This is the actual scorecard I walk founder clients through before they sign with any development vendor โ not abstract advice, a real scoring structure you can use on your next vendor conversation.
Category 1: Technical verification (30 points)
- Real, verifiable production code from a completed project (10 pts)
- GitHub commit history showing consistent, quality contribution (10 pts)
- Ability to explain a past technical decision and its tradeoffs clearly (10 pts)
Category 2: Process and communication (25 points)
- Clear, specific answer on communication cadence, not vague “we’re flexible” (10 pts)
- Evidence of project management structure (real board, not a sanitized demo) (10 pts)
- Responsiveness during your actual evaluation conversations โ did they answer promptly and directly (5 pts)
Category 3: Contract and risk protection (25 points)
- Willingness to structure milestone-based payment, not full upfront (10 pts)
- Explicit IP assignment clause offered without you having to push for it (10 pts)
- Client-owned repository and cloud accounts from day one, offered proactively (5 pts)
Category 4: References and track record (20 points)
- Willing to connect you directly with a past client, not just written testimonials (10 pts)
- At least one honest example of a project that didn’t go smoothly, and what changed (5 pts)
- Track record length appropriate to your project’s complexity (5 pts)
Scoring guide: 85+ is a strong vendor worth prioritizing. 65-84 is workable but needs specific gaps addressed in the contract before signing. Below 65, keep evaluating other options โ the gaps at this level tend to compound into real problems mid-project, not just minor friction.
How to actually use this: don’t just mentally estimate a score โ ask the specific questions in each row directly, in a real conversation, and score honestly based on the actual answer, not the confidence with which it’s delivered. A vendor who answers fluently but vaguely should score lower than one who’s more halting but genuinely specific.
The category most founders skip, to their cost: contract and risk protection. Technical verification feels more important because it’s about capability, but a technically excellent vendor with no IP clause and no milestone structure is a bigger risk than a solid, unremarkable vendor with proper contractual protection โ the contract is what protects you when something inevitably doesn’t go exactly as planned.
Working through this decision for your own build? Send me a few lines about what you need and I’ll give you a direct read on it. Free 30-minute call, no pitch, no obligation. Available for founders in India and Australia. Book a Free Call →
Frequently asked questions
What score should I look for before hiring a development vendor?
85+ out of 100 is a strong vendor. 65-84 is workable if specific gaps get addressed in the contract before signing. Below 65, keep evaluating other options.
What’s the most commonly overlooked vetting category?
Contract and risk protection โ founders focus on technical capability and underweight IP clauses, payment structure, and account ownership, which matter most when something goes wrong mid-project.
How do I verify a vendor’s technical claims instead of just trusting them?
Ask for real, verifiable production code from a completed project and their GitHub commit history โ not a portfolio site or a company-wide highlight reel.
Should a vendor’s confidence in answering questions affect their score?
No โ score the specificity of the answer, not the confidence it’s delivered with. A fluent but vague answer should score lower than a more halting but genuinely specific one.