You have a shortlist of offshore development companies, and every one of them looks good on its own website. The portfolios are full, the testimonials glow, and the first call is friendly. The decision in front of you is not whether offshore development works. It is which of these partners will actually ship your product, and which will quietly cost you six months and a rewrite. This checklist is how you tell them apart.
The hard part of choosing is that the easiest things to see are the easiest to fake. A polished site, a low quote and a warm sales pitch feel like information, but any vendor can produce them in an afternoon. The signals that actually predict a good build take a little digging and are much harder to stage. What follows is that digging, turned into a scorecard you can run on every company the same way.
What does it mean to vet an offshore development company?
Vetting an offshore development company means confirming, with evidence, that the team can build your product, will treat your code and data as yours, and can communicate well enough to work across an ocean. It is due diligence on a software vendor: proof over promises, reference calls over written reviews, and a small paid test before a large contract.
Most founders vet on the wrong signals, because the wrong signals are the loudest. A slick deck and a cheap price feel decisive, yet they say almost nothing about how the app will run a year after launch. The eight points below are the ones that do predict it. Score every company on the same list, including the one you already like, so you are comparing like for like instead of choosing on gut feel. If you are still deciding whether to go offshore at all, start with the guide to outsourcing app development to India, then bring your shortlist back here.
Does their portfolio show real, shipped products?
A real portfolio is made of products you can open and use, not screenshots and concept art. Ask for live apps in the App Store or Google Play, or working websites, and ask exactly which parts the company built. A strong vendor sends you links in seconds. A weak one sends a slide deck of designs that never shipped.
Many agencies show work they only styled, or prototypes that never reached real users. So push past the gallery. Ask the direct question: which of these did you build end to end, and which did you only design? Then test it yourself. Open the app, make an account, click through a real flow, and read the reviews. Check the developer name on the store listing against the company you are talking to. A product that has been live for a year with real users is worth more than ten polished case studies. For example, appico built cGen, an AI compliance platform used in regulated pharma, and GoldKitty, scheme software for jewellers. Both are live products a buyer can go and look at, which is the standard to hold any vendor to.
Who actually writes your code?
The people who write your code should be senior engineers, named, and the same ones who turn up on your calls. The common trap is a senior team in the pitch and juniors on the keyboard after signing. Ask who will be assigned to your project, how many years of experience they have, and whether the team changes partway through.
Seniority matters because the parts that decide whether an app survives are senior decisions: the architecture, the integrations, the security and the hardening. Juniors can build a screen. They tend to miss the things that break under real traffic. Ask for the specific people, their experience, and a short call with the engineer who would lead the build before you sign anything. On cost, there is an honest reason offshore senior talent is affordable: a senior engineer with around ten years of experience in India runs roughly $20 an hour against roughly $200 an hour for the same experience in the US. Treat that as a typical senior rate rather than a market statistic. Talent there is abundant, so a serious partner can staff seniors quickly instead of padding the team with juniors to hit a low price. The guide to hiring offshore developers in India goes deeper on reading a CV and running a technical screen, and the comparison of how agencies, freelancers and AI builders stack up helps if you are still choosing a model.
Will real clients vouch for them?
Ask to speak to two clients from the last year, and actually make the calls. Written testimonials and directory stars are easy to collect and hard to verify. A single real reference call, with a client who picks up and talks honestly, tells you more than a page of five star quotes ever will.
On the call, ask the questions a case study never answers. Did it ship on time? What broke after launch, and how fast was it fixed? How did they handle a disagreement about scope or a bill? Would you hire them again, and for what? Try to speak to a client whose project was about the size of yours, since a tiny website says little about a payments app. If a vendor cannot produce one recent client who will take the call, that silence is your answer. appico has testimonials on record from founders and product leads at companies including Oyelabs, JamesEdition and Nestroots, but you should still ask any vendor, appico included, for a live reference.
How do they handle your security and data?
A trustworthy vendor can explain, in plain words, how they limit who sees your data, how they control access to your systems, and what happens to that data when the project ends. If your users are in the UK or EU and the vendor handles personal data on your behalf, they should also be ready to sign a written data processing agreement.
That written agreement is not optional paperwork. Under UK and EU data protection law, when another company processes personal data for you, the relationship has to be set out in a contract. The UK Information Commissioner points to the rule in Article 28, that processing by a processor "shall be governed by a contract or other legal act" binding on the processor, on its official guidance. Rules differ by country and by the kind of data you hold, so confirm the specifics with your own legal adviser rather than taking a vendor's word for it. Beyond the paperwork, ask the practical questions: who on their team gets access to your production systems, and can you remove them the day the project ends? Do they keep secrets and API keys out of the code? Do they work on least access by default? A vendor who treats these as obvious is a far safer bet than one who waves them off.
Who owns the code, repos and accounts?
You should own everything the moment it is built: the source code, the git repositories, the domains, the cloud and the app store accounts, all in your name. Get it in writing before work starts. If ownership only transfers at final payment, or the accounts live inside the vendor's organisation, you do not really own your product, you are renting it.
The usual trap is quiet. The vendor hosts the repositories in their own account, registers the app under their developer profile, and keeps the domain in their name. It all works fine until you want to leave, and then you find you cannot take the keys with you. So insist on four things from day one: repositories in your organisation, every account in your name, a written IP assignment, and an NDA on request. This is a line appico does not bend on, and it is the line to hold with any partner. The exact clauses to ask for, and the order to get them signed in, are in the guide to protecting your IP when you outsource to India.
Can you communicate, and do your hours overlap?
Clear written English and a dependable daily overlap matter more than sitting in the same time zone. Ask how many hours your working days overlap, who your single point of contact is, and how quickly they reply. A few hours of real overlap, plus good written updates, beats a full shared day spent waiting on slow, unclear answers.
Work the time zones out before you sign, not after. India sits far ahead of US clocks and much closer to the UK. A founder on US Pacific time and a team in India share only a sliver of the day, so the fix is a fixed overlap window, often the founder's early morning, for one daily call, with everything else handled in writing. For a UK founder the shared window is wide and easy. Ask for a named project manager, a shared board you can read any time, and a staging link so progress is visible without a meeting. Test the English on the first call and in writing too: a clear, well organised written proposal is itself a good sign. The daily rhythm of this is covered in working with an India dev team across time zones.
Will they do a small paid trial task?
The single best test is a small paid trial: a scoped, paid slice of real work before the full contract. For a modest amount of money you see their code, their communication and their ability to hit a deadline. A confident vendor says yes. One who will only take the whole project, signed today, is telling you something worth hearing.
Keep the trial small, real and paid. Paid matters, because it means they take it seriously and you own what they produce. Then judge the result on the things that will repeat for the whole project. Did it arrive on time? Is the code clean, readable and documented, or a tangle? Did they ask sharp questions about your users, or just do exactly what the ticket said? Did they keep you posted without being chased? Trust is earned one rung at a time, and a trial lets a vendor climb the first few rungs cheaply.
Is the price a fixed scope, or an open meter?
Ask for a fixed scope with a clear price tied to milestones, not an open hourly meter with no ceiling. Fixed scope means the number is attached to a written list of exactly what you get. And be careful with the cheapest quote: in software, the lowest bid usually means missing features and a rebuild later, which costs far more than it ever saved.
This is where cheap builds quietly break. The corners that get cut to win on price are the ones you only notice after launch: must have features left out, payment reconciliation that does not add up, weak re-engagement, and the poor reviews that follow. As the hard version of this goes, cheap apps do not succeed, and it is better not to build one than to build a bad one. So weigh affordable and senior against cheapest, and compare on scope and proof rather than the headline figure. It helps to have published numbers to anchor against. appico lists starting prices openly: a website from $1,000, an MVP from $10,000 with source code and deployment included, a mobile app from $12,000, and larger builds up to about $150,000 depending on depth, with maintenance as a separate monthly plan. Published guarantees to ask any vendor to match are milestone payments, a staging link by day three, and a bug fix window after launch. For how offshore pricing really compares against building at home, see the breakdown of US vs India app development cost, and the MVP and product development work is built around exactly this fixed scope, milestone shape.
One more question separates a modern vendor from a slow one: how do you keep cost down without cutting corners? A good answer in 2026 is using AI to compress the early phases, the scoping, the documentation, the UI ideation and turning an approved design into front end code, for roughly a 40 percent saving on that part, while keeping human engineers on the architecture, integrations, security and hardening. That mix is the appico approach, and it is a fair thing to ask any company to explain in its own words.
| What to check | Question to ask | What a good answer looks like |
|---|---|---|
| Shipped products | Which live products did you build, and can I use them now? | Links to real apps and sites, and which parts they built |
| Team seniority | Who exactly will write my code, and how senior are they? | Named engineers with real experience, the same ones on calls |
| Client references | Can I speak to two clients from the last year? | Two recent clients who pick up and talk |
| Security and data | How do you protect my data and limit your access? | Least access, secrets kept out of code, a written data term |
| Ownership | Who owns the code, repos and accounts at the end? | You do, from day one, put in writing |
| Communication | How many hours a day will our teams overlap? | A set overlap window and one named point of contact |
| A paid trial | Will you do a small paid task before we commit? | Yes, a scoped slice at a fixed price |
| Pricing | Is this a fixed scope, or will the meter keep running? | A fixed scope tied to milestones, not open hours |
Tell us what you have in mind. We turn AI prototypes and fresh ideas into shipped, scalable products, from India, for the US and UK.
Walk-away signs
Some answers are not yellow flags, they are red ones. Walk away if a vendor cannot show a live product, will not name the engineers, dodges the ownership question, refuses a paid trial, or only competes on being the cheapest. These are not small details to negotiate later. They predict how the entire project will go.
- No live products you can open and use, only mockups, concept art and promises.
- The senior team from the pitch is swapped for juniors once the contract is signed.
- No recent client will take a reference call, or the "clients" cannot be verified.
- Code and accounts stay in the vendor's name, or IP only transfers at final payment.
- They refuse a small paid trial and push hard for the full contract, signed now.
- The quote sits far below everyone else, with no scope that explains the gap.
- Vague answers on security, or no willingness to sign an NDA or a data agreement.
- Heavy features promised where they do not fit, like offline sync for a real time, multi party app, which usually means they have not thought the product through.
Many of these overlap with the most common mistakes when outsourcing to India, which is worth reading before you sign. A vendor who trips even two or three of these is not a bargain waiting to be discovered. It is a rewrite waiting to happen.
Our take
After years of building for founders abroad, the pattern is simple. The best offshore partners are not the cheapest, and they are not the ones with the slickest deck. They are the ones who answer every question on this list without flinching, hand you live products and named engineers, and happily prove themselves on a small paid task first. Offshore development, done with a senior team, is safe, reliable and fast, the same way a well made car is. The real risk is not the ocean between you. It is skipping the checks because a quote looked good.
If you are vetting a shortlist right now, put appico on it and hold us to this exact list. Tell us what you are building and we will show you live products, the engineers who would work on it, and a fixed scope plan, with the code and accounts in your name from day one. You can start that on the app development page.
Frequently asked questions
How do you vet an offshore development company?
Score every candidate on the same evidence, not on promises. Open their live products yourself, confirm who writes your code and how senior they are, call two recent clients, check their security and data practices, get code and accounts in your name in writing, test their English and time overlap, run one small paid trial task, and insist on a fixed scope with a clear price. A good partner welcomes all of it.
What questions should I ask an offshore development company?
Ask which live products they built and whether you can use them now, who exactly will write your code and how senior they are, whether two recent clients will take a reference call, who owns the code and accounts at the end, how they protect your data, how many hours your teams overlap, whether they will do a small paid trial, and whether the price is a fixed scope or an open meter.
How do I check if an offshore company is legitimate?
Go past the website. Open their apps in the app stores and check the developer name on the listing. Confirm the company is registered and has a real address. Ask for two clients from the last year and actually call them. Run a small paid trial so you see their code and their deadlines before you commit. A legitimate vendor makes all of this easy. A fake one stays vague.
Should I pay for a trial task before hiring an offshore team?
Yes. A small paid trial is the single best test you can run. It is a scoped slice of real work, paid so the team takes it seriously and so you own the output. You learn more from one trial than from ten sales calls: whether the code is clean, whether it arrived on time, and whether they communicate without being chased. A confident vendor agrees to one.
Who owns the code when you outsource development?
You should, from the first day, but only if you put it in writing. Insist that the repositories sit in your organisation, the domains and cloud and app store accounts are in your name, and the contract includes an IP assignment plus an NDA on request. If ownership only transfers at final payment, or the accounts stay with the vendor, you do not really own your product. Confirm the wording with your own legal adviser.
How do I check an offshore vendor security?
Ask plain questions. Who on their team gets access to your production systems, and can you remove them the day you finish? Are secrets and keys kept out of the code? Do they work on least access by default? If your users are in the UK or EU and the vendor handles personal data, they should be ready to sign a written data processing agreement. A vendor who treats these as obvious is the safer bet.
What are red flags when choosing an offshore development company?
Walk away if a vendor cannot show a live product, replaces the senior pitch team with juniors after signing, has no recent client who will take a reference call, keeps the code or accounts in their own name, refuses a small paid trial, or only competes on being the cheapest. Vague answers on security, or no willingness to sign an NDA, belong on the same list.
Is the cheapest offshore quote a bad sign?
Often, yes. In software the lowest bid usually hides missing features, weak payment handling and a rebuild later. Cheap apps quietly break, collect poor reviews, and cost more to fix than they saved. The goal is not the cheapest quote, it is affordable and senior: a fair price tied to a written scope, from a team that has shipped real products. Compare on scope and proof, not on the headline number.
How many hours should an offshore team overlap with mine?
A few solid hours a day is enough if the rest runs well in writing. India is far ahead of US time and closer to the UK, so set a fixed overlap window for one daily call and run everything else async, with a shared board and a named point of contact. A dependable overlap plus clear written updates beats a full shared day with slow, unclear replies.
How do I check client references for a dev agency?
Ask for two clients from the last year whose projects were about the size of yours, then call them. Ask whether it shipped on time, what broke after launch, how the agency handled a disagreement, and whether they would hire them again. A written testimonial or a directory star rating is easy to collect. A real person who picks up the phone and answers honestly is the signal you want.
“Disciplined, committed, over-delivers. Three years in, I would re-hire any day.”
“A factory of ideas.”
“A fantastic-looking and performing website.”
Talk to the team, we reply within 24 hours, and the first consultation is free.
Start a conversation →