Handing your business's software to an outside company is a trust decision as much as a technical one. The code can be excellent and the demos impressive — but if the company behind it cannot answer basic questions about security, insurance and continuity, you are carrying risk you cannot see.

After fifteen-plus years of being on the receiving end of supplier questionnaires, we know exactly what good due diligence looks like. Here are the questions we believe you should put to any development partner — including us.

The questions worth asking

  • Who are you, verifiably? A real company has a Companies House registration, a trading history and insurance you can see. Ours are published on our Insurance & Company Information page — registration 07098083, professional indemnity and cyber liability cover, with certificates available on request.
  • What certifications do you hold? Certifications are not box-ticking — they are independent evidence that someone checked. We hold Cyber Essentials and Cyber Essentials Plus at company level; the detail lives on Certifications, Standards & Regulatory Monitoring.
  • Where will our data live? "The cloud" is not an answer. Ask for regions, providers and the provider's own certifications — see our Hosting & Data Residency statement.
  • What happens when something goes wrong? Every serious supplier should have a written incident response process and breach-notification commitments under UK GDPR. Ours are in the Incident Response & Breach Notification statement.
  • Who owns the work? You should. Our Data Ownership & Portability statement confirms it contractually — your data and your ability to take it with you.
  • How is the code actually built? Secure development is a process, not a promise: code review, dependency management, change control. That process is written down in Secure Development & Change Management.

The question most people forget: their suppliers

There is a further question that rarely makes it onto the questionnaire, and it is one of the most revealing: who does your partner depend on, and how do they choose them? No development company works alone. Behind every engagement sit a hosting provider, source control and build tooling, third-party components and sometimes other specialist firms. Your risk does not stop at your partner's front door; it runs the whole length of their supply chain.

A partner who takes this seriously can tell you which subprocessors touch your data, what standards those suppliers are held to, and how a new tool gets approved before it comes anywhere near client work. A partner who has never thought about it will improvise an answer on the spot, which tells you that the vetting you are doing right now has never been done one level down. We publish how we handle this in our supplier management statement, for exactly this reason.

The same logic applies to certifications. A certificate held by your partner says nothing about a firm they quietly subcontract to, so if part of the work will be delivered through a wider team, as is common in software development outsourcing, ask whether the same controls follow the work wherever it goes. We have written separately about what Cyber Essentials Plus means for your business, and why the independently audited version is the one worth insisting on.

The pattern to look for

Notice what those questions have in common: every answer should already exist in writing, before you asked. A partner who has to compose answers from scratch for your questionnaire is telling you something. A partner who maintains a public, dated set of statements is telling you something too.

That is why we keep a Trust & Compliance Centre — one place with our security, hosting, continuity and governance statements, written for exactly the due diligence you are doing right now. If you work with a procurement team, our Common Due-Diligence Questions page answers the questionnaire staples directly.

Beyond the paperwork

Documents get you to a shortlist; conversations get you to a decision. Ask to talk through a real engagement: how requirements were shaped, how changes were handled, what happened when something broke. The way a partner tells those stories reveals the culture the documents can only summarise. Our custom software development page describes how we run engagements end to end.

If you are weighing up a software partner and want the paperwork as well as the promises, our Trust & Compliance Centre has the statements ready to read — and we are happy to walk you through any of it. Start a conversation.