Hello Mithun
On point 1. We do not provide a standard integration flow for this. But, if you want to include PI for security, you can create a pass-through integration flow. It will have the input and outputs but with no mapping.
On point 2, normally for mashups you do not use middleware, it a URL or HTML call.
Right now these are described in the admin guide.
Check back with us early next year for further updates.
All the best
Ginger