Free tool

Could you change development supplier if you had to?

Eighteen questions with factual answers, across ownership, delivery, third-party accounts, recovery and terms. It tells you what you have confirmed and what you have only assumed.

of answered

Where this leaves you

You hold it

Confirmed to be under your control. Worth re-checking after any change of provider or of the person who manages it.

They hold it

Real exposure. Ownership items first, then operability, then terms.

Needs checking

Assumed rather than established. Several of these you can check yourself today without asking anybody.

The things that can stop your product

If any of these is in the supplier's name, deal with it before anything else on this page. Everything else costs time and money; these can cost you the ability to operate.

Is the domain registered to an account your company owns?

And does the recovery address point at a company mailbox rather than somebody at the agency?

If you hold it Check the recovery contacts as well as the registrant. They are set separately and are usually the thing that was forgotten.

If they hold it Highest priority on this page. Losing the domain is losing the product, the email and every integration that resolves to it.

If needs checking Ten minutes with the registrar answers it definitively.

Do you control DNS?

Separate from the registration, and often held somewhere else entirely.

If you hold it Keep an export of the zone. It is the fastest way to rebuild if anything goes wrong.

If they hold it Move it to a provider you hold, or at minimum get owner-level access and an export.

If needs checking Look up the nameservers for your domain and follow them to whoever runs them.

Is the production cloud account or organisation owned by your company?

A sub-account inside a supplier organisation is not yours, however much access you have.

If you hold it Confirm the root credentials are company-held and billing goes to a company payment method.

If they hold it This is a transfer with a process. Raise it while the relationship is comfortable, not during a notice period.

If needs checking Who receives the invoice usually settles it faster than asking.

Is the production database, and its backups, in an account you own?

Including the backup destination, which is frequently somewhere different.

If you hold it Confirm you can reach the backups directly, not only through their tooling.

If they hold it Get an independent copy of the data as a first step, then transfer the account.

If needs checking Ask where last night's backup is, and try to open it yourself.

Code and delivery

Is the source repository in a company-owned organisation, with full history?

A squashed snapshot is not the repository. The history is where a new team learns why things are the way they are.

If you hold it Also confirm at least two of your people hold owner rights on the organisation.

If they hold it Normally uncontroversial to ask for. Do it before the relationship is ending.

If needs checking Check whether the first commit is a real beginning or a single "initial import".

Is CI/CD in an account you own, with the secrets in it accessible to you?

Pipelines accumulate credentials that exist nowhere else.

If you hold it Take an inventory of the secrets stored there. It is usually longer than expected.

If they hold it Ask for a transfer or for the pipeline to be rebuilt in your account.

If needs checking Ask who can see the deployment logs. It is a good proxy.

Has anybody outside the agency deployed to production?

Having credentials is different from having done it.

If you hold it Make sure it is written down as performed, not as remembered.

If they hold it Arrange one supervised release. It is the highest-value hour available to you.

If needs checking Look at the deployment history and see whose name appears.

Could an independent developer get it running locally from the instructions?

From the instructions alone, not by being walked through it.

If you hold it Note how long it took. It is your best onboarding estimate for anybody new.

If they hold it Test it with a contractor for a day. It is a cheap and unusually informative purchase.

If needs checking If nobody outside the agency has ever tried, the answer is no.

Third-party accounts

These accumulate one at a time and nobody ever audits the list. This is the section that usually produces the surprise.

Is the payment provider account in your company name?

Including the merchant account, the bank details and the API keys.

If you hold it Confirm you can reach it without going through their dashboard.

If they hold it Move it first among the third-party accounts. It carries money.

If needs checking Check who the settlement goes to.

Are email and messaging services in your name?

Transactional email carries your customer relationships and your sender reputation.

If you hold it Confirm the sending domain is authenticated under your DNS.

If they hold it Transfer or recreate. Sender reputation moves with the domain, not the account.

If needs checking Look at the headers of an email your product sent you.

Are monitoring, error tracking and analytics accounts in your name?

Losing these is losing your operational history at the moment you most need it.

If you hold it Confirm somebody on your side actually receives the alerts.

If they hold it Lower priority than the others, and still worth doing.

If needs checking Ask who gets paged when production breaks.

Do you have a complete list of every external service the system uses?

Derived from what the system actually calls, rather than assembled from memory.

If you hold it Add a column for whose account each one is in. That is the version that matters.

If they hold it This is the fastest thing on the page to fix and it usually finds two or three nobody mentioned.

If needs checking Ask two people separately and compare their lists.

Recovery and continuity

Has a backup been restored in the last six months, by anybody?

Restoring is a different operation from backing up, and it is the one that fails.

If you hold it Record how long it took. That number is your real recovery time.

If they hold it Ask for it as part of the next sprint. It is a reasonable request and an informative one.

If needs checking Nobody forgets restoring a backup. If it is uncertain, it did not happen.

Are production credentials held somewhere your company controls?

Not only in the agency's password manager.

If you hold it Confirm two of your people can reach them.

If they hold it Get a copy into a company vault. Rotation comes after ownership is settled.

If needs checking Ask where the production database password is.

Is there a written account of what runs on a schedule and what breaks regularly?

Scheduled work and recurring faults are the two categories that disappear entirely at a change of supplier.

If you hold it Check it against the cloud console and the crontabs rather than against memory.

If they hold it Ask for it as a small deliverable. It is a couple of hours of their time and worth weeks of yours.

If needs checking Ask what has to be done by hand each month.

Understanding and terms

Can anybody outside the agency describe what the system is made of?

The dimension that decides how long and how expensive a change of supplier would be.

If you hold it Keep it current. A picture that is two years old is a picture of a different system.

If they hold it This is the whole of the understanding dependency, and it is derivable without their involvement.

If needs checking Ask somebody on your side to explain the system for five minutes.

Does the contract say the intellectual property is yours, including anything built on their internal libraries?

A supplier framework inside your product is a dependency that outlives the contract.

If you hold it Check whether any component is licensed rather than owned.

If they hold it Raise it at the next renewal. It is a standard clause and rarely contentious.

If needs checking Read the intellectual property clause today. Ten minutes.

Does the contract define what happens on termination?

Notice, deliverables, account transfers, a handover period, acceptance criteria.

If you hold it Check it names acceptance criteria rather than only deliverables.

If they hold it Add it at renewal, for this supplier and every future one. It protects both sides.

If needs checking Read the termination clause. It changes how you plan.

Your answers stay in this browser. There is no server behind this page: nothing is submitted, no account is needed, and no email address is asked for. Clearing the page or pressing “Start again” removes them.

  • 18 questions
  • about 10 minutes
  • no account
  • nothing is submitted

Short answer

Dependency on a supplier is not a feeling about a relationship. It is a set of facts about who holds what: the domain, DNS, the cloud account, the database and its backups, the repository, the pipeline, the third-party accounts, and whether anybody outside the supplier can operate the system or describe it. Every one of those is checkable this week, and most companies find that the relationship is fine and the arrangement is fragile.

#How to read the result

The three groups are not equal in weight, and the tool does not pretend they are by averaging them. Read it in this order:

  1. Anything in "they hold it" from the first section. Domain, DNS, cloud, database. These can leave you unable to operate, and they are the only items on the page with that property.
  2. Operability items. Whether anybody else has deployed, run it locally or restored a backup. These are all fixable within a fortnight and each one converts an assumption into a fact.
  3. Understanding. Slower to fix and the thing that determines how long a supplier change actually takes.
  4. Terms. Cheap to fix at renewal, and only at renewal, so worth noting now.

#How to raise it without a fight

The framing that works is continuity, not audit: "we need to be able to answer these questions to somebody outside the company". It is true, it is not about them, and it converts the request from a loyalty test into a task with a deadline.

It is also worth saying out loud that a supplier carries risk from the current arrangement too. Holding a client's domain in your own account is an obligation nobody at the agency asked for, and most are glad to hand it back.

#What this does not do

What this does not do

  • It does not look at your system or your accounts. Every answer is yours.
  • It is not a score and not a benchmark against other companies.
  • It says nothing about whether the supplier is doing good work.
  • It is not legal advice on your contract.
  • It cannot see the parts of a system configured outside the repository, which is where several ownership surprises live.

Questions people actually ask

Framed as continuity planning — "we need to be able to answer this to an investor or an insurer" — almost nobody reads it as notice, because it is a normal thing for a company to want. A supplier who reacts badly to "whose name is the domain in?" has given you information you needed.

It matters more with a good long relationship, not less. That is exactly where ownership questions stop being asked and accounts accumulate in the supplier's name because everybody is comfortable. None of this is an accusation, and a good supplier will usually fix most of it in an afternoon.

Then you have found a real constraint and you now know about it, which is better than the alternative. Plan around it: independent data copies, an independent technical picture, and an exit clause at the next renewal.

Get a technical picture that is yours.

Derived from the system rather than written by the supplier, with citations somebody else can check, and an explicit list of what nobody outside can currently confirm.

Build your project map — free If you are changing supplier