Skip to content
00Free PDF · 12 questions · 5 minute read

The custom software buyer's checklist.

Twelve questions to ask before you sign a SaaS contract or hire anyone to build for you. They are the questions vendors hope you skip, and the ones that decide whether you end up owning the software or renting it forever.

  • Source code ownership
  • Data export and lock-in
  • Pricing-model gotchas
  • Integration limits
  • Security and response times
  • Exit terms
01What's inside

Twelve categories. One question per category that your vendor would rather skip.

Each category in the PDF gives you the question to ask, why it matters, and the answer that should end the conversation.

  1. 01

    Code ownership

    Who owns the codebase the day after launch, and who owns it the day after a dispute? Get the answer in writing.

  2. 02

    Source code escrow

    If the vendor folds, do you get the code? If they are acquired, does your contract survive the new owner?

  3. 03

    Customization limits

    Which workflows are genuinely configurable, and which need a paid upgrade tier or a full rebuild?

  4. 04

    Data export and portability

    Can you leave with every record and the schema intact, without a six-week extraction project?

  5. 05

    Pricing model and gotchas

    Per seat, per record, per feature, or an annual increase? Price it at three times your current size, not today's.

  6. 06

    Support model and response times

    Who picks up when production breaks at 2am? What is the committed response time in the contract, not in the marketing?

  7. 07

    Integrations and APIs

    Open API or walled garden? Will it talk to your accounting, payroll, and CRM without a five-figure connector?

  8. 08

    Security posture

    Encryption in transit and at rest, audit logs, role-based access, named certifications. Ask which they hold today and which they only intend to hold.

  9. 09

    AI capability and roadmap

    Is AI something you can adopt on your own terms, or a black box that reaches into your data on the vendor's schedule?

  10. 10

    Scaling behaviour

    What breaks first at ten times the users, records, or transactions? And what does fixing it cost?

  11. 11

    Exit terms

    How do you leave, how long does it take, and are there termination fees, data-purge charges, or transition penalties?

  12. 12

    Contract length and renewals

    Auto-renew clauses, multi-year lock-ins, price-protection terms. Read every one of them before you sign.

02Why we made this

Most buyers sign the wrong contract.

The same story keeps repeating. A growing business outgrows its starter software, talks to two or three vendors, and signs with whichever one gave the slickest demo. Two years later the subscription has climbed, half the workflow happens in a spreadsheet beside the tool, and leaving would mean a migration project nobody has time for.

Take a single $12,000 a year subscription. Over ten years that is $120,000 if the price never moves, and roughly $151,000 once you allow for a 5% annual increase. A $30,000 build with no subscription is $30,000 over the same decade, breaks even around year two and a half, and leaves you owning the thing at the end. Hosting is real, but it is paid to your provider rather than to us and it varies with the build.

Most of the damage is preventable. The traps sit in the contract, the data model, and the pricing tier they upsell you onto in year two. They are not hidden. They are just easy to miss when you are trying to ship.

This checklist is what we would ask if it were our business and our money. Use it on us. Use it on every vendor you talk to. Walk away from anyone whose answers do not survive the list.

Run the ten-year comparison on your own numbers if you want the arithmetic before the PDF.

03Use it on us first

Our answers to the hard ones.

A checklist you cannot turn on the firm handing it to you is marketing. Here are the eight that matter most, answered plainly, including the one where the honest answer is no.

Who owns the code?
You do. One hundred percent of the source, the data, and the IP transfers on final payment, and that sits in the contract rather than in a FAQ.
What about source escrow?
It does not apply. You already hold the code, so there is nothing for a third party to hold on your behalf.
Can I export my data?
It is your database and your schema. There is no extraction project because there is nothing to extract yourself from.
How is it priced?
Fixed price, billed against milestones. No per-seat licence, no per-record charge, no annual increase. Hosting is paid directly to that provider, not to us, and it varies with the build.
What does support cost?
It is not a flat monthly retainer. Either you take the code and owe nothing, or you keep an hourly relationship priced by the complexity of what was built and triaged by severity. Critical means now and costs more. Simple waits for the next available week.
Which certifications do you hold?
None of the big ones, and we will not imply otherwise. We do not hold SOC 2, ISO 27001, FedRAMP, HECVAT, or StateRAMP. CyberSecure Canada is in progress. WCAG 2.1 AA is a standard we build to, not a certificate we carry.
How hard is the switch?
Nobody on your team should spend more than about fifteen minutes getting set up: a new login, a password, done. Moving the data is our job, not yours.
How do I leave?
There is nothing to leave. You already hold the code, the data, and the infrastructure accounts. If you stop calling us the software keeps running.
04Verifiable, not claimed

The paperwork behind the answers.

Question ten on most procurement forms is whether the vendor is a real, insured, registered company. Here is that answer, with the numbers you can look up yourself.

Commercial general liability
$5,000,000

Bound and in force.

Professional liability (E&O)
$2,000,000

Bound and in force.

Cyber liability
$2,000,000

Bound and in force.

WorkSafeBC account
201966367

Active. Clearance letter on request.

Federal corporation (CBCA)
1730441-2

BlueStone AI Inc., incorporated 2025-09-09.

BC extraprovincial registration
A0142791

Registered to carry on business in British Columbia.

Business number
771523834 RC0001

Canada Revenue Agency.

Ownership
Canadian

Canadian-owned small business.

Certificates of insurance and a WorkSafeBC clearance letter are issued on request, usually the same day. BlueStone AI Inc. is a small supplier under the Canada Revenue Agency threshold and is not currently registered for GST/HST, so invoices carry no GST line.

05About the download

What you are signing up for.

Is the PDF actually free?
Yes. One email field, no card, no call required. The document arrives by email within a couple of minutes.
Will you email me repeatedly afterwards?
No. You get the checklist and nothing else. There is no drip sequence and no newsletter attached to it, so there is nothing to unsubscribe from.
Is it specific to British Columbia?
The twelve questions apply to any software purchase anywhere. The contract and procurement notes are written for Canadian buyers, and every figure in it is in Canadian dollars.
Can I use it on Bluestone?
Please do. Our own answers to the eight hardest questions are published further down this page, including a plain list of the certifications we do not hold.
No pitch · Reply in one business day

Want someone to go through the list with you?

Send us a note and paste in the proposal you are reviewing. We go through the twelve questions against it and tell you straight where the risk sits. You keep the written summary whether you hire us or not.