1. How will you understand our workflow?
Ask who conducts discovery, how requirements are documented and who approves them. A proposal written before the problem is understood may depend on assumptions.
2. What exactly is included?
Request written modules, user roles, reports, integrations, languages, environments, migration assumptions, training and exclusions. Clarify which future requests require a new quotation.
3. How will progress be demonstrated?
Agree on practical milestones, review environments, acceptance responsibilities and how changes are recorded. A calendar estimate should include the decisions and materials expected from your organization.
4. How are security and access handled?
- Authentication, roles and permissions
- Production credentials and administrator access
- Backups, recovery and hosting responsibility
- Activity history and sensitive-data handling
- Dependency and update maintenance
5. Who owns and can export the data?
Confirm access to business data, export formats, source-code or license terms where applicable, domain and hosting ownership, and the handover process if the relationship ends.
6. What happens after launch?
Separate warranty or defect correction from operational support, hosting and new development. Ask for the support period, communication method and commercial terms in writing.
Compare evidence, not promises
Review relevant demonstrations, technical explanations and written terms. Do not rely on guaranteed rankings, guaranteed business results or unsupported performance claims.