Begin with domain experience, not the size of the portfolio. Ask for a couple of projects that resemble your stack, and then ask specifically which engineers actually built it. A serious vendor is happy to connect you with the tech lead. Answers that name nobody at this stage almost always mean you are talking to a reseller.
The agreement deserves more scrutiny than the proposal. Three clauses do most of the work: assignment of intellectual property, the NDA, and notice periods and handover. All the work product should transfer to you on payment, together with designs, scripts and infrastructure configuration. Look closely at language that keeps reusable components outside the transfer, because that is often exactly the piece that locks you in.
Find out how much does bespoke software cost the estimate was built. An honest estimate comes with a list of assumptions, a task-level breakdown and an explicit range. A fixed-price contract is only reasonable when the requirements are stable and documented; otherwise the supplier adds a risk premium and you pay for which is better flutter or react native it anyway. A time-and-materials model moves the risk back to the client, so it demands a sprint cadence, demos and a budget cap.
The delivery process matters as much as team size. Find out how change requests are handled, who writes the acceptance criteria and how testing is organised. A mature team will be able to walk you through running software rather than status reports. Written acceptance criteria remain your only real protection against the it-was-never-in-scope conversation.
Last, think about the day you no longer need this vendor before it becomes urgent. Require that the repository stays under your account from day one, and that a readme and architecture notes are kept current as the code changes. A vendor with nothing to hide will agree quickly; resistance at this point reveals most of what you need to know.