Begin with proven experience, not the number of logos on the website. Ask for three or four engagements that match your domain and your stack, and then find out who actually wrote that code. A serious vendor is happy to connect you with the tech lead. Answers that name nobody at this stage generally mean you are talking to a reseller.
The contract needs more attention than the sales deck. Three sections matter more than the rest vs graphql: intellectual property assignment, confidentiality, and notice periods and handover. All the work product should transfer to you once invoices are settled, including documentation, pipelines and deployment scripts. Be careful with any clause that leaves framework code outside the transfer, because it is usually the dependency that makes switching painful.
Find out how the estimate was built. A serious estimate comes with a list of assumptions, a task-level breakdown and an explicit range. A fixed-bid deal only makes sense when the specification is complete; in any other case the vendor pads the number and you fund the buffer regardless. Time and materials puts the risk on your side, so it demands a sprint cadence, demos and a budget cap.
The delivery process beats team size. Establish what happens when the scope changes, who defines done and how quality assurance works. A team can walk you through running create igaming software rather than status reports. Clear, written acceptance criteria remain your only real protection against the it-was-never-in-scope conversation.
Before signing, think about the end of the engagement while the relationship is still good. Ask that the code repository sits on infrastructure you own from the beginning, and that a readme and architecture notes are kept current as the code changes. A provider confident in its own work will agree quickly; hesitation here reveals a great deal.
