Red flags that deserve investigation
A red flag is a reason to ask for evidence, not always an automatic reason to reject a supplier. Contract type, discovery length, upfront payment, and delivery model can be reasonable or risky depending on scope and protections.
1. Vague scope
The proposal does not state deliverables, exclusions, dependencies, or acceptance criteria.
2. No relevant evidence
The team cannot explain a comparable technical problem, show permitted work, or provide a reference.
3. AI without evaluation
The proposal includes an LLM but no test set, quality threshold, human-review path, or regression process.
4. Unclear ownership
Repository, cloud accounts, domains, data, credentials, or intellectual-property terms remain under the vendor's control without a clear reason.
5. Security promises without a threat model
Words such as “secure,” “HIPAA compliant,” or “enterprise ready” appear without architecture, controls, responsibility boundaries, or evidence.
6. Hidden dependencies
The timeline assumes API access, data, content, designs, or stakeholder approvals that are not identified.
7. No change process
The contract does not explain how new requests affect price, schedule, and acceptance.
8. No production plan
Testing, deployment, monitoring, backups, incident response, and handover are absent.
9. Absolute model claims
The vendor always recommends one provider or model without testing the actual workload.
10. Weak communication
Decisions, risks, and blockers are not documented, or the people selling the work are disconnected from the people building it.
11. Unprotected payment terms
The payment schedule is vague or leaves one party carrying disproportionate risk. Large upfront payments are not automatically fraudulent, and hourly work is not automatically inefficient. Use clear milestones, evidence of progress, termination rights, and appropriate platform or escrow protections.
12. Unsupported marketing numbers
Claims about projects shipped, delivery speed, ROI, client outcomes, or rankings cannot be tied to records.
The strongest supplier is not the one with the most aggressive promise. It is the one that explains assumptions, exposes risk early, and accepts accountability in writing.
Fact-check sources
- NIST Secure Software Development Framework
- OWASP Top 10 for Agentic Applications 2026
- Techlign current about page
Sources and product documentation can change. Recheck time-sensitive pages on the publication date.