Frequently asked questions

Common questions about our services, engagement models, and approach to building enterprise systems.

What exactly does API governance mean? +

API governance is the set of standards, policies, and processes that ensure your organization's APIs are consistent, secure, discoverable, and operationally reliable.

It includes:

  • Design standards (naming conventions, versioning strategies, error formats)
  • Security policies (authentication, rate limiting, access control)
  • Documentation and discoverability requirements
  • Lifecycle management (deprecation, sunsetting)
  • SLO and reliability targets
  • Approval workflows for new or modified APIs

Good governance reduces integration friction, improves security posture, and enables independent teams to move at scale.

How do you approach legacy system modernization? +

We don't believe in "rip and replace." Instead, we design strangler patterns that let you modernize incrementally while maintaining business continuity.

Our approach:

  1. Map current systems and data flows to understand dependencies
  2. Define service boundaries and domain models aligned with your organization
  3. Start with a small, low-risk service and extract it behind an API
  4. Route requests through a gateway that adapts between old and new systems
  5. Gradually migrate other services and retire legacy systems

This approach minimizes risk, allows teams to learn, and lets you move at a sustainable pace.

How long does a typical engagement take? +

Engagement length depends on scope and complexity, but here's a general timeline:

  • Discovery (2–3 weeks): Assessment and stakeholder interviews
  • Blueprint (3–5 weeks): Architecture design and roadmap
  • Build (8–16 weeks): Implementation with your teams
  • Enable (ongoing): Training, documentation, and support

Total: 4–6 months for most engagements. Larger transformations may take longer. We work closely with your team to set realistic timelines and expectations.

Do you conduct security reviews? +

Yes. Security is built into every phase of our engagements:

  • Threat modeling during architecture design
  • Security standards embedded in our design guidelines
  • Code review and approval workflows during build
  • Pre-launch security validation and penetration testing
  • Incident response and security runbooks in Enable phase

We work with your security team throughout and are comfortable operating in regulated environments (healthcare, fintech, energy).

What's your approach to API documentation? +

Documentation is critical to adoption. We believe it should be:

  • Executable: Examples that developers can copy and run
  • Living: Updated alongside the API, not maintained separately
  • Searchable: Easy to find what you need
  • Context-aware: Different paths for different use cases (basic integration vs. advanced patterns)
  • Owned: Responsibility clear for each section

We design documentation systems and content governance that ensures quality while distributing the work across your team.

What if we don't have a dedicated developer portal team? +

That's normal. Most organizations don't. We help you:

  • Choose a portal platform that matches your technical maturity
  • Design lightweight workflows that work with your existing team structure
  • Automate documentation generation so content stays current
  • Distribute portal maintenance across service teams

You don't need a dedicated portal team. You need clear ownership and lightweight processes.

How do you support both cloud and on-premise deployments? +

We design cloud-agnostic architectures using standard patterns, tooling, and languages that work across AWS, Azure, GCP, and on-premises environments.

Our recommendations consider:

  • Your existing infrastructure and vendor relationships
  • Compliance and data residency requirements
  • Team expertise and operational capabilities
  • Cost and long-term flexibility

We work with your infrastructure teams to ensure the solution fits your environment.

What are the risks of transforming our integration landscape? +

We take migration risk seriously. Our approach mitigates it:

  • Strangler pattern: Build new system alongside old, migrate gradually
  • Feature parity checks: Ensure new system handles everything old system did
  • Parallel runs: Route traffic to both systems to validate behavior
  • Rollback plans: Always have a way to revert if issues arise
  • Incident response: War room access and dedicated support during critical periods

The biggest risk is often organizational readiness, not technical. We invest heavily in change management and training.

Do you help with pricing and monetization strategies? +

Yes, if APIs are a business asset for you (partner ecosystems, platform strategies, etc.), we help design pricing models that:

  • Align with your business objectives (penetration, retention, monetization)
  • Work across your customer segments
  • Are easy to communicate and understand
  • Scale smoothly as usage grows

Common models: free tier + paid tiers, usage-based billing, enterprise contracts, and hybrid approaches.

What accessibility standards do you follow? +

We design all user-facing systems (developer portals, admin dashboards, documentation) to WCAG 2.1 AA standard. This includes:

  • Keyboard navigation and focus management
  • Proper semantic HTML and ARIA labels
  • Sufficient color contrast and text sizing
  • Clear navigation and consistent structure
  • Readable alt text for all imagery

Accessibility is a requirement, not a nice-to-have. It improves usability for everyone.

What happens after we launch? +

The Enable phase doesn't end at launch. We provide:

  • Training and knowledge transfer for your teams
  • Documented runbooks and operational procedures
  • Post-launch optimization and tuning
  • Ongoing support based on your tier
  • Guidance for the next phase of evolution

Success isn't measured at launch—it's measured at 6 months, 12 months, and beyond when your organization is operating the system independently.

How do I know if Stackform is a good fit? +

Good fit looks like:

  • You have multiple integrations or a platform strategy
  • Teams are struggling with fragmented or inconsistent APIs
  • You want to scale your integration capability
  • You're willing to invest in getting it right
  • Your leadership is committed to the transformation

The best way to know is to talk. We'll be honest about fit and can tell you quickly if we're the right partner.

Didn't find your answer?

Reach out anytime. We're happy to discuss your specific situation.

Get in Touch