not billed as an optional add-on.
- Who owns the code and the accounts? You should own your repository, your domain, and your hosting accounts from day one — not have them held by the agency.
- What does "done" mean? A written definition of completion tied to the scope document, not a subjective judgment call at delivery time.
- Can I see a comparable past project? Not just a portfolio screenshot — the actual live product, if the agency can share it.
- What's the timeline, and what could change it? A believable answer names specific risks (a third-party API, a design-approval step) rather than a flat "6 weeks, no matter what."
- What happens after launch? Bug fixes, handoff documentation, and a support window should be defined upfront, not negotiated after you've already paid.
The pattern to watch for
Vague answers to concrete questions are the actual signal. An agency that gives a specific, confident answer about scope, review, and ownership is one that has done this enough times to have a real process. An agency that answers with reassurance instead of specifics ("don't worry, we'll take care of it") is telling you they don't have one.
How we answer these
Every engagement starts with a written scope and a fixed price — see how that works on our pricing page — and every build gets a security review before launch regardless of tier. You own the repository and every account from day one. If you want the long version of why fixed price beats hourly for this kind of work, we wrote about that here.