A number produced without questions should be treated as a warning, not a service level. Any serious team will come back with clarifying questions before any number: about who owns the data and what happens on failure. A vendor that quotes without asking anything is working from a template, and a guess becomes a change request later — and go development services you will pay for it.
Look out for any distance between the people you meet and the developers actually assigned. Ask for named engineers in the statement of work, with wording about substitutions. A vendor that only offers roles and will not commit to individuals is preserving the option to staff you with whoever is free.
Insist on the source repository from the start. A team that delivers nothing between demos is asking you to trust a black box. Daily commits show you the actual pace far better than a weekly report. This extends to the CI pipeline: if there is no pipeline, promises about quality are just talk.
Loose phrasing around IP is never an accident. The document must state explicitly that all deliverables belong to your company as they are paid for. Also check which country’s law applies and the payment schedule: heavy prepayment with no milestone tied to it takes away the only leverage you have.
Last, look at the working rhythm. Confirm how many hours you will share each day, spring boot vs symfony which named person handles your questions and within what time. Some genuine overlap generally works; zero overlap converts each small question into a twenty-four hour round trip. Unclear written communication in the proposal does not improve later.
There are no comments