OldKnowledge,New Vessel.
Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.
Enter the archive →— 00 / ThesisEvery business runs on knowledge older than its software.
Latest Entries
The AI Can Read Your COBOL. It Still Can't Tell You Why the Business Does It That Way
One Label Added, $40,000 a Year Gone: Cardinality Is Your Real Observability Bill
Your AI Wrote 400 Tests and Coverage Hit 94%. None of Them Would Catch a Bug
You Can't Un-Ship an API: Versioning, Deprecation, and Getting Consumers Off v1
The Libraries You Depend On Are Drowning in AI Slop — and Your Risk Model Assumes They Aren't
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
We digitize centuries-old manuscripts. Then we build with the same discipline.
AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.
Built for Every Business
Intelligence that never leaves the device
Offline-first, data-sovereign systems — LLMs, vector search, inference at the edge.
02Document IntelligenceAir-gapped document vaults
Sealed, searchable, provable.
03AI ProductsFull-cycle AI product builds
Mobile-first, production-grade.
04MCP & AI SecuritySecuring the agentic stack
Tool poisoning, prompt injection, confused deputies — studied and hardened.
05Indic Language AIOCR for scripts the world forgot
Sovereign OCR for Indic scripts.
06Consulting & Architecture19+ years shipping at scale
OTT, e-commerce & mobility platforms serving millions.

The AI Can Read Your COBOL. It Still Can't Tell You Why the Business Does It That Way
LLMs read COBOL well. They cannot tell deliberate policy from a forty-year-old bug. Rule extraction, parallel-run reconciliation and reversible cutover.

One Label Added, $40,000 a Year Gone: Cardinality Is Your Real Observability Bill
Your monitoring bill doubled and nobody added a service. One unbounded label multiplies every other label. How to budget, enforce and cap cardinality.

Your AI Wrote 400 Tests and Coverage Hit 94%. None of Them Would Catch a Bug
AI-generated tests assert what the code does, not what it should do — so they pass on bugs and fail on fixes. Why coverage broke, and what to measure instead.

You Can't Un-Ship an API: Versioning, Deprecation, and Getting Consumers Off v1
Three live versions, nobody moves off v1, every change is a negotiation. Versioning strategies, what really counts as breaking, and designing an exit you can actually use.

The Libraries You Depend On Are Drowning in AI Slop — and Your Risk Model Assumes They Aren't
Your dependency tree rests on volunteers whose inboxes became unreviewable. Maintenance health as a risk signal your CVE scanner structurally cannot see.

Slopsquatting: Your AI Agent Installs Packages That Don't Exist — Until an Attacker Registers Them
Your coding agent invented a package name. An attacker already registered it. Slopsquatting, why typosquatting defences miss it, and the install-time gates that stop it.

Your Internal Platform Is a Ticket Queue With a Logo: Building an IDP Developers Actually Use
You built a developer platform and everyone still copies the last service. Portals versus paved roads, golden paths with escape hatches, and the metrics that prove leverage.

Stack Churn Is Eating Your Roadmap: A Decision Framework for Choosing Technology That Lasts
Your team rewrote the same feature three times in four years. The innovation-budget framework for choosing technology that lasts — and spotting churn wearing a business case.

Building DPDP-Compliant Systems for Minors: Consent Engine, Feed Gating, and an Audit Trail That Holds
DPDP Rule 10 is notified law on a deadline. The consent state machine, age-band tokens, feed gating, and an audit trail that survives someone trying to rewrite it.

The 3-Tier Parental Control Architecture: Why App Settings Alone Never Work
You maxed out every parental control the app offers and the feed is still wrong. The three tiers that actually hold: DNS filtering, OS hard gates, and feed modification.

Regulating the Feed, Not Just the Data: Why India's DPDP Act Won't Fix Social Media for Children
A platform can be fully compliant with India’s DPDP Act and still run an engagement-maximising feed at a fourteen-year-old. Why privacy law misses the curation problem.

The Agentic Web: Your Next Million Visitors Are AI Agents, and Your Site Isn't Built for Them
Half your traffic has no eyes. It extracts, cites, and acts — and a site built for human browsers fails it silently. The agentic-web architecture: structure, llms.txt, bot policy.

HTMX vs Next.js in 2026: Hypermedia or SPA — and Is HTMX Just PHP With Better Manners?
Your CRUD dashboard ships 900KB of JavaScript to render a table. HTMX vs Next.js in 2026: architectures, the PHP question, pros and cons, and the decision that actually matters.

How to Actually Evaluate a RAG System in 2026: Faithfulness, Groundedness, and the Metrics That Catch Failures
Your RAG "feels accurate" in the demo and is quietly wrong at scale. Evaluate it as two systems: retrieval metrics + faithfulness/groundedness, in a golden-set harness in CI.

Stop Hand-Tuning Prompts: Programmatic Prompt Optimization and the DSPy Shift in 2026
Three weeks nudging a prompt and it still breaks. Stop hand-tuning: programmatic prompt optimization (DSPy) specifies the task and metric and compiles the prompt for you.

Time-Series Foundation Models in Production 2026: Zero-Shot Forecasting That Beats Your Tuned Pipeline
You maintain forty forecasting models. One pretrained model now beats them zero-shot. Time-series foundation models in production: benchmarking, covariates, uncertainty, serving.

Model Deprecation Is a Production Outage With a Calendar Date: The Migration Architecture for 2026
Your provider just announced the model you run on shuts down in 90 days. The migration architecture — inventory, abstraction, version pinning, golden-set evals, canary rollout.

The 5% GPU Utilization Problem: Why Your Inference Bill Is Enormous and Your GPUs Are Idle
Your GPU bill soars while the GPUs sit ~95% idle. It’s a utilization problem, not a capacity one — continuous batching, scale-to-zero, fractional GPU, and the demand-side fix.

Why 86% of Multi-Agent Pilots Never Reach Production — and the Orchestration Architecture That Ships
The multi-agent demo dazzled; the system died before production. Only ~14% of pilots ship — the orchestration reliability layer, compounding-error math, and how to reach 99%.

Late-Interaction Retrieval in 2026: When Your RAG Fails Because a Single Vector Isn't Enough
Your RAG isn’t hallucinating — retrieval handed it the wrong chunk because one vector blurred the detail. Late interaction (ColBERT) and visual retrieval (ColPali), right-sized.
Bring this thinkingto your business.
conversation
One essay, most weeks. No noise.