Once you have decided to build something, the next question is who builds it. The options look interchangeable from the outside and behave very differently in practice. This is a plain comparison, including where each one genuinely wins.
A software agency
Best when: the scope is large and well understood, you need several disciplines at once, and you have someone internally who can hold the vendor to account.
The trade: you are usually sold by senior people and delivered to by whoever is available. That is not cynicism, it is the economics — an agency has to keep a bench busy, so staffing follows utilisation rather than fit. It works when the work is well specified. It fails when the work needs judgement, because judgement does not transfer through a handover document.
The question to ask: who specifically writes the code, and will that person be on the project in month four?
A freelancer
Best when: the task is clear, self-contained and short, and you can specify it precisely.
The trade: capacity and continuity. One person, no cover, and typically no obligation to tell you that what you asked for is the wrong thing. Excellent value for a defined piece of work; risky as the only line of defence on something your business depends on.
The question to ask: what happens if you are unavailable for three weeks, and what is written down so someone else could continue?
Hiring in-house
Best when: the work is permanent and central to what you sell.
The trade: time and risk concentration. Months to hire, a real chance of hiring wrong, and for a company under about 200 people, one senior engineer who becomes the single point of knowledge. It is the right answer eventually for anything core — it is a slow answer for something you need decided this quarter.
The question to ask: is this a permanent capability, or a crossing we need to make once and maintain lightly?
An AI security scanner
Best when: you want continuous coverage of known patterns, cheaply, across a lot of code.
The trade: scanners find what they have a rule for. They are very good at that, and a funded industry has grown up around it. What they cannot do is tell you that your multi-tenancy assumption is wrong, that a field nobody flagged is regulated, or that the audit trail you have will not satisfy the person who asks for it. Those are judgement, and judgement is exactly what a rule engine cannot supply.
The question to ask: does this tell me what is broken, or only what matches a pattern?
A founder-led practice
Best when: the work needs judgement more than hands, and being wrong is expensive.
The trade: deliberately limited capacity. You get senior attention on every engagement and the person who scopes the work is the person who builds it — but a practice that takes a handful of clients cannot also be your whole engineering department. If you need twenty people next month, this is the wrong shape.
The question to ask: how many clients do you hold at once, and what is written down so we are not dependent on you?
How to choose
Match the shape to the risk, not to the price list. Well-specified and large: agency. Small and defined: freelancer. Permanent and core: hire. Broad, pattern-based coverage: a scanner. Consequential, ambiguous, and expensive to get wrong: a senior practice.
Most businesses need more than one of these, and the mistake is rarely picking the wrong one — it is using the same one for everything.
Whichever you choose, ask the same closing question: show me what happens when it's wrong. The answer tells you more than any credentials page. If the honest answer is "we are not sure", a Reality Check is one week and a fixed fee to find out.
This is the part we do — the crossing from a demo to a system that survives production.