Skip to content
The AppScale ArchiveWriting on Sovereign AI
21.4934° N / 86.9135° EEST. 2025 — India
438+ Essays · 33 Series
Scroll ↓

OldKnowledge,New Vessel.

Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.

Enter the archive →
— 00 / ThesisEvery business runs on knowledge older than its software.
01The Archive

Latest Entries

Full index — 438 essays →
02The Library
श्रीगणेशाय नमः ॥
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
[ Coming Soon ]

We digitize centuries-old manuscripts. Then we build with the same discipline.

AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.

न हि ज्ञानेन सदृशं पवित्रमिह विद्यते ।
“Nothing in this world purifies like knowledge.”
Bhagavad Gita · 4.38
03Capabilities

Built for Every Business

Executive AI Series · MCP Security · 日本語 · Edge AI Engineering ·
RAG in Production · Sovereign AI · Fine-Tuning · Agentic Systems ·
19+ yrs engineering·npm — react-native-edge-vector-store·Read in IN · JP · SG·AppScale LLP — DPIIT recognized
05Full Index
Blast-Radius Budgets for Write-Capable Agents: Spend, Scope and Reversibility Are Three Caps, Not One Permission (2026)
ai-architecture1 min read

Blast-Radius Budgets for Write-Capable Agents: Spend, Scope and Reversibility Are Three Caps, Not One Permission (2026)

An agent's authority is a budget that depletes, not a permission that persists. Cap spend at the meter, scope in the credential, irreversibility at the platform.

September 24, 2026Read
Bug Bounty in the AI-Slop Era: Pay for the Reproduction, Not the Report (2026)
cyber-security-patterns1 min read

Bug Bounty in the AI-Slop Era: Pay for the Reproduction, Not the Report (2026)

AI made vulnerability reports free to write and left them expensive to validate. Gate intake with identity and a runnable PoC, reproduce in a sandbox, pay for proof.

September 24, 2026Read
SEC Cyber Disclosure: The Four-Day Clock Starts When You Decide, So Make the Decision an Engineered Record (2026)
cyber-security-patterns1 min read

SEC Cyber Disclosure: The Four-Day Clock Starts When You Decide, So Make the Decision an Engineered Record (2026)

The SEC four-day 8-K clock starts at the materiality decision. How to engineer the facts, convening triggers and audit trail behind it, and what not to automate.

September 23, 2026Read
Active-Active Multi-Region: You Are Buying Disagreement, So Decide Who Wins Per Entity (2026)
multi-cloud-infrastructure1 min read

Active-Active Multi-Region: You Are Buying Disagreement, So Decide Who Wins Per Entity (2026)

Active-active is not two regions that both work; it is two regions allowed to disagree. Classify entities, pick a write model per class, and prove the failover.

September 23, 2026Read
ISO 27001 vs SOC 2 for Indian Product Companies: Choose the Control Set Once, Attest Twice (2026)
cyber-security-patterns1 min read

ISO 27001 vs SOC 2 for Indian Product Companies: Choose the Control Set Once, Attest Twice (2026)

ISO 27001 and SOC 2 are two auditors reading one control set. Build it once, sequence by revenue geography, and skip the "SOC 2 in two weeks" package the AICPA now flags.

September 22, 2026Read
The Sidecar Tax: Ambient Mesh, the eBPF Data Plane, and What a Sidecarless Migration Actually Buys (2026)
microservices-patterns1 min read

The Sidecar Tax: Ambient Mesh, the eBPF Data Plane, and What a Sidecarless Migration Actually Buys (2026)

Sidecarless meshes do not make L7 cheaper; they let you stop buying L7 for services that never used it. Istio ambient vs Cilium eBPF vs sidecars, with the honest limits.

September 22, 2026Read
Fleet Firmware Updates as a Security Control: Signing, Staged Rollout, and Rollback (2026)
cyber-security-patterns1 min read

Fleet Firmware Updates as a Security Control: Signing, Staged Rollout, and Rollback (2026)

The OTA updater is the root of trust after day one. A 2026 guide to offline signing keys, director targeting, A/B slots, staged cohorts and rollback that never un-patches.

September 21, 2026Read
AML Transaction Monitoring: The False-Positive Economics Nobody Models (2026)
cyber-security-patterns1 min read

AML Transaction Monitoring: The False-Positive Economics Nobody Models (2026)

AML alerts are free to generate and expensive to close. A 2026 architecture for tiered monitoring: rules for coverage, a scoring layer to route, dispositions as labels.

September 21, 2026Read
Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)
ai-architecture1 min read

Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)

For AI work that can move in time or space, the cleanest grid hour is usually the cheapest. A 2026 guide to carbon-aware scheduling, marginal signals and clean-power procurement.

September 20, 2026Read
OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)
cyber-security-patterns1 min read

OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)

OT security inverts IT priorities — availability and safety first. A 2026 guide to Purdue zones and conduits, protocol gateways, data diodes and patching by reachability, not CVSS.

September 20, 2026Read
Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)
cyber-security-patterns1 min read

Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)

A wallet credential is a presentation you verify, not an identity you store: integrate EUDI and mDL as a higher-assurance branch behind the onboarding step you already run.

September 19, 2026Read
Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)
cyber-security-patterns1 min read

Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)

The cyber-insurance questionnaire is an architecture spec written by an actuary: map MFA, EDR and immutable backups to real systems, evidence each, and cut premium and loss.

September 19, 2026Read
Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)
ai-architecture1 min read

Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)

3D Gaussian Splatting became web infrastructure once delivery caught up: SPZ and SOG compression, WebGPU rendering, streamed LOD. The pipeline is the product — not the capture.

September 18, 2026Read
Age Assurance Architecture: Estimation, Verification, and the Privacy Trade-off (2026)
cyber-security-patterns1 min read

Age Assurance Architecture: Estimation, Verification, and the Privacy Trade-off (2026)

Age assurance is an attribute-release problem, not identity collection: estimation with a buffer age, double-blind tokens and retention you can prove — the 2026 architecture.

September 18, 2026Read
RLVR: Reinforcement Learning from Verifiable Rewards, and Where It Breaks (2026)
ai-architecture1 min read

RLVR: Reinforcement Learning from Verifiable Rewards, and Where It Breaks (2026)

RLVR trains models against a verifier instead of a reward model. Where correctness is checkable it is powerful; where the checker can be gamed it fails.

September 17, 2026Read
Bot Management in the Residential-Proxy Era: Detecting Humanlike Automation (2026)
cyber-security-patterns1 min read

Bot Management in the Residential-Proxy Era: Detecting Humanlike Automation (2026)

Rate limits and CAPTCHAs no longer stop bots riding residential proxies. The architecture that works scores intent from device, behaviour and network provenance.

September 17, 2026Read
Insider Threat and UEBA Architecture Without Surveillance Theatre (2026)
cyber-security-patterns1 min read

Insider Threat and UEBA Architecture Without Surveillance Theatre (2026)

Insider detection fails as surveillance, works as economics: behavioural baselines, priced alerts, pseudonymised triage — the UEBA architecture that survives review.

September 16, 2026Read
Digital Public Infrastructure: Architecting on UPI, ONDC and Aadhaar-Class Rails (2026)
architecture-patterns1 min read

Digital Public Infrastructure: Architecting on UPI, ONDC and Aadhaar-Class Rails (2026)

UPI, ONDC and Aadhaar give you a billion-user network without a contract — and no SLA, no chargebacks, no support queue. The architecture you owe a public rail.

September 16, 2026Read
External Attack Surface Management: Finding the Assets Nobody Owns (2026)
cyber-security-patterns1 min read

External Attack Surface Management: Finding the Assets Nobody Owns (2026)

EASM is a discovery-to-ownership pipeline, not a scanner: seed, expand, verify, attribute, decide — and default unclaimed assets to decommission before they are exploited.

September 15, 2026Read
SIM Swap and the Telecom Channel: Designing Authentication That Survives It (2026)
cyber-security-patterns1 min read

SIM Swap and the Telecom Channel: Designing Authentication That Survives It (2026)

SIM swap defeats SMS and voice OTP at the carrier, not in your stack. The architecture: demote the number, query carrier SIM-change signals, and tier recovery.

September 15, 2026Read
04Contact

Bring this thinkingto your business.

Start a
conversation

One essay, most weeks. No noise.