Skip to content
The AppScale ArchiveWriting on Sovereign AI
21.4934° N / 86.9135° EEST. 2025 — India
467+ Essays · 34 Series
Scroll ↓

OldKnowledge,New Vessel.

Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.

Enter the archive →
— 00 / ThesisEvery business runs on knowledge older than its software.
01The Archive

Latest Entries

Full index — 467 essays →
02The Library
श्रीगणेशाय नमः ॥
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
[ Coming Soon ]

We digitize centuries-old manuscripts. Then we build with the same discipline.

AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.

न हि ज्ञानेन सदृशं पवित्रमिह विद्यते ।
“Nothing in this world purifies like knowledge.”
Bhagavad Gita · 4.38
03Capabilities

Built for Every Business

Executive AI Series · MCP Security · 日本語 · Edge AI Engineering ·
RAG in Production · Sovereign AI · Fine-Tuning · Agentic Systems ·
19+ yrs engineering·npm — react-native-edge-vector-store·Read in IN · JP · SG·AppScale LLP — DPIIT recognized
05Full Index
Multi-Tenancy in Internal Platforms: Namespaces Isolate What Is Namespaced, So Choose the Tenancy Model by Who Owns the Cluster-Scoped Objects (2026)
multi-cloud-infrastructure1 min read

Multi-Tenancy in Internal Platforms: Namespaces Isolate What Is Namespaced, So Choose the Tenancy Model by Who Owns the Cluster-Scoped Objects (2026)

Namespace per team, vCluster virtual control planes or cluster per team: how to pick a Kubernetes tenancy model for internal platforms by who owns the cluster-scoped objects.

October 9, 2026Read
Homomorphic Encryption in Production: The Server Computes Blind, So Only Fixed-Shape Lookups and Small Models Pay, and Everything Else Is a Trusted-Execution Decision (2026)
cyber-security-patterns1 min read

Homomorphic Encryption in Production: The Server Computes Blind, So Only Fixed-Shape Lookups and Small Models Pay, and Everything Else Is a Trusted-Execution Decision (2026)

What homomorphic encryption can do in production in 2026, what Apple and Zama actually run, where it fails, and when a trusted execution environment is the honest answer.

October 9, 2026Read
Real-Time Streaming Into a Digital Twin: The Twin Is a Materialised View With a Staleness Contract, Not a Database You Write Sensor Data Into (2026)
ai-architecture1 min read

Real-Time Streaming Into a Digital Twin: The Twin Is a Materialised View With a Staleness Contract, Not a Database You Write Sensor Data Into (2026)

Sparkplug, MQTT, Kafka and the twin platform in four tiers: how sensor data should flow into Azure Digital Twins, TwinMaker or Ditto, and the staleness contract that stops lag.

October 8, 2026Read
WASM at the Edge: The Cold Start Is the Price of the Trust Boundary, So Choose the Sandbox by What the Code Must Be Allowed to Do (2026)
multi-cloud-infrastructure1 min read

WASM at the Edge: The Cold Start Is the Price of the Trust Boundary, So Choose the Sandbox by What the Code Must Be Allowed to Do (2026)

Isolates, Wasm sandboxes, microVMs and containers compared on the limits vendors publish, where Wasm is the right edge boundary, and what no cold start really costs you.

October 8, 2026Read
World Models in Production: The Model Simulates the Environment, So Treat It as a Generative Test Harness and Never as Ground Truth (2026)
ai-architecture1 min read

World Models in Production: The Model Simulates the Environment, So Treat It as a Generative Test Harness and Never as Ground Truth (2026)

Genie 3, Cosmos 3, Waymo's world model and Marble: where a generative environment belongs in a robotics or autonomy stack, the two-simulator pattern, and where it lies to you.

October 7, 2026Read
Confidential Containers on Kubernetes: The Pod Treats Its Own Cluster as the Adversary, So Every Platform Convenience Becomes a Policy Decision (2026)
ai-architecture1 min read

Confidential Containers on Kubernetes: The Pod Treats Its Own Cluster as the Adversary, So Every Platform Convenience Becomes a Policy Decision (2026)

Confidential containers put the pod in a TEE and your own Kubelet, admins and control plane outside it. CoCo v0.23, AKS preview, GKE nodes and OpenShift 1.13 compared for 2026.

October 7, 2026Read
ROS 2 in Production: The Distro Is a Dependency, the Middleware Is a Decision and the Default QoS Is a Field Bug Waiting to Happen (2026)
ai-architecture1 min read

ROS 2 in Production: The Distro Is a Dependency, the Middleware Is a Decision and the Default QoS Is a Field Bug Waiting to Happen (2026)

Your ROS 2 robot worked in the lab and fails in the warehouse. Distro end-of-life dates, Fast DDS vs Cyclone vs Zenoh, QoS as a contract and executors for 2026 fleets.

October 6, 2026Read
Secure by Design Is an Engineering Contract, Not a Pledge: Turn CISA's Seven Goals Into Release Gates That Can Fail a Build (2026)
cybersecurity1 min read

Secure by Design Is an Engineering Contract, Not a Pledge: Turn CISA's Seven Goals Into Release Gates That Can Fail a Build (2026)

You signed CISA's Secure by Design pledge. What does engineering have to show? Seven goals rewritten as release gates with metrics, owners and SSDF anchors for 2026.

October 6, 2026Read
RAG Citation Forgery: A Citation Is a Claim About a Source, Not Evidence, So Verify the Link, the Passage and the Claim as Three Separate Things (2026)
cybersecurity1 min read

RAG Citation Forgery: A Citation Is a Claim About a Source, Not Evidence, So Verify the Link, the Passage and the Claim as Three Separate Things (2026)

Your RAG answer came with a footnote. Who put it there? Four citation forgery classes and the resolve-entail-attest architecture that binds link, passage and claim in 2026.

October 5, 2026Read
Tokenised Real-World Assets: The Token Is a Pointer, Not the Asset, So Design the Four Places the Pointer Meets the World (2026)
ai-architecture1 min read

Tokenised Real-World Assets: The Token Is a Pointer, Not the Asset, So Design the Four Places the Pointer Meets the World (2026)

A token is a pointer, not the asset. The 2026 architecture for tokenised funds and bonds: custody, eligibility, oracles and settlement finality, with ERC-3643 and the DLT Pilot.

October 5, 2026Read
Golden-Path Template Drift: Every Scaffold Is a Fork, So Treat the Template as a Dependency With a Version and an Update Channel (2026)
multi-cloud-infrastructure1 min read

Golden-Path Template Drift: Every Scaffold Is a Fork, So Treat the Template as a Dependency With a Version and an Update Channel (2026)

You fixed the service template. 214 scaffolded services did not get the fix. Why golden-path templates drift and how to treat the template as a versioned dependency in 2026.

October 4, 2026Read
Threat Intelligence Enrichment With LLMs: The Report-to-STIX Pipeline, and Exactly Where the Model Lies (2026)
cybersecurity1 min read

Threat Intelligence Enrichment With LLMs: The Report-to-STIX Pipeline, and Exactly Where the Model Lies (2026)

LLMs can turn 300 threat reports a week into STIX, or into a hallucination archive. The report-to-STIX pipeline, where the model lies, and the controls that stop it in 2026.

October 4, 2026Read
What SLA Can Your Internal Platform Actually Promise? Platform SLOs, Reliability Contracts and Error Budgets for Internal Developer Platforms (2026)
multi-cloud-infrastructure1 min read

What SLA Can Your Internal Platform Actually Promise? Platform SLOs, Reliability Contracts and Error Budgets for Internal Developer Platforms (2026)

Platform SLOs are contracts about the request path, not uptime. How to split planes, set targets under your cloud SLA and write a bilateral error-budget policy in 2026.

October 3, 2026Read
When the Defender Is the Model: Adversarial Evasion of AI-Based Detection in Fraud, EDR and Anti-Abuse Systems (2026)
cyber-security-patterns1 min read

When the Defender Is the Model: Adversarial Evasion of AI-Based Detection in Fraud, EDR and Anti-Abuse Systems (2026)

Your fraud, EDR or abuse model is a classifier the attacker can query for free. How evasion works by domain and the 2026 architecture that makes probing expensive.

October 3, 2026Read
The Twin Is a Read Model, Not a System of Record: Integrating a Digital Twin With ERP and MES Using ISA-95 (2026)
architecture1 min read

The Twin Is a Read Model, Not a System of Record: Integrating a Digital Twin With ERP and MES Using ISA-95 (2026)

Digital twins fail when they keep a third copy of ERP and MES truth. Use ISA-95 ownership, OPC UA, outbox commands and reconciliation to stay trusted in 2026.

October 2, 2026Read
The Victim Is the Authenticated User: Pig-Butchering Scam Detection Architecture for Banks, Fintechs and Exchanges (2026)
cyber-security-patterns1 min read

The Victim Is the Authenticated User: Pig-Butchering Scam Detection Architecture for Banks, Fintechs and Exchanges (2026)

Pig-butchering victims pass every auth check because they mean to pay. Detect the escalating episode, map mule graphs and design interventions that work in 2026.

October 2, 2026Read
A Chaos Experiment Is a Hypothesis Test, Not a Fault Injection: Steady State, Blast Radius, Abort Conditions and the Blame Problem (2026)
multi-cloud-infrastructure1 min read

A Chaos Experiment Is a Hypothesis Test, Not a Fault Injection: Steady State, Blast Radius, Abort Conditions and the Blame Problem (2026)

Most chaos programmes inject faults and learn nothing. Steady state, falsifiable hypotheses, bounded blast radius, tested aborts and blameless findings, in 2026.

October 1, 2026Read
Encryption Hides the Words, Not the Rhythm: Token-Length and Timing Side Channels in Streaming LLMs, and Why Your Own Proxy Is the Hop That Leaks (2026)
cyber-security-patterns1 min read

Encryption Hides the Words, Not the Rhythm: Token-Length and Timing Side Channels in Streaming LLMs, and Why Your Own Proxy Is the Hop That Leaks (2026)

TLS hides what an LLM says, not how it streams. How token-length and timing side channels leak topics, and why your own proxy is usually the hop that leaks.

October 1, 2026Read
A Topology Spread Constraint Is an Admission-Time Promise, Not a Runtime Invariant: Fixing Pod Distribution Drift on EKS with the Descheduler (2026)
multi-cloud-infrastructure1 min read

A Topology Spread Constraint Is an Admission-Time Promise, Not a Runtime Invariant: Fixing Pod Distribution Drift on EKS with the Descheduler (2026)

Topology spread is checked once, at pod placement. Why EKS pod distribution drifts after a zone gap, what it costs in resilience, and when the descheduler is safe to run.

September 30, 2026Read
The Semantic Layer Is Now an AI Interface: The Model Picks the Metric, the Compiler Writes the SQL (2026)
ai-architecture1 min read

The Semantic Layer Is Now an AI Interface: The Model Picks the Metric, the Compiler Writes the SQL (2026)

The semantic layer is now an AI interface. What MetricFlow, Snowflake semantic views, Databricks metric views and Apache Ossie give you, and when not to build one.

September 30, 2026Read
04Contact

Bring this thinkingto your business.

Start a
conversation

One essay, most weeks. No noise.