How to hire a web developer you have never met
We are an offshore firm that asks American small businesses to send money to people they will never shake hands with. Here is exactly how we would vet us — what to verify, how to pay, and the red flags we would run from ourselves.
Somewhere this week, a small-business owner wired a deposit to a developer they found online and will never hear from them again. You know this. We know you know it — we are on the other side of that transaction, an engineering firm in India asking businesses in Ohio and Indiana to trust us with their money and their web presence, sight unseen.
So instead of telling you we are trustworthy, which is what everyone says, here is the vetting process we would use on ourselves. It works on any remote developer — offshore, out-of-state, or across town — and none of it requires technical knowledge. It requires about an hour and a willingness to be slightly rude.
Verify the things that cannot be faked
Anyone can build a portfolio page full of screenshots in an afternoon. Ignore everything that is cheap to fake and check the things that are not:
- Live client websites you can visit. Not screenshots — addresses. Open them. Then check the businesses behind them are real: search the name, look for reviews, a phone number, a Google listing. A screenshot proves nothing. A live site belonging to a verifiable business that keeps paying its hosting bill proves a working relationship.
- A marketplace history with money behind it. An Upwork-style profile shows jobs completed, hours billed, and reviews from clients who paid through escrow. The platform verifies that payment actually happened, which makes those reviews expensive to fake in a way that website testimonials never are.
- A registered legal entity. An Indian LLP has a public registration number you can look up on the Ministry of Corporate Affairs website in two minutes. A registered firm has named partners, a paper trail, and something to lose. An anonymous freelancer has a Gmail address.
- The actual person, on video. Insist on a video call before signing anything. You are checking three things: that the person exists, that they can explain your project back to you in plain language, and that the person on the call is the person who will do the work — not a salesperson fronting for a team you will never meet.
Pay so that nobody has to trust anybody
A good payment structure does not protect you from criminals — it removes the need for trust entirely, which protects both sides from something much more common than crime: an honest disagreement with money already on the wrong side of it.
- Run the first project through a platform. Escrow holds your money until you approve each milestone. It costs the developer a platform fee, and a good one accepts that as the fair price of a brand-new relationship.
- Tie milestones to things you can see. Design approved. Site running at a staging address you can click. Site launched. Pay after each one, never before.
- Never pay everything upfront. A deposit of a third to a half is normal. One hundred percent upfront is not a deposit; it is a donation.
- Buy something small first. For any large project, start with a small paid piece — an audit, a single page — and judge the working relationship on a few hundred dollars instead of a few thousand.
Own everything from day one
The most common offshore horror story is not theft. It is hostage-taking, and it is usually accidental: the vendor registered your domain in their own account, hosted the site on their own server, kept the only copies of the passwords — and then got busy, got sick, or got gone. Nothing was stolen. Everything is stuck. The defense is boring and absolute:
- The domain is registered in your account at the registrar, on your card. The vendor gets access, never ownership.
- The hosting account is in your name. They get a login you can revoke.
- The code lives in a repository you control, or is handed over at every milestone.
- Every password — admin, analytics, search console — sits in a list you hold, updated as the project goes, not promised at the end.
A vendor who resists any of this is telling you, politely and in advance, that leaving them will hurt. A good vendor insists on it — partly because it is right, and partly because it protects them from being blamed for things they no longer control.
Five questions before you sign
- What exactly is included — and what is excluded? In writing. The exclusions tell you more than the inclusions.
- Who writes the words and supplies the photos? More projects die on this question than on anything technical.
- What happens after launch? What does ongoing care cost, and what exactly happens if I pay for none?
- What hours do you overlap with my timezone, and where do we talk — email, scheduled calls, something else? "Whenever" means "never" across nine and a half time zones.
- If we part ways halfway through, what do I walk away with, and what do I still owe?
The red flags we would run from
- Full payment upfront, for any reason, however politely framed.
- No live client site you can independently verify. Screenshots and "NDA projects" all the way down.
- Refuses a video call, or sends a different person to every call.
- "We'll take care of the domain for you" — registered in their account.
- A quote with no written scope. You cannot hold anyone to a conversation.
- Testimonials from businesses with no footprint — no website, no reviews, no map listing.
- A price 80% below everyone else's. Someone pays that difference eventually, and it will be you.
- A guarantee of first place on Google. Nobody controls Google. Anyone promising a ranking is lying about at least one thing, and probably not just one.
Our own answers
It would be strange to publish this checklist and hide from it. Measured against it: our client sites are live and you can visit every one of them — each belongs to a real business you can look up independently. Our Upwork profile shows Top Rated status, 100% job success, over 1,600 hours and 20 completed jobs, all through escrowed payments the platform verified. Quantis Sphere LLP is registered in Tamil Nadu, India — LLPIN ACT-9528, which you are welcome to look up. Our prices and exclusions are published, so the written scope exists before you ever talk to us. And the founder takes the video call himself, because the founder is who does the work.
What we cannot show you: a US office, a large team, or twenty years of history. We are a small founder-led firm, and this checklist is how small firms earn work they have no handshake to win. Use it on us. Use it on everyone who quotes you. The vendors worth hiring will pass it without flinching.

Subin Sunder Raj
Subin leads security and infrastructure at Quantis Sphere. He runs the web and API penetration tests, hardens the Linux and cloud environments client systems run on, and builds the Wazuh SIEM deployments the security practice is built around — the same person scopes the engagement and does the work.