Every agency website shows the same things: a portfolio, a logo wall, five-star reviews, and a page about culture. None of it predicts whether the engagement will work, because none of it is falsifiable. The firms that disappoint you have all of it too.

What follows are the checks that actually correlate with outcomes — most of which you can run in a single well-structured conversation.

Start with the people, not the company

The single most reliable predictor is whether you meet the engineers who will do the work, before you sign.

Ask to interview them. Not a sales engineer, not a solutions architect who’ll disappear after kick-off — the named people who’ll be committing code. A firm confident in its bench agrees readily. A firm that deflects (“we allocate after contract signature”, “our process assigns the best available”) is telling you the CVs in the proposal are marketing material.

In that conversation, skip the algorithm puzzles. Ask instead:

  • Walk me through something you built that went badly. What did you do?
  • What’s the last technical decision you disagreed with, and how did you handle it?
  • How do you approach a codebase you’ve never seen?

You’re testing for judgement and candour. Engineers who can describe a failure precisely are almost always stronger than those with an unbroken record of triumphs.

Verify the claims that are verifiable

Most agency claims can’t be checked. A few can, and the exercise is revealing:

  • Company registration. Confirm the legal entity exists in the country claimed, with an incorporation date roughly matching “founded in…”. Most jurisdictions have a free public register.
  • Team size. Compare the claimed headcount against LinkedIn employees and the size of the engineering team specifically. A firm claiming 200 engineers with 40 people on LinkedIn is counting something other than employees.
  • Client references. Ask for two, and ask for one where the engagement ended. Anyone can produce a happy current client; how a firm talks about a finished relationship is far more informative.
  • Named case studies. Vague ones (“a leading fintech”) are unverifiable by design. Ask whether you can speak to that client. The answer tells you whether the case study is real.

The technical checks that matter

Ask to see code. Not a portfolio screenshot — actual source, from an open-source project they maintain or a sanitised sample they own. Look for tests, readable naming, and commit messages that explain why. If nothing can be shown for confidentiality reasons, ask them to walk you through a repository on screen.

Ask how they handle code review. Specifically: who reviews, what blocks a merge, and what happens when the reviewer disagrees. Firms without a real review culture will answer this vaguely, because the honest answer is “the client reviews it.”

Ask about their testing position. Not “do you test” — everyone says yes. Ask what percentage of their last project was covered, what they chose not to test, and why. The willingness to say “we didn’t unit-test the UI layer, here’s the reasoning” indicates engineering judgement rather than sales training.

Ask what they’d need from you. A strong partner has requirements of their own: access, environments, a decision-maker, a defined backlog. A firm that claims to need nothing hasn’t thought about delivery.

  • IP ownership from the first commit, in your repository, under your organisation’s account. Not transferred on final payment.
  • Notice period, both directions. Symmetry matters more than length.
  • Named-personnel clause. The people you interviewed are the people assigned, and substitutions require your agreement.
  • Data handling. Where is your data processed and stored, and under which legal basis? If you’re in the UK or EU and delivery is outside it, you need the transfer mechanism in writing. If you handle health or payment data, ask about the specific regime — the answer should be immediate and specific.
  • Subcontracting. Ask directly whether any part of delivery is subcontracted. Some firms broker work onward. That isn’t automatically disqualifying, but discovering it later is.

Operational reality

Timezone overlap, in writing. “We work with US clients” is a marketing statement. Four hours of daily overlap is a commitment. Get the hours in the contract, not the sales call.

Communication cadence. Who do you talk to daily, weekly, and when something goes wrong at 2am? A named escalation path beats an account manager.

English fluency of the engineers, not just the account team. This is a genuine and frequently dodged issue. If you’re only ever allowed to speak to a project manager, you’re paying for a translation layer that will lose nuance in both directions.

Red flags, ranked

  1. You can’t meet the engineers before signing. Nothing else on this list matters as much.
  2. Every answer is yes. A partner who has never said “that’s not a good idea” during sales won’t say it during delivery either.
  3. The estimate arrives without questions. A firm that can price your project from a two-page brief is guessing, and you’ll pay for the guess in change requests.
  4. Rates far below the market band. Sustainable delivery has a floor. Below it, you’re buying juniors sold as seniors, or a team that will churn.
  5. No written process for handover. Ask what you receive if the engagement ends tomorrow. Hesitation here is expensive later.
  6. Pressure to sign before a trial. Which brings us to the best de-risking tool available.

Run a paid trial

The most effective vetting technique is a small, paid, time-boxed piece of real work — two to four weeks, a genuine feature, your repository, your review process.

It costs little relative to the engagement and tells you what no reference call can: how they write code in your codebase, how they handle ambiguity, whether they ask good questions, and whether the estimate held. Any partner confident in their delivery will welcome it. The ones who resist are giving you the answer for free.

Frequently asked questions

Are agency review sites reliable? Directory reviews are typically solicited from clients the agency chose to ask, and are better read for specifics than for scores. A review describing a concrete situation is worth ten five-star ratings.

Should I avoid smaller firms? No, but the risk profile differs. Smaller firms give you closer access to senior people and carry more key-person risk. Larger firms have depth and are likelier to rotate staff. Neither is safer in the abstract; ask which risk you’re taking.

How much does location matter? Less than overlap and communication. A team six hours away with committed overlap hours outperforms a nearer team with none.

What if the engineers change mid-project? Expect some churn on long engagements. What matters is notice, a handover period, and who pays for the replacement’s ramp-up. Get that in the contract.


Internal links: #1 engagement models, #4 timezone overlap, #9 field service buyer’s guide, /about, /contact. External references: national company registers (Companies House, MCA India, etc.); ICO guidance on international data transfers where relevant. CTA: “Happy to be vetted this way — ask to meet the engineers first.” → /contact