Nythrex

Guide · Outsourcing without regrets

13 red flags your software vendor is hiding problems.

Outsourced projects rarely fail with a bang. They fail quietly — through status reports that sound fine, demos that get vaguer and dates that slip by “just two weeks” every month. Here are the signals worth acting on, and the question to ask for each one.

By Nythrex EngineeringUpdated 4 min read

  1. Vague updates

    “Good progress this week”

  2. Slipping dates

    “Just two more weeks”

  3. Surprise costs

    “That wasn’t in scope”

  4. Key person leaves

    “We’re onboarding someone new”

  5. Crisis

    Nobody knows what’s left

How troubled projects usually progress. The earlier you act, the cheaper the fix.

Visibility: you can’t see what’s happening

01Status reports without artefacts

“Good progress on the backend” with no link to a demo, a release or a closed item. Ask: “Can you show it running?”

02Demos of screens, not flows

Months in, you still see mock-ups or isolated pages. Ask: “Can I complete the main user journey end-to-end myself?”

03No access to the backlog

You don’t see the task board or it’s a sanitised copy. Ask: “Please give us read access to the real board.”

04Hours without outcomes

Invoices list hours by person, not what they produced. Ask: “What did last month’s hours deliver, item by item?”

Predictability: dates and costs keep moving

01Dates slip in small increments

Two weeks here, one sprint there — never a re-plan. Ask: “What is the forecast based on, and what would move it?”

02Risks appear only when they hit

You hear about a third-party API problem the week of the release. Ask: “What are the top five risks today?”

03Scope changes without a price

Things get added or dropped verbally, and the bill tells you later. Ask: “Every change needs a written estimate before work starts.”

Ownership: you couldn’t leave if you wanted to

01Code lives in the vendor’s repository

You get zip files or “access on request”. Ask: “Move the repository to our organisation this week.”

02Production runs in the vendor’s cloud

Your product, their account, their bill. Ask: “Transfer the subscription or migrate to an account we own.”

03Only the vendor can deploy

No documented pipeline, no way to release without them. Ask: “Can our own engineer deploy following your docs?”

Team: knowledge sits with too few people

01One hero knows everything

Every answer waits for the same person. Ask: “Who else could explain this module?”

02Silent team rotation

New names appear on invoices without an introduction or handover. Ask: “Who joined, who left and how was knowledge transferred?”

03Nobody pushes back

Every request is “no problem”. Healthy teams question unclear or risky asks. Ask: “What in our plan worries you?”

Vendor lock-in test

1 of 12

Is the Git repository in an organisation account your company owns?

What healthy delivery looks like instead

01Working software every iteration

A demo you can click through yourself, recorded for people who missed it.

02A forecast with a range and its assumptions

“Nov 18–23, assuming the payment API sandbox is available by Oct 30.”

03Changes priced before they start

Each change request states cost and schedule impact; nothing starts without approval.

04Risks raised early, with mitigations

You hear about problems when they are cheap to fix.

05Your company owns the assets

Repository, cloud, domains and third-party accounts are in your name from day one.

06Documentation as a by-product

Architecture and runbooks are kept current, not written at the end.

This is exactly what we built the Nythrex delivery model and Client Portal around: progress, budget, decisions, risks and releases visible as they happen, and ownership that makes switching vendors possible without a rewrite.

Found several flags? Do this, in this order

  1. 1

    Secure your assets

    Repository, cloud accounts, domains, app stores, third-party services and credentials — all under your company’s control. Do it calmly and without accusations; it’s simply good practice.

  2. 2

    Ask for a written status

    What’s done (with demos), what’s left (with estimates), top risks, and a forecast with assumptions.

  3. 3

    Get an independent view

    A short technical audit tells you whether the problem is communication, capacity or the codebase itself.

  4. 4

    Decide deliberately

    Reset expectations with the current vendor, bring in help alongside them, or plan a handover. See switching vendors without a rewrite.

Frequently asked questions

Want a second opinion on your project?

Tell us what you’re building and where you’re stuck. We’ll reply within one business day with the most practical next step — even if that step isn’t us.

Start a project