Updated September 8, 2026. Facts about StatusBird are as published on statusbird.io on that date. Third-party products are named to identify them only.
To choose a software company, check four things you can verify rather than four things you are told: a portfolio with software that is live and still running, security practices the firm can show you, a support process with a named response time, and pricing that states what is included and what costs extra. A firm that passes all four is a safe hire; a firm that fails any one of them will cost you more than the quote.
This checklist comes from StatusBird, a software company in Phoenix, Arizona that builds and runs its own product. We have been on both sides of the table: hiring vendors for parts of our stack and being evaluated by store owners deciding whether to trust us with their alerts. The same questions work in both directions.
What should you check in a software company's portfolio?
Ask for three examples of work that is still in production and ask to use them. A screenshot proves someone designed a screen; a live URL or a demo account proves the software shipped, survived real users, and is still maintained. For each example, ask:
- Is it live today? Open it. If the firm cannot point to running software, treat the portfolio as design work, not engineering work.
- What did the firm build versus configure? Assembling a Shopify theme and building a custom inventory system are both legitimate, but they are different skills at different prices.
- Who maintains it now? If every project was handed off and never touched again, you will be hiring a builder, not a partner.
- Can you speak to the client? One reference call answers more than an hour of sales conversation. Ask the reference what went wrong, not what went right. Every project has something.
How do you verify a software company's security practices?
You do not need to be technical to check security. You need to ask questions that have concrete answers and notice when the answer is vague.
| Question | A good answer sounds like | A warning sign sounds like |
|---|---|---|
| Where will my data be stored? | A named hosting provider and region (for example, a managed Postgres database on Render in Oregon) | "On our servers" with no further detail |
| How are payments handled? | Card data never touches the firm's systems; a processor such as Stripe or Shopify holds it | The firm stores card numbers or "encrypts them ourselves" |
| How do you handle third-party API keys and tokens? | Stored as environment variables or in a secrets manager, rotated, never committed to source code | Keys in a shared document or in the code repository |
| What happens when a dependency has a breach? | A process: rotate credentials, notify affected customers, publish what happened | "That has never happened to us" |
| Who has access to production? | A short named list with two-factor authentication required | "The whole team" |
| Do you have a written privacy policy and terms? | Public pages you can read before signing | "We can send that over later" |
If the firm serves regulated customers, ask for a SOC 2 report or an equivalent audit. If it does not, do not demand one; a small shop that answers the table above clearly is more trustworthy than a large one that hides behind a badge.
What does good software support look like?
Support is where most software relationships fail, because it is the part that is not in the demo. Ask for the support terms in writing and check for these specifics:
- A named response time. "Within one business day" is a commitment. "As soon as possible" is not.
- A channel a human answers. Email is fine. A ticket portal is fine. A chatbot with no escalation path is not.
- A definition of what is covered. Bug fixes on delivered work should be included for a stated period. New features should be quoted separately, and the firm should say so up front.
- Monitoring. Ask how the firm finds out when the software it built stops working. The honest answers are "we run uptime checks and get paged" or "we do not, and you should set that up." The dishonest answer is "it does not go down."
Test the support channel before you sign. Send a real question to the support address and time the reply. StatusBird publishes support@statusbird.io and a phone number on its about page for exactly this reason; a company that is confident in its support invites the test.
How should software pricing be structured?
Good pricing is legible: you can look at a quote and know what you will pay in month one, month twelve, and when something changes. Check for four things.
- What is included. Design, development, testing, deployment, documentation, and a support window should each be listed, with the ones that are excluded named explicitly.
- Who owns the code. For custom work, you should own the source code and have access to the repository from day one. For subscription software, you are renting, and the price should say what happens to your data if you cancel.
- Recurring costs. Hosting, third-party services, and licenses are real money the firm may not include in its quote. Ask for a list with the monthly figure for each.
- The change process. Every project changes scope. The quote should say how a change is priced and who approves it before work starts.
For subscription products, the same rule applies in a simpler form: the pricing page should show every plan, every limit, and every add-on. StatusBird's pricing page lists a free plan for 1 service, Pro at $29 per month, Business at $49 per month and Agency at $99 per month, with the features of each spelled out. If you have to book a call to learn a price, budget for the price to be high.
Does it matter if the software company is local?
Less than it used to for delivery, more than you would expect for accountability. Software can be built from anywhere. What a local firm gives you is a legal entity in your jurisdiction, a person you can meet, and a reputation that is visible in your own business community. If you are hiring in the Phoenix area, for instance, you can check an Arizona LLC's standing with the Arizona Corporation Commission in a few minutes. Do that for any firm you are about to pay a deposit to, local or not.
A scored checklist you can use in one meeting
Score each line 0 (no evidence), 1 (claimed), or 2 (verified). A total of 16 or more out of 20 is a confident hire. Below 12, keep looking.
| Check | How to verify | Score |
|---|---|---|
| Three live examples of past work | Open the URLs yourself | 0 / 1 / 2 |
| Reference client who will take a call | Make the call | 0 / 1 / 2 |
| Named hosting provider and data location | Ask, then check the provider's site | 0 / 1 / 2 |
| Card data handled by a payment processor, not the firm | Ask which processor | 0 / 1 / 2 |
| Public privacy policy and terms | Read them before the meeting | 0 / 1 / 2 |
| Written support response time | Get it in the proposal | 0 / 1 / 2 |
| Support channel answered by a person | Send a test email and time the reply | 0 / 1 / 2 |
| Itemized quote with exclusions named | Compare against the four pricing checks above | 0 / 1 / 2 |
| Code ownership and repository access stated in writing | Read the contract | 0 / 1 / 2 |
| Legal entity in good standing | Search the state business registry | 0 / 1 / 2 |
Frequently asked questions
What is the most important factor when choosing a software company?
Evidence over claims. The single most predictive check is whether the firm can show you software it built that is live and still maintained, and put you in touch with the client who uses it. Everything else on the checklist supports that one question.
How many software companies should I compare before hiring one?
Three is enough to see the range of prices and approaches without spending weeks in sales calls. Score each against the same ten-line checklist so you are comparing evidence rather than presentations.
Should a small business hire a local software company or a remote one?
Hire the one that scores higher on the checklist. Local firms are easier to hold accountable and easier to verify in public records; remote firms often cost less. Neither location guarantees quality, and the verification steps are identical.
What questions should I ask a software company about security?
Where data is stored, who handles payment card data, how API keys and passwords are stored, who has production access, and what the firm does when a vendor it relies on is breached. Each has a concrete answer; vagueness on any of them is the warning sign.
How do I know if a software company's pricing is fair?
Fair pricing is itemized, names its exclusions, lists recurring costs such as hosting and licenses, and states how scope changes are priced. Compare the total of those four lines across quotes rather than the headline number.
About the author: StatusBird is an independent software company in Phoenix, Arizona that builds and operates a monitoring service for e-commerce stores. It checks 84 third-party services every 2 minutes and alerts store owners by SMS, email, Slack, Teams and Discord when one goes down. Everything in this article comes from building and running that product; StatusBird does not sell custom software development.