FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Pakistan · 5 minute read

How to Vet a Software Company in Pakistan

Vet a Pakistani software company with five checks: reference calls that ask what went wrong, a walkthrough of comparable work under NDA, the master services agreement read before the pitch, interviews with the named engineers, and a bounded paid pilot. Together they take about a week.

By FISTA Solutions· AI-Native Engineering Team·
How to Vet a Software Company in Pakistan article cover

Vetting a software company does not require special expertise, only a refusal to accept claims without evidence. Five checks, about a week.

Check one: reference calls that ask about failure

Ask two previous clients what went wrong and how it was handled. Ask how much of their own team's time the engagement consumed. Ask whether the named engineers stayed for the duration. Ask whether they would use the firm again for the same kind of work.

Positive generalities tell you nothing. A specific account of a problem, a response, and a change afterwards tells you almost everything.

Check two: a walkthrough of comparable work

Under NDA, a screen-share through a repository from a project like yours. You are not auditing the code; you are looking at whether pull request reviews contain substance, whether tests exist and run, whether commit history is coherent, and whether documentation is real.

Twenty minutes of this reveals more than any technical presentation, and a company confident in its work will offer it. The scorecard page covers what to look for.

Check three: read the contract first

Request the master services agreement before the pitch call. Look at four things:

TermWhat to check
IP assignmentOn creation, not on final payment
ConfidentialityPresent, with a survival period
Data handlingClassification, access, incident notification
TerminationHandover obligations and notice

How a company writes its contract tells you how it thinks about risk and ownership, before anyone has tried to charm you.

Check four: interview the named engineers

The pitch team is frequently not the delivery team. Ask who would work on your project, then interview at least the lead. Ask about a production incident they handled, an estimate they got badly wrong, and what they would push back on in your brief.

Then put those names on the statement of work with substitution terms covering notice, handover, and your right to interview replacements.

Check five: a bounded paid pilot

Three to six weeks of real work with written acceptance criteria, delivered in your repository. This is the only check that tests everything at once: specification quality, communication, handling of surprises, code standards, and whether the people you met are the people who appear.

Everything before it narrows the field. This decides.

What about certifications, awards, and reviews?

Hygiene facts. Registrations confirm that a company exists formally and participates in the sector. Awards frequently reflect submission fees. Review platforms measure review collection effort as much as quality.

Note them in the company profile, weight them lightly, and spend your attention on the five checks. The PSEB post covers what registrations actually signify.

What should you verify about the company itself?

Incorporation and the contracting entity's jurisdiction, because that determines your recourse. Whether they have a foreign entity, which simplifies contracting and payment considerably. How long they have operated. And who the leadership is.

FISTA Solutions Inc. is a Delaware corporation founded in 2017, delivering from Faisalabad, with a due-diligence pack available under NDA.

What are the warning signs?

A fixed price quoted before anyone has seen your systems. Refusal to name engineers. Code planned for the vendor's repository. No acceptance criteria. References who cannot be contacted. Vague answers about security practices.

Any one is negotiable. Several together indicate a commercial model that depends on ambiguity, which always costs the buyer.

How do you vet AI capability specifically?

Ask for an evaluation report with per-task accuracy and named failure classes, a production trace showing an agent's steps and tool calls, and the permission model. Firms that have shipped agents produce all three; firms that have demonstrated them produce another demonstration.

The AI agent hiring guide covers the questions in detail.

What does the whole process cost you?

About a week of attention plus the pilot fee. Against the cost of a failed engagement — months of calendar time, a codebase you cannot maintain, and the work redone — it is the cheapest insurance available in software procurement.

How do you keep the process fair to the vendors?

By being specific and consistent. Send the same brief to every candidate, ask for the same artefacts, run the same agenda, and give a decision by a stated date. Vendors invest real time in scoping conversations, and processes that go silent after three calls damage relationships you may want later.

It also improves the answers you get. Firms that sense a serious, well-run process bring their better people to the call and prepare properly; firms that sense a fishing expedition send a salesperson. The discipline you apply to your own selection is visible from the other side, and it affects what you are shown.

What does FISTA Solutions offer to vetting buyers?

References on request under NDA, a repository walkthrough, the MSA before the pitch, interviews with the named engineers, a due-diligence pack covering entity and security practices, and a bounded pilot with code in your repository from the first commit.

Related reading: how to outsource step by step and questions to ask a Pakistani software company, plus staff augmentation.

Five checks, one week, one pilot

Run them in order and the shortlist sorts itself. Skip them and you are choosing on presentation, which predicts very little.

Message FISTA Solutions on WhatsApp or start a project and put us through all five.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What should I ask a reference?

What went wrong and how it was handled, how much of their own team's time the engagement consumed, whether the named engineers stayed, and whether they would use the firm again for the same work. Positive generalities tell you nothing.

02Why read the contract before the pitch?

Because it reveals how a company thinks about risk and ownership before anyone has tried to charm you. IP assignment timing, confidentiality, data handling, and termination terms say more about a vendor than any presentation.

03What does a repository walkthrough show?

Whether reviews contain substance, whether tests exist and run, whether commit history is coherent, and whether documentation is real. Twenty minutes of this is worth more than an hour of technical discussion.

04Should I interview the engineers?

Always. The pitch team is frequently not the delivery team, and the engineers assigned determine your outcome. Interview at least the lead, and put the names on the statement of work with substitution terms.

05Do certifications and awards matter?

They are hygiene facts rather than evidence. Registrations confirm a company exists formally; awards frequently reflect submission fees. Note them in the profile and spend your effort on references, code, contracts, and a pilot.

06How long should vetting take?

About a week for the five checks, then three to six weeks for a pilot that produces real work. Longer evaluations tend to add process rather than information, and they end with the same uncertainty they started with.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project