Leap to Scale
Leap to Scale is for technology curious leaders of service firms who want higher margins without adding headcount. Each week, Justin Davis and Greg Ross-Munro show how to turn firm expertise into repeatable, sellable technology products: SaaS, packaged workflows, and AI-powered tools clients can buy again and again. With AI, more of your know-how can be captured, standardized, and protected as IP instead of being rebuilt in every engagement.
We focus on practical decisions: what to productize, how to price it, when to build vs. buy, and how to use AI responsibly without risking delivery quality or margin. Clear steps, real tradeoffs, usable examples.
Leap to Scale
Questions to Ask Your Software Development Company
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The search for the right software development agency for your project can be daunting, especially if this is your first time having custom software built!
In this episode, Sara Altenhoff is joined by Greg Ross-Munro and Gregg "3G" Hilferding to discuss some important things to consider as you vet development agencies. Tune in to learn which questions you should ask about the agency's team, liability, compliance, and previous work.
Welcome to Decoder Podcast, where we step inside the world of a software development agency and learn how bits and bytes become useful technology. Each episode features conversations with creators and users about the process, challenges, and fun of building software. Intended for a non-technical audience, this podcast will help you understand how software is built so you can more effectively engage with software developers for more successful projects. Hello. Welcome to Decoder Podcast. I'm Sarah Altenhoff, and I'm here today with Greg Rossman Roe, CEO of Source Toad, and Greg 3G Hilfertine, VP of Delivery at SourceTode. Hello, Gregs.
SPEAKER_00Hi, Sarah. Hi, Sarah. Hi, Greg. Hi, Greg.
SPEAKER_02So on today's episode, we're going to talk about a really important topic, which is how to vet a potential software development agency. So if you've reached the point with your team where you've recognized that you have a problem that needs to be solved with technology, and it's a big complex problem that is perhaps unique to your business or unique to your industry, you've looked into existing off-the-shelf solutions, but you're not really finding anything that's quite a perfect fit. So you've decided it's time to reach out to a custom development agency and invest in something custom built just for you. You've got a budget in mind, and maybe you're looking around your network for potential agencies to be referred to you in your researching, and you're reading online reviews and you're doing diligence. But having never gone through this process before, it can be hard to know what kind of questions to ask once you start having conversations with software development agencies. So that being said, since Source Toad is a software development agency, we can help give you an insider's perspective on what questions to ask and what might be a red flag or a green flag to help make sure you find the right partner for your project. So uh why don't we begin with 3G? Um, what are some initial questions that you would ask if you were having a first meeting with an agency to begin vetting them?
SPEAKER_00Well, I think the very first thing that I'd want to know is what their specialty really is. And that's really gonna make a difference. Uh, there isn't a right answer to this. It really makes a difference of what type of technology product I'm building. Um, there's a lot of agencies that do development work, but they're not all dedicated development agencies. You have some that are design agencies who have branched off into doing development. You have marketing agencies who have, you know, hired some developers and are building stuff for their clients because there's the need out there. And depending on what product you're building, you really want to know where they started because that's going to tell you what they're going to be best at. And you have to make sure that that's a good fit for the thing you're trying to build.
SPEAKER_01If you I mean, you look look at us. Um we we're a software engineering company. We didn't build our own website. Exactly. We yeah, I mean, I mean, okay, first of all, like the cobblest children have no shoes, right? But I mean, we we build a lot of we build a lot a lot of web technology. We could totally have built our own website, but we're not like a website development, like a website marketing website company. So we knew that we shouldn't do that. So we um hired a web development, web design company, sorry, web design company that was kind of more on the marketing side to do that. And we had a marketing person run that project rather than you know a product owner or slash technologist kind of person.
SPEAKER_00Yeah, exactly. And even with some of our projects, we will, you know, because we are a development agency and we're really there solving like the difficult technology problems, like the complex business problems. Um, you know, we sometimes work with design agencies and work with marketing agencies. They bring their expertise, we bring our expertise, and then, you know, the product in the end is everything that it needs to be, not just the specialty of one of the agencies involved.
SPEAKER_02Yeah, so it's good to right off the bat find out what their specialties are and see if that's the right fit for your project.
SPEAKER_00Exactly. And I'm most of a most agencies will have some sort of portfolio. If it's not online, they, you know, it might be something that you need to sign an NDA in order to get a presentation of past projects that they've worked on. And that's gonna tell you a ton about what their strengths are because they're gonna be showing you the best work they've done. And if you're building something that needs to be beautiful and everything they've built is beautiful, you are probably at the right place. And if you need to solve complex problems, but everything they show you is just beautiful, um, you're probably not in the right place. And you need to find a better fit.
SPEAKER_02Yeah. So um, other than first of all, figuring out like what their specialties are, um, what kind of questions would you ask about the company's team and how uh what roles they have on their team, um where the team is based, um, how large the team is, uh, stuff like that. What do you think?
SPEAKER_01I mean, the to kind of go back a little bit to Greg's point about um how like design agencies and marketing companies and advertising firms, like typically almost all of them eventually at some point branched out in the last 10, 20 years into doing some sort of digital work, right? That that's just it's not possible to live in this day and age without uh playing in the digital space. So they will have developers or design or like web developers or some something like that on their team. And a lot of the time uh those agencies will have also uh started outsourcing um as well, some of their, or you know, like they'll find a company in uh India or Eastern Europe or Central South America, and they will white label the agency that actually runs the team there, and then they'll kind of present that as their their dev team. Or in some situations they'll partner with a company like us, right? Like we'll uh and we partner with marketing companies. That's a little more that's a lot more transparent to the client where it's like, hey, this is our development partner, source toad or whatever, something like that. So and then the marketing company will bring us bring us in. The same way that a good relationship with um with our clients, sometimes we'll see somebody come in uh and they want to build something and they really need a marketing or design company to help. And we have like partners that we'll bring to the table in that situation. So uh so when when you're asking about like who the personnel are who are building it, you're gonna hear like I think two typical answers. One is they'll start like showing you resumes, or they'll have like a deck of who the people are and where they're based, and that's a positive sign. Or they'll give a song and dance about how well we don't really like to have developers um be known to our clients because we don't want them to be stolen, or we don't want them to move jobs, or um we want to protect the team. Those are reasonable things to say, but those are contractual issues, those are things that like non-solicitation clauses are common in development contracts. You you don't have to like hide the people's faces. If if you don't know the names of the people who are working on your software, it it can it can be a suspicious red flag sign, like that those developers do not actually work for this company that you're talking to. Um there are quite a few firms that we run into, especially in the United States. And I say firms, but I mean they're like they look like a development agency, they quack like a development agency, but they're not a development agency, right? It's like it's some dude um or like him and like three salespeople uh who are who have like a dev agency that they have white labeled in Eastern Europe or India or Central South America, who this is their business model. They find representatives inside the United States or inside in uh the UK or France, and they will um get these like salespeople, like franchise guys, and they will they'll go and they'll get them to sell saying they're their own agency. And so you'll uh if you go look at their LinkedIn pages now, and you'll like look for the developers who work there, they've all worked on like six different companies over the last like six years, and it's not because they're hopping job, it's because whichever project they were on for the longest, they put that on on the LinkedIn page because there's no there's no way to prove that. And so it looks like these developers have just moved from job to job, and now they're maybe at the finally at this agency. So they're they're not they're not actually employees, and they don't necessarily care about your product, and they don't necessarily um they're not necessarily invested in what you're doing, and they might just be moved to another project tomorrow. And that's why it's a bad thing. So I should have already led with that, like, hey, there's a reason why you don't want that.
SPEAKER_00Yeah, and I think that you know, when you're at the early stage of a project, you are thinking about building it. And so if you can find someone who says they're gonna build it, then you're like, yeah, I'm good. Like, this is this is what I need. I need someone to build it. The thing is with almost all software is that you're never really gonna be done building it if it's successful. And that means that whoever you start working with, you're gonna be with them a long time. And if you're gonna be with them a long time, you probably want the team to be with your project for a long time, too. So if they're contractors and you the initial build is a six-month contract, that contractor might just move on to something else after that. And now suddenly you are watching the whole team change out from under you. And the new folks, they didn't build it. Um, they might come in and say, Oh, this thing, oh gosh, we have to rebuild the whole thing. And you thought you had a long-term relationship, but what you really were doing was just kind of hiring a contractor through somebody else, and you're rebuilding your team every six months. And it's not gonna feel good, yeah.
SPEAKER_01And and I mean, to some sometimes that's the business model, right? Where uh there's a company that I kind of respect, I quite like the way they do business, they're a big development company. Um uh, but you know, times are tough and um cost cutting is required. So the way they often they got acquired, and their business model now is um that when you uh when you sign up the team, you know, they're a big uh development company, they they do work on like massive projects, and so you know, they have like blended rates of two and two hundred fifty dollars an hour, whatever, and you sp you're you're some big fancy company, and you hire a team of 15 people or a scrum team of under six or seven uh coming out of this this agency, and everyone is like there's seniors and mid-level developers only, and they and architects, and they all know what they're doing, and they're all good with the client. And the client shows up on the Zoom call for day one, and everyone is like super enthusiastic, and the first like couple weeks of work are just like amazing, and then after like week six, um you know John disappears from the team, and now Susan joins the team, and that's fine, right? Like, it's not a problem. But what you don't know is that, or what you didn't, what the client doesn't know at initially is that Susan is kind of a mid-level developer living in um in Peru, and that's totally fine. Um, and but her her rate now, instead of being like part of that blended rate, the company's rate has gone down, their effective rate has gone down. And three more weeks go by, and now um, you know, uh Melissa has left the team and is joined by uh Alejandro, and Alejandro's living in Colombia, right? So what they'll do is they'll slowly but slowly remove all the like the high-level native English speaking senior developers, like one by one, slowly, like boiling a frog, until you have now got a completely kind of near-shore or offshore team that you did not actually sign up for and did not start with. There's nothing wrong with near-shoring and offshoring, but typically what you want is as many native speaking um uh developers from the same country that your product is going to be released in if you want a good, like a great successful product that like fits all the cultural boundaries. So maybe half the team is offshore or something like that, but you need that core. And if they're slowly replacing that as part of their game plan, that's something you should watch out for.
SPEAKER_02So, like, what kind of question could you ask a potential agency to prevent that situation from happening from them impressing you at first with the big song and dance and then slowly phasing out all of the really experienced people and then phasing in uh less experienced offshore people? Is there anything that you could ask up front to to figure out if that's going to happen?
SPEAKER_01Yeah, so it's uh I mean it's a really, really good question, right? So you you it's probably tough to talk to somebody in the sales department about um what you know, what is gonna happen six months from now? Is my team gonna stay the same? You can ask them that question, but you you know, even the best salespeople are known to like kind of just bend the truth a little bit. So um the the best thing to do is to talk to their clients, right? Um you know, ask for referrals or two. Um uh my suggestion is typically asking for three referrals. Um and uh that's it's so much work, it's like it's it's annoying and and it can be kind of uncomfortable. You know, you've got to call somebody up at some other company and say, hey, was you know the um the the blue the blue elephant development company were they're really good? Um you know, how did the project work for you? And um, you know, you don't want to like interrupt someone's day, but you have to do it. You just have to have to actually send that email or call that company because um they're gonna tell you a little bit about the process. And don't ask them, like, are you happy with them? Because they wouldn't give you those people as a reference if they weren't like happy clients, right? I mean, that I to be honest, I have seen I've seen like uh bad references before where you actually call the person up and they're like, they're terrible. I don't know why they gave you my phone number. Um that's I've I've literally seen that happen. I'm like, what? That is strange. But don't ask them about like, was it a good project? Was it successful? Um, talk ask them specific questions about like, hey, what happened to the team over time? Did were they able to was the quality the same at the beginning of the project as it was at the end? Or like, are you still working with them? What you know, what specifically do you like about working with this team that um makes you want to continue to work with them? So those are the questions I think uh you need to ask, and you can't ask those to the actual company themselves, you've got to go to the referrals. I don't know if Greg has a some like cool trick up his sleeve.
SPEAKER_00Yeah, no, I think going to referrals is really important. I think there is an angle here though to ask the agency themselves, and this kind of goes back to like asking them about the team. So some agencies will can provide a ton of roles for a project. They can give you a project manager, they can give you uh they can give you developers, they maybe they have a UX designer, maybe they have QA people. All those roles that are involved, I think that's the angle to ask the question, which is what kind of like as the project progresses, who is going to be doing these different parts? Am I doing all my own testing? Are you doing some testing? Am I providing you designs? Are you doing the design work? And that kind of helps you pick apart like what is the team? Like who are the like who are the people that I will be interacting with for hopefully the next five years, 10 years, if the product is a if the product is successful. And so I think it's very good to talk about those roles. Um, ask what is expected of you from the client, because if they're expecting you to spend 10 hours every week testing the latest beta build, you probably want to know that upfront.
SPEAKER_02Yeah.
SPEAKER_00Right? Like that probably shouldn't be a surprise. Um, and asking those questions kind of gets back at what we're talking about, which is like, who are you interacting with? Who are these people that are building and supporting this product? Um, and it's okay to ask those questions, and an agency should have answers.
SPEAKER_01And um, you can also ask them like who their newest client was if you can speak to their newest client, and also maybe their oldest client, right? And they they obviously have the right to tell you no, or like there's a reason why you know things aren't going well in a particular project, nothing's perfect. Um, and maybe your newest client is having a speed bump and they're like, Can you not talk to them right now? But you will see how they react when you ask those questions as well.
SPEAKER_00So um, yeah, I think even asking, like, do you have a client who has a project that is similar in size and scope to what we're talking about building together? Um, because they may have a really successful client whose business is 20 times bigger than you're going to be, or they might have a really successful client who's like a one-person startup and you're trying to build an enterprise product. And again, those referrals, when you ask them questions, it's all couched in the context of what they're trying to do with the agency. And what works well with some sizes of clients may not work well with you if you're a different size.
SPEAKER_02Okay. So what about other considerations like liability insurance and compliance? Um, what types of things are.
SPEAKER_01Well, the exciting stuff, huh? Sarah from you.
SPEAKER_02What types of questions do the Greggs think you should definitely ask during the vetting process to make sure that um this agency is secure and compliant, and also you won't get burned on the liability side of things?
SPEAKER_01So I can I can tackle the I'll tackle the liability um stuff to start with. Um and maybe kick the um compliance stuff to Greg in a minute. But uh as it as every political answer starts, it depends. And it depends on what you're trying to do. If you are a um single founder startup and you're just trying to get a proof of concept out the door, you're probably looking for fast and cheap. And fast and cheap does not mean that they're gonna have like a HIPAA uh compliant certification, and they're definitely not gonna carry like five million dollars in cyber liability, right? Um so but if you are a um you know uh regional hospital chain, you're gonna you're gonna want to see some some proof before you you uh engage with a an agency. And and so you're not gonna be able to pick, well, hopefully you're not gonna be able to pick um certain companies. They're gonna be just be excluded based on your requirements. And that's fine, but you should know what those are going in. If you are that re regional hospital chain or you're a financial institution, you really have to um know what kind of compliance and insurance levels you're even looking for. Like that you you should understand that before you just start picking up the phone and asking your buddies if you know if they know someone who can like build you a an app. Um, because everyone is gonna say, yeah, we can build you an app, and they're not gonna have the controls or the insurance or the whatever in place, so that you can um uh you can continue your compliance. Uh insurance insurance is a is a is a crazy one, right? Like insurance has gotten so expensive recently. Um cyber insurance especially uh is has become problematic the more um the more hacks there've been over the past few years, the more like leaks there've been. Every time that happens, cyber insurance it goes up. I think it's for us, I think it started at something like I don't know, five thousand dollars a month or whatever, which is not that much, but it's still probably quite a burden if you're a tiny dev company. Um I think it's now up in the 30s or the 40s for us. And um, you know, that's that's a lot of money for some people that for some like smaller agencies, that's a full time employee just in cyber insurance. And I'm sure next year it's Gonna double or triple like it has in the past, and it's just cost of doing business because when we sign contracts with large companies, they want to be uh or they require part of their legal departments to be listed as a co-insurer or a co-claimant on our insurance, and that's totally fine. That's something that you should ask is like, hey, can we be listed as a named entity on your insurance? And it's pretty common in the contracting world, right? So you definitely want to make sure that I would say if you're if you do any more than like $10 million in revenue a year as an organization, you're looking for a dev company that at least is carrying $2 million in cyber insurance. Um I I hate to say that because it's such a pain in the ass, to be honest, but it's it's it is it is it it means that you have to take other things seriously to do that. Um I don't know. The it's just one of those, like if you're looking for serious people doing serious stuff, there are there are costs to working with serious people. Um, and compliance is one of them. I'm sure Greg deals with a bunch of like compliance issues all the time that that maybe you should be looking for as well.
SPEAKER_00Yeah, on the compliance side, I think you've covered that really well. There's again, it's the industry-specific things that you know there's you won't necessarily by hiring someone who has worked on if you need to be HIPAA compliant, like what you're looking for is an agency that has built uh HIPAA compliant products before, because they've had to navigate that already, and you're not going to be paying them to learn how to do it, right? Someone else paid them to learn how to do it, and they've if they've done it a few times, they're actually really good at it now. They've figured out the fastest ways to get to meet the compliance requirements. Um, and those specific ones, you know, it's like if you're gonna operate in Europe, you need to, you know, finding an agency that has dealt with GDPR is an important thing that's gonna save you a ton of time and money if it can be uh built with that in mind from day one. There is one certification that's really interesting, and that's a a SOC, uh a SOC or a SOC 2 certification. And that one is that is something that the actual agency can carry that certification themselves. And what that signals to you is that they have an actual process for changing code. And what that means is that their engineers can don't have keys to the server, they can't just go and upload whatever code they want whenever they want to. It has to go through a multi-step process, which uh somebody has to approve it. That is a different person than the person who wrote the code. And that's a really interesting one because that obviously has to slow things down, right? But if you are building like a financial system, you obviously do not want anyone to be able to upload code to your server because they could be uploading code that's going to be uh stealing clients' sensitive data and shipping that off to be sold to the highest bidder.
SPEAKER_01Even if the database is separated out, they can write some code like a backdoor that will then like siphon stuff out of the database and send it to them somewhere else.
SPEAKER_00Yeah, and there's a ton of answers there where it's like, oh, we have encryption at rest. Like, well, that doesn't really matter. If they can push up code, then they can get around that. Um and so SOC compliance is a really uh a really interesting one because it does mean that there's a process that has to be followed. Process means overhead, but as soon as it's real, the product you're building, that is the process you're going to want. And if they don't have that kind of thing, then you really want to dig into what is their process, what are the protections, um, you know, how do they keep those situations from from being possible? But if they have the sock compliance, you know they've already been they've already gone through all that, it's already been handled by somebody else.
SPEAKER_01And if the stock compliance is like being audited more than one year, more than like you they've had it for more than a year in a in a row, right? So like if you're going through your first order, yeah, I can't believe we're talking about this. But it's it's it's it's really important. Like, so I mean on on on the on the HIPAA side, there's um there is one um there is one other thing just to briefly touch on. If if you do need to build HIPAA software, HIPAA compliant software, like if you're if you have anything that deals with patient records or um PII personal, but uh PHI personal health information or protected health information, sorry, um you have to um you will want to become a HIPAA-certified uh organization, right? Like you're building, or you are a HIPAA-certified sort of organization. Let's say you're building a virtual pharmacy or telehealth system, whatever it is, it needs to be HIPAA compliant. Um, there's something called a BAA, which is uh uh uh like a pass through which says that the companies, though your providers below you are also um compliant. Um and if I think it's called like a business associate agreement, business associate agreement, and you can't uh sign a BAA as a vendor uh unless you are actually going to follow the HIPAA compliance laws, and then you have to be HIPAA certified. So you don't have to sign BAAs with all your vendors if you are a HIPAA-certified organization, but when your audit comes along, it's just gonna be more challenging and more difficult. So if you do have to do that, go and find somebody who can sign a BAA and who is HIPAA who has a HIPAA certification because otherwise it's gonna make your life miserable. The other thing you can do, which is kind of what happened to us, is the very first time, I don't know, years and years ago that whenever this happened, was that we had a client who knew that they wanted us to be able to sign that BAA, and we didn't have it yet. And so they just were like, hey, we really like you as developers, everything you do has been like amazingly good. You've got the SOC certification already, so there's not like a huge, huge jump to add the controls that you need to get that HIPAA compliance. So they basically said, Look, we'll we'll go in 50-50 with you, we'll pay for you to like learn this painful process, and at the end of the day, you're gonna have something that's a competitive advantage, whatever. So you can, if you find a development company who's like flexible enough and you're prepared to pay them to get those certifications, you can also do that. Like you can invest in them, and that'll be a good way to build that relationship with them into the future.
SPEAKER_02Yeah, and it's also probably important to keep in mind that just because your software is HIPAA compliant, that that doesn't make your organization HIPAA compliant, because that's up to you, right?
SPEAKER_00Um Yeah, and that's the thing with all of those compliances. And again, oh my gosh, I'm trying not to yawn. But the um we had we should have had a better guest on to talk about this stuff. We have the experts here.
SPEAKER_02We could do a whole compliance episode.
SPEAKER_01I got some black washing my hair that day.
SPEAKER_00Yeah, but so the thing about most of those is that like most of those, you can't just claim ignorance about them. Like you can't say, well, I hired this development agency and I thought they were gonna do the right thing. Um, you can't end up delegating that that responsibility in a lot of cases, unless it's a certification that specifically allows that pass-through, like Greg was saying, and that that that vendor does actually sign those sorts of agreements. So it's definitely an area. If you're playing in that one of those spaces, it's something you gotta know and something you should bring up right away, because not all agencies are set up to handle that.
SPEAKER_02Well, um, other than the compliance talk, this has been a great discussion. No, I'm just kidding.
SPEAKER_01I'm just kidding, and super exciting.
SPEAKER_02So, yeah, as you're vetting a development agency, um, just to recap, make sure you find out what their specialties are, what their team actually looks like, and where they're located. Find out about their compliance. Um uh try to get some referrals to other clients if you can, new clients and old clients. And yeah, just make sure you're doing your due diligence and all the work that you do ahead of time will certainly pay off when you get the beautiful piece of software that works exactly how you want it and is beautiful. So um, yeah, thank you for joining us today, dear listeners. If you would like to get more insight into the world of software development, subscribe and follow Decoder Podcast. And until next time, have a great day.
SPEAKER_01Thank you, sir.
SPEAKER_02Thanks, Gregs.