The sales call is not evidence. It is a performance, and a good one costs nothing to stage.
Most advice on how to vet an offshore development team stops at “check references and ask for a portfolio.” Both are trivially faked. A reference is a phone number the vendor chose. A portfolio is a set of screenshots with no chain of custody. If you have already been burned once, you know the shape of it: the senior engineer on the call, the polished deck, the invoice, and then eight weeks later a build that does not compile and a project manager who has started saying “the team” instead of a name.
What follows is the evidence a real team can produce inside a day, without a legal review, without a special request escalated to management. Every item is something you can check yourself before money moves. Where a vendor cannot produce it, the honest answer is a specific reason, not a longer explanation.
Reviews only count when the client has a name attached
Testimonials on a company website are copy. They cost the same as the rest of the copy. The only review history worth anything is one held by a platform that will not let the vendor edit it, and that ties each review to a transaction that actually settled.
Fiverr is one of those. Its review system only accepts feedback on a completed order or an eligible cancelled one, the buyer’s public review has to land before the seller can respond, and accounts caught inflating ratings get suspended. That means a rating is a count of paid deliveries, not a marketing asset. Freelancer.com works on the same principle. So does Upwork.
Here is our own, and you can open it yourself rather than take it from this page: 525 delivered orders on Fiverr at a 4.9 rating across 335 reviews, and 5.0 across 156 reviews on Freelancer. Those are two different platforms, two different sets of clients, and neither number is ours to change.
When you ask a vendor for this, ask for the profile URL, not a screenshot. Then read the reviews themselves rather than the average. You are looking for three things: reviews in the technology you are buying, reviews from more than a year ago, and reviews that mention scope changes or delays and still ended well. A profile with forty five-star reviews all written in the same six weeks is a new account, and a new account may be fine, but it is not a delivery record.
Open repositories are the only portfolio nobody can borrow
A portfolio piece can be licensed, copied, or simply claimed. A public repository cannot. It carries commit timestamps, author identities, review comments, abandoned branches and the ugly middle of the work. That is exactly why it is useful.
Ask what the team maintains in the open. Not “do you use open source,” which everyone answers yes to. What do you publish, and under whose name. Then go read it. On GitHub you can check the commit history author by author, and where commits are signed with a GPG, SSH or S/MIME key, GitHub marks them Verified and keeps that status attached to the commit inside the repository’s network. Verified is not a quality signal. It is an identity signal, which is the one you need here.
Our trail: open-source .NET MAUI libraries including TwStyling and Shadcn.Maui, and UrLang, an Urdu-flavoured typed language that compiles to JavaScript. None of that is client work and none of it is a pitch. The point is that it is openable. You can see who wrote which commit, at what hour, and how the code changed when someone filed an issue. Counted from our own git history there are over 160 commits landed between 1 and 5 a.m., which tells you something true about how the work actually happens and is not a line we would have written on a deck.
If a vendor has nothing public, that is common and not automatically damning. Push for the substitute: a screen share of a private repository’s commit graph and pull request history, with the client’s identifying code redacted. What you want to see is many small commits from named people over months. What you do not want to see is a repository whose entire history is one commit called “initial commit,” dated the week the previous client’s contract ended.
Confirming who writes the code, not who joined the call
This is the single question the ranking guides skip, and it is where most of the money goes wrong. The people on a sales call are selected for being good on calls. Assume no overlap between that group and the group who will open your codebase, until someone tells you otherwise in writing.
So ask it flatly. Name the engineers who will be assigned. Then ask for each one’s GitHub or GitLab handle, not a CV. A CV is a document the agency produced. A handle is a public account with a history you can read in ten minutes: what languages they actually commit in, whether their activity is continuous, whether the React Native work on the CV shows up anywhere in the account. If the answer is that profiles are private for security reasons, ask for a thirty-minute call with that engineer and no account manager on the line, and ask them to walk you through a decision they made in a repository you have already looked at.
The bait-and-switch has a tell. The senior you met is described as the “tech lead” or “solution architect” and is not billed to your project, or is billed at ten per cent. The people billed at full time are unnamed. When you ask why, you are told the resourcing is confirmed at kickoff. That is the swap, scheduled.
The subcontracting question, asked in writing
Reselling is the failure mode nobody puts in the contract. An agency signs your project, keeps the account manager, and hands the build to a second shop it has never worked with either. You now have two margins stacked on your budget and no direct line to anyone typing.
The question to send by email, so the answer is on paper: is every engineer assigned to this project employed by your company, and will any part of this work be subcontracted or outsourced to another firm or to independent contractors? Get a yes or no. Then get a clause in the agreement that names subcontracting as requiring your written approval in advance.
Watch how the answer is shaped. “We have a trusted partner network for overflow capacity” means yes. “All our people are vetted” answers a different question than the one you asked. A real in-house team answers this in one line, because it is the easiest question they will get all week.
There are decent reasons to subcontract a slice: a specialist for a payments integration, a designer for two weeks. Fine. You just need to know before, not when a stranger’s name appears on a pull request.
Verifying a portfolio piece without taking anyone’s word
Portfolio fraud is quieter than the other failure modes. A team shows an app it maintained for two months after another shop built it, or a template it customised, or a case study lifted whole. The screenshots are real. The authorship is not.
Three checks get you most of the way. First, ask for the app’s live listing on the App Store or Google Play and look at the developer account name and the first release date, then ask the vendor what they shipped in which release. Second, ask for a specific engineering decision inside that project: why that state management library, what broke in the first version, what they would rewrite. People who built a thing answer this immediately and with irritation. People who did not go abstract. Third, ask to be introduced to that client. Not a testimonial. A fifteen-minute call.
Our own version of the third check is easier than most because the reviews carry client names, on platforms we cannot edit. Yours may be harder. Ask anyway, and treat a flat refusal to connect you with any past client at all as the answer it is.
A paid trial task with fixed scope and a walk-away clause
Interviews measure interviewing. A trial task measures shipping. Pay for it, keep it small, and write down the exit before it starts.
Four things make a trial task diagnostic rather than decorative:
- Fixed scope, written. One feature, one bug fix in your existing codebase, or one vertical slice of version one. Defined in a paragraph you both sign, with the acceptance criteria stated as behaviour rather than adjectives.
- Fixed price and a fixed deadline. Five working days is usually enough. If the number moves during the trial, that is data.
- The named engineers do the work. The same handles you checked. Ask for the commits, review them yourself or have your own engineer review them.
- An explicit walk-away clause. If the work does not hold up, you pay the agreed price, you keep the code and the IP, and both sides stop. No notice period, no penalty, no negotiation about whether it was really a fair test.
The walk-away clause is the part vendors quietly resist, and the resistance is the finding. A team confident in its work would rather be paid for five days and released than argue its way into a six-month contract.
Price it against what a wrong hire costs you, not against your procurement instinct. A failed offshore engagement burns the fee, the calendar and usually the codebase. A trial task burns one week.
Measuring timezone overlap during the trial, not on the call
Overlap is promised in hours and delivered in whichever hours are convenient after signing. It is the easiest commitment to make and the easiest to quietly drop.
Do the arithmetic before you accept a number. Pakistan runs at UTC+5. New York in summer is nine hours behind. So four hours of overlap with a New York morning means someone in Karachi or Lahore is at their desk until 10 p.m. local, every day, not just in week one. Ask who specifically, whether it is rostered or voluntary, and what happens to it during Ramadan and on public holidays that are not on your calendar.
Then measure it during the trial. Note the timestamp of the first message each day and the last, and the gap between your question and a substantive answer. Five days of that gives you the real number. Ours, plainly: our team is in Pakistan, which means genuine overlap with US Eastern hours costs somebody their evening, and overlap with US Pacific is thin. We would rather say that than discover it with you in week three.
Milestone payments, and letting a platform hold the money
Never fund a project in one transfer. Milestones do two jobs: they cap what you can lose, and they force scope to be written down in checkable pieces.
If the engagement can run on a freelance platform, let it. On Upwork’s fixed-price contracts the money sits in escrow, you get 14 days to review submitted work and either approve it or ask for changes, and only funded milestones are protected. Anything agreed in a side conversation is not. The platform fee buys you a third party holding the money and a dispute process, which for a first engagement with an unknown team is cheap.
Off-platform, structure it the same way. First milestone no larger than fifteen per cent of the total. Each milestone has a deliverable you can run, not a percentage of “development complete.” Payment follows acceptance, and acceptance is defined in the same behavioural language as the trial task.
Getting the IP assignment written before the first commit
Assume nothing transfers by default, because under US law it mostly does not. A “work made for hire” label is not a magic phrase: the Copyright Office is explicit that for commissioned work the parties must sign a written instrument, and the arrangement only applies to nine enumerated categories of work. Custom software is not among them.
What actually moves ownership is a present assignment clause covering all code, designs and documentation produced under the agreement, signed by the company and by every individual contributing, including subcontractors if you approved any. Add three things people forget: the repositories, CI accounts, cloud projects and app store listings live under your organisation from day one, not theirs. Credentials and third-party API keys are yours. And there is a written handover deliverable, so the build runs on a machine that is not theirs.
If a vendor wants to keep “reusable components” out of the assignment, get the list of components by name before you sign, not after.
Where our own trail is thin
Symmetry matters here, so: what we cannot show you. Most of our client work sits under NDA, so the repositories you can open are our own libraries rather than the apps we shipped. Team bios and photographs are not on the site yet, and we would rather leave that gap visible than fill it with invented headshots. How long we have shipped together is our own claim about ourselves, and it is worth exactly what any vendor’s is: check the dates on the platform reviews and the commit history instead of taking a number on trust.
We also lose work by saying no. When a template, a no-code build or a two-week script solves the problem, we say so, and that recommendation costs us the project. If a vendor has never once told you your scope is too big, you have not yet heard them be honest with you.
The 36-hour night with a TV app that kept dying, before we gave up patching and rewrote it in Kotlin, is the kind of thing you only learn about a team from the commit history or from asking. It is also the kind of thing worth asking about. What did you get wrong recently, and what did the fix cost.
How to vet an offshore development team, in order
Run it in this sequence, because each step is cheaper than the next and kills more candidates.
- Read the platform reviews and open the repositories. One hour, and it removes most candidates before you have spoken to anyone.
- Send the subcontracting question and the who-writes-the-code question by email. Five minutes to write, a day of waiting, and the answer is on paper.
- Take the thirty-minute call with the named engineer, no account manager on the line, about a repository you have already read.
- Buy the five-day trial task, fixed scope, fixed price, walk-away clause written before it starts.
- Measure the timezone overlap while the trial runs. First and last message each day, and the gap between your question and a substantive answer.
Two candidates through the trial is better than one. If both hold up you have a second option for the month a lead engineer leaves.
If you are talking to us, start with the Fiverr and Freelancer profiles and the public repositories, then ask for the trial. We will quote the trial at a fixed price with the exit written in, and if the work does not convince you, take the code and go.