OldKnowledge,New Vessel.
Essays on on-device AI, data sovereignty, and building systems that keep knowledge where it belongs.
Enter the archive →— 00 / ThesisEvery business runs on knowledge older than its software.
Latest Entries
Account Takeover Defence Architecture: Signals, Scoring, and Step-Up (2026)
Real-Time Infrastructure at Scale: WebRTC, SFUs, and the Cost Curve (2026)
LiteLLM vs Portkey vs Kong vs Cloudflare: The AI Gateway You Actually Need (2026)
Edge Runtime or Multi-Region? The Latency You Buy vs the Complexity You Own
Card-Not-Present Fraud: 3DS, Risk Routing and the Approval-Rate Trade-off
अथ प्रथमोऽध्यायः ॥
विद्या ददाति विनयं विनयाद् याति पात्रताम् ।
पात्रत्वाद्धनमाप्नोति धनाद्धर्मं ततः सुखम् ॥
We digitize centuries-old manuscripts. Then we build with the same discipline.
AppScale's roots are in a quiet project: structuring classical Sanskrit texts into faithful digital form. Extraction, structure, provenance, sovereignty — the same principles now power our client work.
Built for Every Business
Intelligence that never leaves the device
Offline-first, data-sovereign systems — LLMs, vector search, inference at the edge.
02Document IntelligenceAir-gapped document vaults
Sealed, searchable, provable.
03AI ProductsFull-cycle AI product builds
Mobile-first, production-grade.
04MCP & AI SecuritySecuring the agentic stack
Tool poisoning, prompt injection, confused deputies — studied and hardened.
05Indic Language AIOCR for scripts the world forgot
Sovereign OCR for Indic scripts.
06Consulting & Architecture19+ years shipping at scale
OTT, e-commerce & mobility platforms serving millions.

Account Takeover Defence Architecture: Signals, Scoring, and Step-Up (2026)
Account takeover now arrives with valid stolen credentials. The defence is not more MFA — it is login as a continuous risk score, with step-up spent only when earned.

Real-Time Infrastructure at Scale: WebRTC, SFUs, and the Cost Curve (2026)
Mesh WebRTC dies at five participants. The SFU is the real group-video topology — and the bill lives in egress and TURN relay, not the media server.

LiteLLM vs Portkey vs Kong vs Cloudflare: The AI Gateway You Actually Need (2026)
AI gateways converge on features and diverge on deployment. LiteLLM, Portkey, Kong and Cloudflare compared on the axis that decides: who runs it and where it sits.

Edge Runtime or Multi-Region? The Latency You Buy vs the Complexity You Own
Edge runtime or multi-region? The edge only wins when the request needs no region-bound data. The moment it hits your database, data gravity drags the latency back.

Card-Not-Present Fraud: 3DS, Risk Routing and the Approval-Rate Trade-off
Card-not-present is now most card fraud. 3DS is not prevention — it is a liability-and-friction router. Route challenges by risk, keep the safe majority frictionless.

Stablecoin Payment Rails: Settlement Architecture for Real Products
The on-chain transfer is minutes of work. The ledger, reconciliation, treasury and compliance are the build — on a rail with no chargebacks, you inherit the acquirer's job.

The Passkey Migration Nobody Plans: Recovery, Fallback, and Enterprise Rollout
Passkeys make login unphishable — so attackers phish recovery, fallback and the helpdesk instead. The enterprise migration is won or lost in the flows nobody budgets for.

CDC at Scale: When Debezium Becomes the Critical Path
CDC is trivial to demo and hard to operate. At scale it becomes a dependency of your source database — the slot pins WAL, the snapshot hurts the source, the schema break is silent.

Kubernetes Security Architecture: Admission, Runtime, and Network Policy That Hold
A passing scan is not a control. Kubernetes security lives in four enforcing planes — admission, RBAC, network, runtime — and a cluster is only as strong as the weakest.

Reverse ETL and the Operational Analytics Loop: The Write Path Nobody Owns
Reverse ETL pushes modelled warehouse data into the SaaS tools where work happens. It is a write path you do not control — and idempotency plus change detection is the whole game.

The Cyber Resilience Act Is a Product Security Contract, Not a Paperwork Exercise
The EU Cyber Resilience Act reporting duty lands 11 September 2026. It is a product security contract — here is the SBOM, support-period and incident architecture it forces.

Ephemeral Preview Environments: On-Demand Provisioning Without the Staging Queue
Shared staging serialises every team through one mutable environment. The per-PR preview architecture: GitOps reconciliation, database branching, TTLs and quotas.

Which Agent Is Actually Calling? Authentication and Impersonation in Multi-Agent Systems
Multi-agent systems launder user identity into prose at the first hop. The architecture that stops impersonation: SPIFFE identity, RFC 8693 delegation chains, signed cards.

Improper Output Handling: When the LLM's Answer Becomes XSS, SSRF or RCE
When an LLM app renders or executes model output unencoded, the model becomes an injection vector for XSS, SSRF and RCE. The output-handling boundary that stops it.

HBM Is the Bottleneck, Not FLOPs: Designing Inference Around Memory Bandwidth
Your GPU sits idle generating tokens because decode is memory-bound. Why HBM bandwidth in TB/s, not peak FLOPs, decides your inference serving architecture.

Model Extraction Over the API: Stealing a Model You Never Shipped
You never released your weights, yet a rival ships a model that behaves like yours. How model extraction over the API works — and the layered defence that raises its cost.

Parquet Is Not Free: Encoding, Layout and the Scan You Didn't Need
Parquet gives you the option to read less; bad layout throws it away. How row-group size, encodings, footer stats and the page index cut the scan you pay for.

Data Mesh, Five Years On: What Survived Contact With Production
Five years on, two of data mesh’s four principles survived and two were abandoned. What domain ownership, data-as-a-product, federated governance and self-serve became.

Backdoored Weights: Data Poisoning and Sleeper Behaviour in Fine-Tuned Models
A backdoored model passes every benchmark and fires only on a trigger. Data poisoning, sleeper behaviour, and the provenance-first supply chain that actually contains it.

Your Browsing Agent Just Read an Attacker's Web Page
A browsing agent obeys the page it reads. Indirect prompt injection, the lethal trifecta, and the dual-LLM plus egress-gating architecture that actually contains it.
Bring this thinkingto your business.
conversation
One essay, most weeks. No noise.