Skip to content
The AppScale ArchiveWriting on Sovereign AI
21.4934° N / 86.9135° EEST. 2025 — India
420+ Essays · 32 Series
Scroll ↓

OldKnowledge,New Vessel.

Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.

Enter the archive
— 00 / ThesisEvery business runs on knowledge older than its software.
01The Archive

Latest Entries

Full index — 420 essays →
02The Library
श्रीगणेशाय नमः ॥
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
[ Coming Soon ]

We digitize centuries-old manuscripts. Then we build with the same discipline.

AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.

न हि ज्ञानेन सदृशं पवित्रमिह विद्यते ।
“Nothing in this world purifies like knowledge.”
Bhagavad Gita · 4.38
03Capabilities

Built for Every Business

Executive AI Series · MCP Security · 日本語 · Edge AI Engineering ·
RAG in Production · Sovereign AI · Fine-Tuning · Agentic Systems ·
19+ yrs engineering·npm — react-native-edge-vector-store·Read in IN · JP · SG·AppScale LLP — DPIIT recognized
05Full Index
External Attack Surface Management: Finding the Assets Nobody Owns (2026)
cyber-security-patterns1 min read

External Attack Surface Management: Finding the Assets Nobody Owns (2026)

EASM is a discovery-to-ownership pipeline, not a scanner: seed, expand, verify, attribute, decide — and default unclaimed assets to decommission before they are exploited.

September 15, 2026Read
SIM Swap and the Telecom Channel: Designing Authentication That Survives It (2026)
cyber-security-patterns1 min read

SIM Swap and the Telecom Channel: Designing Authentication That Survives It (2026)

SIM swap defeats SMS and voice OTP at the carrier, not in your stack. The architecture: demote the number, query carrier SIM-change signals, and tier recovery.

September 15, 2026Read
CERT-In Directions in Practice: 6-Hour Reporting and 180-Day Logs as an Architecture (2026)
cyber-security-patterns1 min read

CERT-In Directions in Practice: 6-Hour Reporting and 180-Day Logs as an Architecture (2026)

CERT-In's 6-hour reporting and 180-day India-resident log mandate, read as a specification: instrument the "noticed" event and build a queryable, tamper-evident log tier.

September 14, 2026Read
KV-Cache Side Channels: Cross-Tenant Prompt Leakage in Shared LLM Inference (2026)
cyber-security-patterns1 min read

KV-Cache Side Channels: Cross-Tenant Prompt Leakage in Shared LLM Inference (2026)

Shared prefix caches leak prompts across tenants through timing. Why a content-keyed KV cache is an oracle, and how to put the tenant boundary into the cache key.

September 14, 2026Read
Logging Without Leaking: PII, Secrets and the Observability Boundary (2026)
cyber-security-patterns1 min read

Logging Without Leaking: PII, Secrets and the Observability Boundary (2026)

Logs are the most-replicated copy of your sensitive data. Redact PII and secrets at emit — not at read — and treat the log pipeline as a DLP export path.

September 13, 2026Read
Built-In Browser AI: On-Device Models Behind a Web API (2026)
ai-engineering1 min read

Built-In Browser AI: On-Device Models Behind a Web API (2026)

Chrome now runs an on-device LLM behind web APIs. Treat built-in AI as a detected enhancement with a real fallback — never a hard dependency.

September 13, 2026Read
Open Weights vs Closed Models: A Strategy Decision, Not a Values Debate (2026)
ai-strategy-leadership1 min read

Open Weights vs Closed Models: A Strategy Decision, Not a Values Debate (2026)

Open vs closed AI is not a values debate. It is a per-workload choice of which lever you buy — cost floor, exit cost, or compliance. The move is a portfolio, not a camp.

September 12, 2026Read
Credential Stuffing at Scale: Rate Limits Are Not a Defence (2026)
cyber-security-patterns1 min read

Credential Stuffing at Scale: Rate Limits Are Not a Defence (2026)

Per-IP rate limits never stop credential stuffing — it is distributed across a proxy botnet. The real defences price the attack: breached-password checks, device signals, passkeys.

September 12, 2026Read
Continuous Validation: Breach and Attack Simulation vs the Annual Pentest (2026)
cyber-security-patterns1 min read

Continuous Validation: Breach and Attack Simulation vs the Annual Pentest (2026)

The annual pentest is a photo; breach and attack simulation is the regression test that proves your controls still detect known ATT&CK techniques and catches control drift.

September 11, 2026Read
Vision-Language-Action Models: The Robotics Foundation-Model Shift (2026)
ai-architecture-patterns1 min read

Vision-Language-Action Models: The Robotics Foundation-Model Shift (2026)

VLA foundation models — GR00T, Gemini Robotics, π0.5, OpenVLA — reshaped robotics by 2026. The architecture that matters is not the model but the dual-rate loop around it.

September 11, 2026Read
The Predictive-Maintenance Closed Loop: Digital-Twin Architecture From Sensor to Work Order (2026)
architecture1 min read

The Predictive-Maintenance Closed Loop: Digital-Twin Architecture From Sensor to Work Order (2026)

Predictive maintenance fails when the loop stays open: a dashboard predicts and nothing happens. The digital-twin architecture from sensor to approved work order to feedback.

September 10, 2026Read
Outcome-Based Pricing for Software: The Metering, Attribution and Dispute Architecture (2026)
architecture1 min read

Outcome-Based Pricing for Software: The Metering, Attribution and Dispute Architecture (2026)

Outcome-based pricing makes your metering pipeline a system of record for money. How to define the outcome, meter it idempotently, attribute it with evidence, and survive disputes.

September 10, 2026Read
Automated Threat Modelling: STRIDE at the Speed of a Sprint (2026)
cyber-security-patterns1 min read

Automated Threat Modelling: STRIDE at the Speed of a Sprint (2026)

Threat modelling dies as an annual workshop. The 2026 pattern: a diagram-as-code model that STRIDE-analyses every pull request and fails the build on new risk.

September 9, 2026Read
Technical Debt in AI-Generated Codebases: Detection and Containment (2026)
ai-engineering1 min read

Technical Debt in AI-Generated Codebases: Detection and Containment (2026)

AI-generated code fails as plausibility, not a crash. The 2026 taxonomy of that debt, how to detect it by provenance and churn, and the containment architecture.

September 9, 2026Read
DORA for Engineering Teams: Operational Resilience Beyond the Policy Document (2026)
cyber-security-patterns1 min read

DORA for Engineering Teams: Operational Resilience Beyond the Policy Document (2026)

DORA is engineering capabilities with clocks: 4-hour incident notification, a graph-backed provider register, TLPT every 3 years, rehearsed exits, measured restores.

September 8, 2026Read
SPIFFE/SPIRE: Workload Identity Without Long-Lived Secrets, and the Attestation Chain That Makes It Real (2026)
cyber-security-patterns1 min read

SPIFFE/SPIRE: Workload Identity Without Long-Lived Secrets, and the Attestation Chain That Makes It Real (2026)

SPIRE issues short-lived SVIDs only after node and workload attestation, so no workload stores a secret. Design the chain, keep 1h TTLs, federate across clouds.

September 8, 2026Read
Alert Fatigue Is an Architecture Problem, Not a Discipline Problem (2026)
multi-cloud-infrastructure1 min read

Alert Fatigue Is an Architecture Problem, Not a Discipline Problem (2026)

The on-call still gets 400 pages a week after every cleanup because pages fire on causes, not symptoms. The fix is SLO burn-rate alerting, inhibition, and ownership routing.

September 7, 2026Read
Signed Images or It Didn't Ship: Sigstore, Attestations, and Admission Gates That Actually Refuse (2026)
cyber-security-patterns1 min read

Signed Images or It Didn't Ship: Sigstore, Attestations, and Admission Gates That Actually Refuse (2026)

"We sign all our images" stops nothing until an admission gate refuses. Identity not keys, SLSA provenance, digest pinning, fail-closed per namespace, and negative tests.

September 7, 2026Read
Secret Rotation at Scale: The Architecture Behind "We Rotated Everything" (2026)
security1 min read

Secret Rotation at Scale: The Architecture Behind "We Rotated Everything" (2026)

After the Drift and Nx token thefts, "rotate everything" took weeks. The architecture that makes it a button: overlap windows, evidence-gated revoke, dynamic credentials.

September 6, 2026Read
Data Clean Room Architecture: Privacy-Preserving Collaboration Without Handing Over the Data (2026)
ai-architecture1 min read

Data Clean Room Architecture: Privacy-Preserving Collaboration Without Handing Over the Data (2026)

Clean rooms are query policy engines, not storage. How identity matching, analysis rules and privacy budgets let partners compute joins without handing over data.

September 6, 2026Read
04Contact

Bring this thinkingto your business.

Start a
conversation

One essay, most weeks. No noise.