Category
Guides
Type
Hub page
For
Founders, PMs, developers
Tone
Educational
Updated
May 2026

Technical guides.

A collection of practical guides on app and software development. Written to help you ask the right questions before choosing a supplier, not to sell you anything.

What this hub is

This page brings together the technical guides we write at Appfront for people in the middle of a project where software decisions have to be made. A founder thinking about a first app, a product manager looking for a supplier, a dev lead who has to explain internally why a particular architecture does or doesn't fit: that's the audience.

Each guide covers a single, clearly defined topic and aims to treat it as neutrally as possible. We have no commercial interest in which technology or partner you choose; we do have an interest in you understanding the trade-offs. Our experience building custom software for clients — see also software development and app development — is reflected in the content.

The guides can be read on their own, but they refer to one another where topics overlap. Architecture and compliance, for example, constantly overlap; AI questions often bring security decisions with them. We try to make those connections explicit rather than pretending each topic stands alone. For readers who want more context on the wider knowledge base, our knowledge bank offers additional background articles that are not classed as "guides" but are still relevant.

i
Tone of these guides

Educational, not salesy. If a guide helps you obtain a better quote from someone else, we have done our job too.

Guides on app development

App development has a few topics that keep prompting the same questions: security, the difference between apps serving business users and consumers, what goes wrong with internal apps, and the minimum bar for getting through the app stores. We have written a deeper explanation for each of these themes.

Available

If you want to look beyond these guides, our knowledge base also covers broader topics around strategy, costs and architecture that are relevant to app projects.

Guides on web development

In web development, most questions concern architecture choices: whether to go for a single-page application or classic server-rendered pages, whether to opt for a traditional CMS or a headless variant, and how to maintain performance at the level Google and your users expect. We are actively writing on these themes; some guides are already live, others are on the way.

In development
  • SPA versus MPA — when to choose which Topic The architectural trade-off between single-page applications (React, Vue, Svelte) and multi-page applications with server-side rendering. SEO impact, performance budget, and what it means for your development team.
  • Headless CMS — why and when Topic Headless versus traditional: what changes for your editors, what changes for your developers, and how you can tell whether you are ready for it.
  • Web performance as a business topic Topic Core Web Vitals, image budgets, and why a slow site costs you both conversions and SEO at the same time. What can be improved in practice without a complete rebuild.

Guides on AI

AI has gone from futuristic to a standard component of many software projects in just two years. The questions we hear most often are less about "can it be done" and more about: how do we make it reliable, how do we keep hallucinations under control, and how do we turn an AI strategy into actual implementation. Our guide on AI agents for businesses covers that last point from an operational angle.

In development
  • AI strategy for your organisation Topic From use-case inventory to a first pilot: how organisations without a data team can still build a realistic AI strategy. With attention to governance and build-versus-buy.
  • AI implementation in existing software Topic Where to place an LLM in your architecture: as a standalone service, as an integration, or as part of an agent workflow. With considerations around cost per call and latency.
  • Hallucination mitigation in production Topic Retrieval-augmented generation, grounded prompting, output validation and human checks. What works to keep factual errors at an acceptable level in business applications.

Compliance guides

Compliance questions rarely arise at the start of a project, but they become more urgent midway through or just before going live. Most people have come across GDPR at some point, but the AI Act, NEN 7510 for healthcare, and DORA for financial institutions are newer topics that impose specific architectural choices.

In development
  • GDPR for software projects Topic Practical guidance: what belongs in a data processing agreement, how to handle the right to erasure in a database architecture, and when a DPIA is truly necessary.
  • The AI Act — what changes for your software Topic The European AI Act classifies systems by risk. What falls where, and which obligations apply to a high-risk application.
  • NEN 7510 for healthcare software Topic Information security in healthcare requires specific measures. How NEN 7510 relates to ISO 27001 and what it means for your architecture.
  • DORA — operational resilience in finance Topic The Digital Operational Resilience Act sets requirements for financial institutions and their ICT suppliers. What changes in incident reporting, third-party management and testing.

Architecture guides

The architectural choice made in year one often determines how much pain you feel in year three. Microservices sound modern but are not always the right answer; a well-structured modular monolith takes many teams much further. We cover these trade-offs, along with the integration question that affects almost every project.

In development
  • Microservices — for whom and when Topic The cases where microservices genuinely add value, versus the cases where they mainly bring complexity and operational burden.
  • Monolith versus modular monolith Topic Why a modular monolith is often the right starting point for SMEs and scale-ups, and how you can later split it up if needed.
  • APIs versus integration platforms Hub page Our other hub page, focused on integrations: direct API integrations versus iPaaS platforms such as Workato, Mulesoft or Boomi.

How to use these guides

The guides are not meant to be read in one sitting. Each reader takes something different from them, depending on their role in the project. A few suggestions to help you get started:

As a founder or client

Start with the topics closest to your business question. If you want to build an internal app, begin with the guide on ten pitfalls in internal apps and the wider context on our app development page. The aim: making sure you notice during vendor conversations when someone leaves out something important.

As a product manager

You mainly use these guides to test your own assumptions. Topics around architecture, security and compliance are where product managers often depend on engineering. Our guides give you just enough to ask the right questions, without you having to become a developer.

As a developer or dev lead

Many topics will probably be familiar ground, but the guides can be handy as an internal link to share when you need to explain a choice to business stakeholders. Pointing to a guide is sometimes more efficient than writing yet another document yourself.

As a compliance or security officer

The compliance guides focus in particular on the intersection of legislation and concrete software decisions. They are not full legal texts, which you should leave to your lawyer, but they do cover the architectural consequences of a classification or obligation. The pieces on the AI Act, NEN 7510 and DORA in particular are written so you can hand them to an engineering team without any translation step in between.

As a director or decision-maker without a technical background

Some guides are written more closely to the technology than others. If you prefer a higher-level read, the hub pages themselves are often a good start: the knowledge base as an overview, and this page as the entry point to the deeper pieces. The compliance guides and the guide on internal business apps are also easy to follow without technical background.

Update cycle and versions

Every guide carries a date stamp and is reviewed at least once a year. For fast-moving topics such as AI and compliance, we look more often. If a guide has fundamentally changed, we note that at the top; for minor improvements, we only update the date.

Reviews are not a detached desk exercise. They are carried out by the same people who work with these topics on live projects. As a result, corrections from practice tend to make their way into the text quickly. A discovery at a client, such as a new pitfall, a changing API policy or a revised legal interpretation, can be reflected in the relevant guide within a few days.

We deliberately keep the content pragmatic. No academic completeness, just the trade-offs we find relevant in practice. If you miss a topic you would find useful, we would love to hear about it. Email fabian.vandijk@appfront.nl with a short description. We add suggestions to our backlog and get back to you once a guide is planned or published.

For people who would rather talk to a person than to a guide: that is always possible. An introductory call is deliberately low-threshold: half an hour, no obligation, and you speak with someone who builds software themselves rather than only writing quotes. See contact for the details.

Frequently Asked Questions

What exactly is in these guides?

Each guide covers one clearly defined topic: the definition, the trade-offs you need to make, the pitfalls we encounter in practice, and a number of concrete questions you can put to a potential supplier. No marketing, no sales talk. Our services are listed separately, under services.

Who writes the guides?

The guides are written by the Appfront team, with Fabian van Dijk as editor-in-chief. Every guide is checked for content by at least one developer and one of our project leads.

Can I suggest new guides?

Please do. Send an email to fabian.vandijk@appfront.nl with the topic you would like to read and the reason why. The more specific your context, the more useful the guide we can write. Not every suggestion makes it onto our backlog, but recurring questions take priority.

How often are the guides updated?

A full review every year, and in between whenever something changes that affects the content, such as new legislation, a major technology shift, or a correction we spot ourselves. The date at the top of each guide shows the most recent review.

May I reuse or quote the guides?

Quoting with attribution is fine. Please do not reproduce longer passages verbatim without checking with us first. Are you wondering whether a specific use is allowed? Emailing us usually resolves that within a day.

Do you also offer personal advice based on the guides?

Yes. For most readers the guides are enough, but if you would rather discuss your specific situation, you can schedule a no-obligation introductory conversation via contact. We do not charge for that time, and you are under no obligation.

No guide found that fits?

Sometimes your question sits between two topics, or your context is just a bit more specific. In that case, book a no-obligation introductory conversation: half an hour, no commitments, and you will speak straight away with someone who builds software themselves.

Edit content