OldKnowledge,New Vessel.
Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.
Enter the archive →— 00 / ThesisEvery business runs on knowledge older than its software.
Latest Entries
The Predictive-Maintenance Closed Loop: Digital-Twin Architecture From Sensor to Work Order (2026)
Outcome-Based Pricing for Software: The Metering, Attribution and Dispute Architecture (2026)
Automated Threat Modelling: STRIDE at the Speed of a Sprint (2026)
Technical Debt in AI-Generated Codebases: Detection and Containment (2026)
DORA for Engineering Teams: Operational Resilience Beyond the Policy Document (2026)
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
We digitize centuries-old manuscripts. Then we build with the same discipline.
AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.
Built for Every Business
Intelligence that never leaves the device
Offline-first, data-sovereign systems — LLMs, vector search, inference at the edge.
02Document IntelligenceAir-gapped document vaults
Sealed, searchable, provable.
03AI ProductsFull-cycle AI product builds
Mobile-first, production-grade.
04MCP & AI SecuritySecuring the agentic stack
Tool poisoning, prompt injection, confused deputies — studied and hardened.
05Indic Language AIOCR for scripts the world forgot
Sovereign OCR for Indic scripts.
06Consulting & Architecture19+ years shipping at scale
OTT, e-commerce & mobility platforms serving millions.

The Predictive-Maintenance Closed Loop: Digital-Twin Architecture From Sensor to Work Order (2026)
Predictive maintenance fails when the loop stays open: a dashboard predicts and nothing happens. The digital-twin architecture from sensor to approved work order to feedback.

Outcome-Based Pricing for Software: The Metering, Attribution and Dispute Architecture (2026)
Outcome-based pricing makes your metering pipeline a system of record for money. How to define the outcome, meter it idempotently, attribute it with evidence, and survive disputes.

Automated Threat Modelling: STRIDE at the Speed of a Sprint (2026)
Threat modelling dies as an annual workshop. The 2026 pattern: a diagram-as-code model that STRIDE-analyses every pull request and fails the build on new risk.

Technical Debt in AI-Generated Codebases: Detection and Containment (2026)
AI-generated code fails as plausibility, not a crash. The 2026 taxonomy of that debt, how to detect it by provenance and churn, and the containment architecture.

DORA for Engineering Teams: Operational Resilience Beyond the Policy Document (2026)
DORA is engineering capabilities with clocks: 4-hour incident notification, a graph-backed provider register, TLPT every 3 years, rehearsed exits, measured restores.

SPIFFE/SPIRE: Workload Identity Without Long-Lived Secrets, and the Attestation Chain That Makes It Real (2026)
SPIRE issues short-lived SVIDs only after node and workload attestation, so no workload stores a secret. Design the chain, keep 1h TTLs, federate across clouds.

Alert Fatigue Is an Architecture Problem, Not a Discipline Problem (2026)
The on-call still gets 400 pages a week after every cleanup because pages fire on causes, not symptoms. The fix is SLO burn-rate alerting, inhibition, and ownership routing.

Signed Images or It Didn't Ship: Sigstore, Attestations, and Admission Gates That Actually Refuse (2026)
"We sign all our images" stops nothing until an admission gate refuses. Identity not keys, SLSA provenance, digest pinning, fail-closed per namespace, and negative tests.

Secret Rotation at Scale: The Architecture Behind "We Rotated Everything" (2026)
After the Drift and Nx token thefts, "rotate everything" took weeks. The architecture that makes it a button: overlap windows, evidence-gated revoke, dynamic credentials.

Data Clean Room Architecture: Privacy-Preserving Collaboration Without Handing Over the Data (2026)
Clean rooms are query policy engines, not storage. How identity matching, analysis rules and privacy budgets let partners compute joins without handing over data.

Diffusion Language Models: Parallel Text Generation and What It Breaks (2026)
Autoregressive models decode one token at a time. Diffusion LLMs generate tokens in parallel at 1,000+ per second — but break KV-cache, streaming, and length handling.

AI Feature Unit Economics: The Gross Margin Per Request Nobody Modelled (2026)
An AI feature’s cost scales with usage while flat pricing does not, so power users can run deeply negative margins. Model gross margin per request, then defend it.

Account Takeover Defence Architecture: Signals, Scoring, and Step-Up (2026)
Account takeover now arrives with valid stolen credentials. The defence is not more MFA — it is login as a continuous risk score, with step-up spent only when earned.

Real-Time Infrastructure at Scale: WebRTC, SFUs, and the Cost Curve (2026)
Mesh WebRTC dies at five participants. The SFU is the real group-video topology — and the bill lives in egress and TURN relay, not the media server.

LiteLLM vs Portkey vs Kong vs Cloudflare: The AI Gateway You Actually Need (2026)
AI gateways converge on features and diverge on deployment. LiteLLM, Portkey, Kong and Cloudflare compared on the axis that decides: who runs it and where it sits.

Edge Runtime or Multi-Region? The Latency You Buy vs the Complexity You Own
Edge runtime or multi-region? The edge only wins when the request needs no region-bound data. The moment it hits your database, data gravity drags the latency back.

Card-Not-Present Fraud: 3DS, Risk Routing and the Approval-Rate Trade-off
Card-not-present is now most card fraud. 3DS is not prevention — it is a liability-and-friction router. Route challenges by risk, keep the safe majority frictionless.

Stablecoin Payment Rails: Settlement Architecture for Real Products
The on-chain transfer is minutes of work. The ledger, reconciliation, treasury and compliance are the build — on a rail with no chargebacks, you inherit the acquirer's job.

The Passkey Migration Nobody Plans: Recovery, Fallback, and Enterprise Rollout
Passkeys make login unphishable — so attackers phish recovery, fallback and the helpdesk instead. The enterprise migration is won or lost in the flows nobody budgets for.

CDC at Scale: When Debezium Becomes the Critical Path
CDC is trivial to demo and hard to operate. At scale it becomes a dependency of your source database — the slot pins WAL, the snapshot hurts the source, the schema break is silent.
Bring this thinkingto your business.
conversation
One essay, most weeks. No noise.