Blog

Articles about API gateways, spec-driven development, and building with Rust and WASM.

Compliance by design, part 2: the compliance controls

From schema validation and secrets management to FIPS 140-3 cryptography and GitOps workflows — the specific controls Barbacane provides for SOC 2, PCI DSS, HIPAA, FedRAMP, and beyond.

barbacane api-gateway compliance security audit fips soc2 pci-dss policy-as-code
Read more

How we build our roadmap at Barbacane

A roadmap isn't a feature wishlist. It's a series of bets about what matters most, made with incomplete information. Here's how we decide what to build next for an open-source API gateway.

barbacane open-source roadmap engineering
Read more