What does API integration involve?
All integrations between software systems where data is exchanged automatically through a standardised interface — usually a REST or GraphQL API, sometimes webhooks or event streams. In practice: your CRM passing deals on to your accounting, your webshop syncing orders with your ERP, or your ATS passing candidates to payroll. Government integrations such as KvK, BAG, Peppol and DigiD also fall under this.
iPaaS or custom development: what should I choose?
Depends on volume, complexity and maintenance burden. iPaaS (Workato, Boomi, MuleSoft, Make) is quicker to set up and suits relatively simple many-to-many integrations. Custom middleware pays off for complex transformations, high volume, strict compliance, or where code ownership matters. A mixed landscape works too: iPaaS for the simple flows, custom builds where it counts. We've written an in-depth
API vs integration platform comparison.
Which vendors do you integrate with?
Too many to list, but the most requested: Salesforce, HubSpot, Pipedrive (CRM); Exact Online, AFAS, Twinfield, Microsoft Dynamics (accounting/ERP); Bullhorn, Connexys, Homerun, Recruitee, HR-Office (recruitment); NMBRS, Visma, Loket (payroll); Shopify, Magento, WooCommerce (e-commerce); Mollie, Adyen, Stripe, Buckaroo, MultiSafepay (payments); WhatsApp Business, Twilio, Slack, Teams (communication); Microsoft Entra, Okta (SSO); KvK, BAG, Kadaster, Peppol, DigiD (government); Snowflake, BigQuery, Power BI (data). Almost any SaaS system with a documented API, we can integrate.
How secure is this? GDPR, encryption, audit?
As standard: encryption in transit (TLS 1.2+) and at rest, OAuth2 or OIDC for authentication, secrets held in a vault (never in plain text in code), and an audit log of who changed what. For every integration we produce a data flow diagram that classifies each field (personal data, financial, sensitive), which you can use as input for your DPIA. Where relevant we also consider DORA (financial sector), NIS2 (critical infrastructure) or NEN 7510 (healthcare).
What determines the cost of an integration?
Three main factors: the number of systems and data flows, the complexity of the transformations (a one-to-one mapping is cheap, business logic with validation and enrichment costs more), and the level of error handling you need. A simple Shopify-Exact integration is a different project from a multi-PSP routing setup with fraud detection. After the audit, we provide a concrete scope with a sprint budget, not open-ended hourly estimates.
How long does a project like this take?
For a simple point-to-point integration, a first working integration can be in place within a few sprints. A broader integration landscape with multiple systems, transformations and a compliance layer takes several sprints. We work in fixed sprints so you can adjust course after each one and recalibrate the scope based on what we learn.
Who owns the code?
You do. As standard, all custom code sits in your repository under your account, and credentials and API keys live in your own vault. For iPaaS implementations you own the tenant and the flows, and we only have access for as long as it is needed. No lock-in: you can change implementation partner at any time without losing the integration itself.
Can you migrate from iPaaS to custom development (or the other way round)?
Yes. Many clients start with a no-code tool such as Zapier or Make and over time run into its limits: performance, error handling, or a monthly fee that gets out of hand. We migrate step by step: first the pain points move to custom middleware or a more powerful iPaaS, then the rest. The reverse also works: a hardened custom system can be scaled back to iPaaS for parts simple enough to suit it.
How do you handle multi-tenant or multi-business-unit setups?
For organisations with several business units, or software vendors delivering client-specific integrations, we build a layer in which tenants are logically separated. Each tenant has its own credentials, its own mapping rules and its own logs. Configuration is handled through an admin UI or declaratively in code, depending on what suits your team.
What do you do about monitoring and error recovery?
Every integration is monitored for throughput, latency and failure rate. Messages that cannot be processed successfully go to a dead-letter queue with a retry strategy. Critical failures trigger alerts to the channel of your choice (Slack, Teams, PagerDuty, email). For custom integrations we also build a replay UI so your own team can intervene manually without developer help.
Do you work alongside our in-house IT department?
Almost always. We run knowledge transfer in the final sprints, deliver runbooks for incident response, and agree clear responsibilities. For some clients we act as the main contractor; for others we are an extension of an internal platform team that keeps overall control. We also work with other integrations or agencies your organisation already uses, without ego and with sound mutual agreements.
What if the vendor API changes unexpectedly?
It inevitably happens: Salesforce, Shopify and Microsoft regularly push breaking changes. For our active clients, we follow the release notes of the integrated systems, test against upcoming versions in a sandbox, and patch before the deadline. For clients on a maintenance contract, this is part of the service; outside that, we warn you in good time so you can decide who resolves it.
Do you also do AI or LLM integrations?
Yes. We connect LLMs (OpenAI, Anthropic, Azure OpenAI, or self-hosted models) to business processes for enrichment, classification or automated processing. Examples include categorising incoming emails, summarising contracts, or routing customer enquiries. Always with deterministic fallbacks and human-in-the-loop for critical decisions: an LLM should not approve invoices on its own.