Skip to content
The AppScale ArchiveWriting on Sovereign AI
21.4934° N / 86.9135° EEST. 2025 — India
438+ Essays · 33 Series
Scroll ↓

OldKnowledge,New Vessel.

Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.

Enter the archive →
— 00 / ThesisEvery business runs on knowledge older than its software.
01The Archive

Latest Entries

Full index — 438 essays →
02The Library
श्रीगणेशाय नमः ॥
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
[ Coming Soon ]

We digitize centuries-old manuscripts. Then we build with the same discipline.

AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.

न हि ज्ञानेन सदृशं पवित्रमिह विद्यते ।
“Nothing in this world purifies like knowledge.”
Bhagavad Gita · 4.38
03Capabilities

Built for Every Business

Executive AI Series · MCP Security · 日本語 · Edge AI Engineering ·
RAG in Production · Sovereign AI · Fine-Tuning · Agentic Systems ·
19+ yrs engineering·npm — react-native-edge-vector-store·Read in IN · JP · SG·AppScale LLP — DPIIT recognized
05Full Index
Backstage Adoption: A Reality Check — It Is a Framework You Staff, Not a Portal You Install (2026)
ai-architecture1 min read

Backstage Adoption: A Reality Check — It Is a Framework You Staff, Not a Portal You Install (2026)

Backstage is a framework you staff, not a portal you install. Self-host with a central team, pay a vendor to host it, or buy a non-Backstage portal: how to decide in 2026.

September 25, 2026Read
Content Provenance for the Enterprise: C2PA Signs the Origin, Durable Credentials Survive the Strip (2026)
cyber-security-patterns1 min read

Content Provenance for the Enterprise: C2PA Signs the Origin, Durable Credentials Survive the Strip (2026)

Article 50 applies from August 2026 and a C2PA manifest dies at the first re-encode. Sign the origin, add a soft binding, run a repository, log the marking as evidence.

September 25, 2026Read
Blast-Radius Budgets for Write-Capable Agents: Spend, Scope and Reversibility Are Three Caps, Not One Permission (2026)
ai-architecture1 min read

Blast-Radius Budgets for Write-Capable Agents: Spend, Scope and Reversibility Are Three Caps, Not One Permission (2026)

An agent's authority is a budget that depletes, not a permission that persists. Cap spend at the meter, scope in the credential, irreversibility at the platform.

September 24, 2026Read
Bug Bounty in the AI-Slop Era: Pay for the Reproduction, Not the Report (2026)
cyber-security-patterns1 min read

Bug Bounty in the AI-Slop Era: Pay for the Reproduction, Not the Report (2026)

AI made vulnerability reports free to write and left them expensive to validate. Gate intake with identity and a runnable PoC, reproduce in a sandbox, pay for proof.

September 24, 2026Read
SEC Cyber Disclosure: The Four-Day Clock Starts When You Decide, So Make the Decision an Engineered Record (2026)
cyber-security-patterns1 min read

SEC Cyber Disclosure: The Four-Day Clock Starts When You Decide, So Make the Decision an Engineered Record (2026)

The SEC four-day 8-K clock starts at the materiality decision. How to engineer the facts, convening triggers and audit trail behind it, and what not to automate.

September 23, 2026Read
Active-Active Multi-Region: You Are Buying Disagreement, So Decide Who Wins Per Entity (2026)
multi-cloud-infrastructure1 min read

Active-Active Multi-Region: You Are Buying Disagreement, So Decide Who Wins Per Entity (2026)

Active-active is not two regions that both work; it is two regions allowed to disagree. Classify entities, pick a write model per class, and prove the failover.

September 23, 2026Read
ISO 27001 vs SOC 2 for Indian Product Companies: Choose the Control Set Once, Attest Twice (2026)
cyber-security-patterns1 min read

ISO 27001 vs SOC 2 for Indian Product Companies: Choose the Control Set Once, Attest Twice (2026)

ISO 27001 and SOC 2 are two auditors reading one control set. Build it once, sequence by revenue geography, and skip the "SOC 2 in two weeks" package the AICPA now flags.

September 22, 2026Read
The Sidecar Tax: Ambient Mesh, the eBPF Data Plane, and What a Sidecarless Migration Actually Buys (2026)
microservices-patterns1 min read

The Sidecar Tax: Ambient Mesh, the eBPF Data Plane, and What a Sidecarless Migration Actually Buys (2026)

Sidecarless meshes do not make L7 cheaper; they let you stop buying L7 for services that never used it. Istio ambient vs Cilium eBPF vs sidecars, with the honest limits.

September 22, 2026Read
Fleet Firmware Updates as a Security Control: Signing, Staged Rollout, and Rollback (2026)
cyber-security-patterns1 min read

Fleet Firmware Updates as a Security Control: Signing, Staged Rollout, and Rollback (2026)

The OTA updater is the root of trust after day one. A 2026 guide to offline signing keys, director targeting, A/B slots, staged cohorts and rollback that never un-patches.

September 21, 2026Read
AML Transaction Monitoring: The False-Positive Economics Nobody Models (2026)
cyber-security-patterns1 min read

AML Transaction Monitoring: The False-Positive Economics Nobody Models (2026)

AML alerts are free to generate and expensive to close. A 2026 architecture for tiered monitoring: rules for coverage, a scoring layer to route, dispositions as labels.

September 21, 2026Read
Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)
ai-architecture1 min read

Carbon-Aware Scheduling: Energy as an Architecture Input for AI Datacenters (2026)

For AI work that can move in time or space, the cleanest grid hour is usually the cheapest. A 2026 guide to carbon-aware scheduling, marginal signals and clean-power procurement.

September 20, 2026Read
OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)
cyber-security-patterns1 min read

OT/IT Convergence Security: Architecture for When Downtime Is Physical (2026)

OT security inverts IT priorities — availability and safety first. A 2026 guide to Purdue zones and conduits, protocol gateways, data diodes and patching by reachability, not CVSS.

September 20, 2026Read
Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)
cyber-security-patterns1 min read

Digital Identity Wallets: Integrating EUDI and mDL Without Rebuilding Onboarding (2026)

A wallet credential is a presentation you verify, not an identity you store: integrate EUDI and mDL as a higher-assurance branch behind the onboarding step you already run.

September 19, 2026Read
Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)
cyber-security-patterns1 min read

Cyber Insurance Controls Mapped to Architecture: What Underwriters Actually Require (2026)

The cyber-insurance questionnaire is an architecture spec written by an actuary: map MFA, EDR and immutable backups to real systems, evidence each, and cut premium and loss.

September 19, 2026Read
Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)
ai-architecture1 min read

Gaussian Splatting and Neural Rendering as Product Infrastructure: The 3D Capture-to-Web Pipeline (2026)

3D Gaussian Splatting became web infrastructure once delivery caught up: SPZ and SOG compression, WebGPU rendering, streamed LOD. The pipeline is the product — not the capture.

September 18, 2026Read
Age Assurance Architecture: Estimation, Verification, and the Privacy Trade-off (2026)
cyber-security-patterns1 min read

Age Assurance Architecture: Estimation, Verification, and the Privacy Trade-off (2026)

Age assurance is an attribute-release problem, not identity collection: estimation with a buffer age, double-blind tokens and retention you can prove — the 2026 architecture.

September 18, 2026Read
RLVR: Reinforcement Learning from Verifiable Rewards, and Where It Breaks (2026)
ai-architecture1 min read

RLVR: Reinforcement Learning from Verifiable Rewards, and Where It Breaks (2026)

RLVR trains models against a verifier instead of a reward model. Where correctness is checkable it is powerful; where the checker can be gamed it fails.

September 17, 2026Read
Bot Management in the Residential-Proxy Era: Detecting Humanlike Automation (2026)
cyber-security-patterns1 min read

Bot Management in the Residential-Proxy Era: Detecting Humanlike Automation (2026)

Rate limits and CAPTCHAs no longer stop bots riding residential proxies. The architecture that works scores intent from device, behaviour and network provenance.

September 17, 2026Read
Insider Threat and UEBA Architecture Without Surveillance Theatre (2026)
cyber-security-patterns1 min read

Insider Threat and UEBA Architecture Without Surveillance Theatre (2026)

Insider detection fails as surveillance, works as economics: behavioural baselines, priced alerts, pseudonymised triage — the UEBA architecture that survives review.

September 16, 2026Read
Digital Public Infrastructure: Architecting on UPI, ONDC and Aadhaar-Class Rails (2026)
architecture-patterns1 min read

Digital Public Infrastructure: Architecting on UPI, ONDC and Aadhaar-Class Rails (2026)

UPI, ONDC and Aadhaar give you a billion-user network without a contract — and no SLA, no chargebacks, no support queue. The architecture you owe a public rail.

September 16, 2026Read
04Contact

Bring this thinkingto your business.

Start a
conversation

One essay, most weeks. No noise.