The contract needs more scrutiny than the proposal. A few clauses carry most of the weight: assignment of intellectual property, the NDA, and exit terms and handover.
Require the source repository from day one. A partner that shows a build only at the end of each phase is asking you to trust a black box. Daily commits tell you who is really on the project far better than a weekly report.
Ambiguous phrasing around IP is not an oversight. The document needs to state in plain terms that all outputs produced under it become the property of your company upon settlement of the relevant invoice.
Describe the scope as short scenarios: what the user does and what the system does in response. Every bit as useful, state explicitly what the first release deliberately excludes.
Quality attributes silently change the estimate. An internal tool used by a small internal team costs far less than the same feature set serving a hundred thousand users.
A few questions usually settle it. Start here: is the system the product itself, or internal plumbing? Then: how long does the work continue — months or years? Last: who will maintain it in two years?
Quality attributes quietly rewrite the budget. An internal tool used by twenty people has almost nothing in common with the same feature set serving public traffic.
The build price is not the total cost. Budget for hosting, subscriptions and licences, logging and alerting and a change budget annually.