OldKnowledge,New Vessel.
Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.
Enter the archive →— 00 / ThesisEvery business runs on knowledge older than its software.
Latest Entries
Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)
OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)
Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)
Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)
Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
We digitize centuries-old manuscripts. Then we build with the same discipline.
AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.
Built for Every Business
Intelligence that never leaves the device
Offline-first, data-sovereign systems — LLMs, vector search, inference at the edge.
02Document IntelligenceAir-gapped document vaults
Sealed, searchable, provable.
03AI ProductsFull-cycle AI product builds
Mobile-first, production-grade.
04MCP & AI SecuritySecuring the agentic stack
Tool poisoning, prompt injection, confused deputies — studied and hardened.
05Indic Language AIOCR for scripts the world forgot
Sovereign OCR for Indic scripts.
06Consulting & Architecture19+ years shipping at scale
OTT, e-commerce & mobility platforms serving millions.

Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)
For AI work that can move in time or space, the cleanest grid hour is usually the cheapest. A 2026 guide to carbon-aware scheduling, marginal signals and clean-power procurement.

OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)
OT security inverts IT priorities — availability and safety first. A 2026 guide to Purdue zones and conduits, protocol gateways, data diodes and patching by reachability, not CVSS.

Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)
A wallet credential is a presentation you verify, not an identity you store: integrate EUDI and mDL as a higher-assurance branch behind the onboarding step you already run.

Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)
The cyber-insurance questionnaire is an architecture spec written by an actuary: map MFA, EDR and immutable backups to real systems, evidence each, and cut premium and loss.

Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)
3D Gaussian Splatting became web infrastructure once delivery caught up: SPZ and SOG compression, WebGPU rendering, streamed LOD. The pipeline is the product — not the capture.

Age Assurance Architecture: Estimation, Verification, and the Privacy Trade-off (2026)
Age assurance is an attribute-release problem, not identity collection: estimation with a buffer age, double-blind tokens and retention you can prove — the 2026 architecture.

RLVR: Reinforcement Learning from Verifiable Rewards, and Where It Breaks (2026)
RLVR trains models against a verifier instead of a reward model. Where correctness is checkable it is powerful; where the checker can be gamed it fails.

Bot Management in the Residential-Proxy Era: Detecting Humanlike Automation (2026)
Rate limits and CAPTCHAs no longer stop bots riding residential proxies. The architecture that works scores intent from device, behaviour and network provenance.

Insider Threat and UEBA Architecture Without Surveillance Theatre (2026)
Insider detection fails as surveillance, works as economics: behavioural baselines, priced alerts, pseudonymised triage — the UEBA architecture that survives review.

Digital Public Infrastructure: Architecting on UPI, ONDC and Aadhaar-Class Rails (2026)
UPI, ONDC and Aadhaar give you a billion-user network without a contract — and no SLA, no chargebacks, no support queue. The architecture you owe a public rail.

External Attack Surface Management: Finding the Assets Nobody Owns (2026)
EASM is a discovery-to-ownership pipeline, not a scanner: seed, expand, verify, attribute, decide — and default unclaimed assets to decommission before they are exploited.

SIM Swap and the Telecom Channel: Designing Authentication That Survives It (2026)
SIM swap defeats SMS and voice OTP at the carrier, not in your stack. The architecture: demote the number, query carrier SIM-change signals, and tier recovery.

CERT-In Directions in Practice: 6-Hour Reporting and 180-Day Logs as an Architecture (2026)
CERT-In's 6-hour reporting and 180-day India-resident log mandate, read as a specification: instrument the "noticed" event and build a queryable, tamper-evident log tier.

KV-Cache Side Channels: Cross-Tenant Prompt Leakage in Shared LLM Inference (2026)
Shared prefix caches leak prompts across tenants through timing. Why a content-keyed KV cache is an oracle, and how to put the tenant boundary into the cache key.

Logging Without Leaking: PII, Secrets and the Observability Boundary (2026)
Logs are the most-replicated copy of your sensitive data. Redact PII and secrets at emit — not at read — and treat the log pipeline as a DLP export path.

Built-In Browser AI: On-Device Models Behind a Web API (2026)
Chrome now runs an on-device LLM behind web APIs. Treat built-in AI as a detected enhancement with a real fallback — never a hard dependency.

Open Weights vs Closed Models: A Strategy Decision, Not a Values Debate (2026)
Open vs closed AI is not a values debate. It is a per-workload choice of which lever you buy — cost floor, exit cost, or compliance. The move is a portfolio, not a camp.

Credential Stuffing at Scale: Rate Limits Are Not a Defence (2026)
Per-IP rate limits never stop credential stuffing — it is distributed across a proxy botnet. The real defences price the attack: breached-password checks, device signals, passkeys.

Continuous Validation: Breach and Attack Simulation vs the Annual Pentest (2026)
The annual pentest is a photo; breach and attack simulation is the regression test that proves your controls still detect known ATT&CK techniques and catches control drift.

Vision-Language-Action Models: The Robotics Foundation-Model Shift (2026)
VLA foundation models — GR00T, Gemini Robotics, π0.5, OpenVLA — reshaped robotics by 2026. The architecture that matters is not the model but the dual-rate loop around it.
Bring this thinkingto your business.
conversation
One essay, most weeks. No noise.