The clearest red flags when hiring a software agency are: they will not name the actual engineers who will build your product, they refuse to fix scope or price, they leave source-code and IP ownership vague, they route all communication through a salesperson, and their quote is far below everyone else's. Each of these predicts a bad outcome, and each can be exposed with one direct question the agency must answer on the spot. This checklist gives you the warning signs and the exact questions that force the truth out — use it before you sign anything.
Why red flags matter more than references
Any agency can supply three happy references and a polished deck. What they cannot easily fake is a direct, specific answer to a hard question under mild pressure. Red flags are useful precisely because they are hard to disguise: an agency that plans to staff your project with juniors cannot comfortably name senior engineers, and one that intends to lock you in will get evasive about the contract.
Your job in the evaluation is not to be impressed. It is to ask the questions that make evasion visible, then watch how they respond. Confidence and specificity are good signs; deflection and "we'll sort that out later" are not.
Red flag 1: they won't tell you who writes your code
The most common trap in Indian software procurement is the bait-and-switch: senior architects in the sales meeting, junior developers in delivery. The agency wins on the strength of people who will never touch your project.
The question that exposes it: "Can you give me the names, experience, and portfolios of the specific engineers who will work on my project?" A senior-led team answers immediately with real names. An evasive team gives you titles ("our senior developers"), talks about the company's overall experience, or promises to "assign the right resources" — which means they do not know yet and it will be whoever is free. Insist on named people, and make it a contractual commitment.
Red flag 2: they won't fix scope or price
For a defined product, an agency that will only work time-and-materials with a vague statement of work is either unable to estimate or wants the meter running indefinitely. Open-ended billing transfers all the risk to you.
The question that exposes it: "Will you commit to a fixed price for this written scope, and what exactly happens when scope changes?" A confident team gives you a fixed number against a clear scope and a transparent change process. A red-flag team keeps everything hourly, resists writing scope down, and cannot tell you what a change costs — which is how a ₹3 lakh project quietly becomes ₹6 lakh. Sanity-check any number against the project cost calculator, and read the hidden costs of cheap software development for how vague scope becomes expensive.
The red-flag / green-flag checklist
| Area | Red flag | Green flag |
|---|---|---|
| Team | won't name engineers; senior in sales, junior in delivery | named senior engineers, in the contract |
| Pricing | hourly only, vague scope, "we'll estimate as we go" | fixed price against written scope |
| Ownership | code lives in their accounts; IP terms unclear | full source, IP, repo transferred on payment |
| Communication | all contact via salesperson / account manager | direct access to the engineers |
| Quote | far below all competitors | in line with the market for the scope |
| Handover | no documentation or KT mentioned | documented handover + knowledge transfer |
| Support | mandatory, opaque lock-in AMC | optional, transparent AMC pricing |
If a shortlisted agency lands in the left column on ownership, communication, or team, that is usually enough to walk away — those three are the hardest to fix after you sign.
Red flag 3: ownership left vague
This is the most financially dangerous flag. If the contract does not explicitly transfer source code, IP, and repository access to you on final payment, you may finish the project owning nothing but a running app you cannot touch. Switching vendors or adding a feature then means rebuilding from scratch — ₹3–5 lakh to reconstruct what you already paid for.
The question that exposes it: "Does the contract assign me full source code, IP, and repository and infrastructure access on final payment — in writing?" The right answer is an immediate yes and a clause to point to. Hesitation, "we host it for you," or "the code stays on our servers for support" are all lock-in in disguise. Ownership is central to how you choose a software company in India; do not compromise on it.
Red flag 4: you never talk to the builders
If every conversation runs through a salesperson or account manager and you are never allowed to speak with the people writing code, expect slow, distorted communication and no real insight into progress. Layers exist to manage juniors and to control the narrative — neither serves you.
The question that exposes it: "During the build, will I communicate directly with the engineers, or only through a project manager?" A senior custom software development team gives you direct access as a matter of course. A body shop insists on the buffer. Direct communication is not a luxury; it is how wrong assumptions get caught in hours instead of sprints.
Red flag 5: the quote is too good to be true
When one vendor quotes ₹2.5 lakh and everyone else is at ₹8 lakh, that is not a bargain — it is a signal. The low number is made possible by cutting something: seniority, testing, documentation, or ownership. The saving is an illusion that reverses through rework and change orders.
The question that exposes it: "Walk me through what's included at this price versus a higher quote — what are you doing differently?" An honest agency can explain a genuine efficiency. A low-baller gets vague, because the real answer is "juniors and no tests." Cheap upfront is almost always expensive over two years — the arithmetic is in our hidden costs breakdown.
Red flag 6: no documentation or handover plan
An agency that never mentions documentation, knowledge transfer, or handover is planning to keep you dependent — whether by design or by neglect. Undocumented software is software only they can maintain, which quietly converts every future change into a call to them at whatever rate they choose.
The question that exposes it: "What exactly do I receive at handover — documentation, deployment instructions, credentials, and a knowledge-transfer session?" A senior team treats this as a normal part of delivery and can describe it without hesitation. A red-flag team is surprised by the question, promises to "provide docs" vaguely, or frames proper handover as an extra you must pay more for. Clean handover is how you own what you paid for; its absence is a slow-motion lock-in that only reveals itself when you try to leave.
Red flag 7: mandatory, opaque maintenance lock-in
Support and maintenance are legitimate and worth paying for — but they should be optional and transparently priced, not a mandatory tether. Watch for agencies that make ongoing AMC compulsory, refuse to quote it clearly, or structure it so that only they can ever touch the product. That is lock-in dressed up as care.
The question that exposes it: "Is post-launch maintenance optional, what does it cost per year, and could another vendor take it over if I chose?" The healthy answer is that AMC is optional, priced in plain INR, and portable because you own the code and documentation. If the answer is that support is mandatory and the code stays with them, you are not buying a product — you are renting one indefinitely. The hidden costs of cheap software development almost always include a lock-in AMC like this.
How should I run the evaluation call?
Bring the checklist above and ask the five exposing questions in order: who writes the code, fixed price or not, ownership terms, communication path, and what the quote includes. Do not soften them or accept a deferral to "later." Then judge the quality of the answers, not the confidence of the pitch — a smooth salesperson can sound great while dodging every specific.
Take notes on evasions. One vague answer might be nerves; two or three on ownership, team, or pricing is a pattern, and the pattern is the prediction. The agencies that answer all five directly are the ones worth a paid trial milestone. For the deeper decision framework around these calls, see in-house vs agency vs freelancers vs big offshore firm.
Where NexaEx fits
NexaEx is built to pass this checklist. We are a senior-led, remote-first team registered in Erode, Tamil Nadu, serving clients across India and worldwide. Senior engineers only — named in your contract, no juniors, no hand-offs. Fixed price against a written scope. Full source-code and IP ownership transferred to you on payment. Direct communication with the people building your product. Transparent INR pricing with optional, clearly-priced AMC. We build web platforms, mobile apps, and AI solutions the way this guide says an agency should. See our full services.
Talk to us
Evaluating agencies and want a second opinion on a proposal? Contact NexaEx or message WhatsApp +91 97912 97741 — send us the quote and scope and we will flag anything that looks off, even if you end up hiring someone else. We reply within 24 hours.
Frequently asked questions
What are the top red flags when hiring a software agency?
They won't name the actual engineers, they refuse to fix scope or price, ownership terms are vague, all contact runs through a salesperson, and the quote is far below everyone else's. Each predicts a bad outcome and each can be exposed with one direct question on the call.
What question exposes an agency that will use juniors?
Ask: 'Can you give me the names, experience, and portfolios of the specific engineers who will work on my project?' A senior-led team answers immediately with real names. An evasive team offers titles or promises to assign resources later — meaning it will be whoever is free.
How do I make sure I own my source code?
Ask whether the contract assigns you full source code, IP, and repository and infrastructure access on final payment, in writing, and point to the clause. Answers like 'we host it for you' or 'the code stays on our servers' are lock-in in disguise; do not compromise on this.
Should maintenance be mandatory with an agency?
No. Support is worth paying for, but it should be optional and transparently priced, not a compulsory tether. If AMC is mandatory, unpriced, or structured so only they can touch the product, that is lock-in dressed as care. You own the code, so another vendor should be able to take it over.