Hiring the people who will build your software is one of the most expensive decisions to reverse. When it goes wrong, you don't just lose money — you lose months, and sometimes the project itself. The good news: the signs of a good vendor show up before the contract, if you know what to ask.
We have built software for dozens of companies over more than ten years — and seen up close what makes a project deliver value or turn into regret. The pattern is clear. Below are the six questions we would ask if we were on the other side of the table, hiring.
01Will I see software running early — or just presentations?
The biggest risk in a software project is discovering too late that it isn't what you imagined. Vendors who work in long cycles — three, six months until the "big delivery" — push that risk to the end, when fixing things is expensive.
Ask for the opposite: working software in the first few weeks, not a timeline that promises everything by the end of the year. If the first tangible thing only arrives in month three, you are funding faith, not progress. In practice, a first functional delivery is possible within two weeks — and from there you adjust based on what you saw, not on what someone imagined.
02In the end, do I own the code?
It sounds obvious, but it isn't. Many contracts leave you trapped: the system runs on infrastructure that isn't yours, depends on a license only the vendor controls, and migrating means starting over. That is lock-in — and it shows up precisely when you need freedom the most.
The right question is direct: at the end of the project, are the code and the data mine, to run wherever I want? A good partner answers "yes" without hesitation — including the option of running on your own infrastructure (on-premise or self-hosted), with no dependency on someone else's cloud.
03What happens if the first sprint disappoints?
This is the question that reveals the character of the relationship. Most vendors have never thought about it — or change the subject. A confident partner already has the answer in writing.
What to look for is a real guarantee: if the first work cycle doesn't deliver what was agreed, you get your investment back; bugs in what was delivered are fixed for a defined period; and if the relationship doesn't work out, you leave without penalty. Whoever can offer that can do so because they deliver early and by evidence — not because they are lucky.
04Are decisions made by evidence or by opinion?
"I think users will prefer it this way" is the sentence that sinks projects. Good product decisions come from real signals — what people actually do, what each path costs, what measures better — not from the loudest opinion in the room.
Ask how scope choices are made. If the answer involves measuring, prioritizing by impact and showing the cost of each decision, you are dealing with serious people. If it boils down to "just trust us", be suspicious.
05Are they honest about AI — or selling magic?
AI has become a sales word. Almost every vendor today claims to "use AI". The question that separates the real thing from the marketing is: where, exactly, is the AI — and where is it not?
An honest partner points out where there is actual intelligence, and states plainly where the system is deterministic, where it is roadmap, and where AI only helped during construction. Whoever promises AI in everything, without distinguishing, is selling the word — not the capability. The yardstick is simple: where there is AI, point to it; where it is a promise, say it is a promise.
06Are security and LGPD "by design" — or a patch at the end?
Security bolted onto the end of a project almost never holds. If sensitive data, encryption, legal basis and provenance are not part of the design from the very beginning, you will inherit a liability — and, under the LGPD (Brazil's data protection law), a real risk.
Ask how the vendor handles personal data from day one: minimization, PII encryption, control over where the data goes (including to external AIs). "We'll deal with that later" is the wrong answer.
TAKE WITH YOU The six questions, for any vendor
- Do they deliver early? I will see software running in the first few weeks, not only at the end.
- Is the code mine? At the end, I run it wherever I want, with no lock-in.
- Is there a guarantee? What happens, in writing, if the first cycle disappoints.
- Do they decide by evidence? Scope prioritized by impact and cost, not by opinion.
- Honest about AI? Where the AI actually is — and where it isn't.
- Security by design? LGPD and encryption in the design, not as a patch.
These questions are not a test to catch anyone out — they are the minimum you deserve to know before entrusting months and budget to someone. They apply to any software house you evaluate.
Including us. It was precisely to answer "yes" to all six that ZDZCloud designed the way it works: delivery in two weeks, code that is yours, a written guarantee, evidence-based decisions, honesty about where the AI is, and security from day one.
Ask us these questions.
A free diagnosis of your case — we understand the problem and outline the scope of the first step. No sales pressure.
Request a free diagnosis →