Specifics, not thought leadership.
What things actually cost, which approach we would pick and why, and what we got wrong often enough to write down. Written by the engineers doing the work.
Recent writing.
- Mobile·3 min
App Store Optimisation: a checklist for a first launch
Most first launches lose installs to fixable causes — an unindexed title, screenshots that show the interface instead of the benefit, and a rejection nobody planned for. The store listing is a conversion surface, and it is worth the same attention as the app.
- Blockchain·3 min
Smart contract audits: process, cost and what gets found
An audit is a time-boxed review by people trying to break your contracts before someone with a financial motive does. Most findings are access control, arithmetic and external-call ordering. A clean report is evidence of effort, not a guarantee of safety.
- Software engineering·4 min
Legacy modernisation without a big-bang rewrite
A rewrite asks a team to rebuild years of accumulated behaviour while the original keeps changing, then swap everything at once. Replacing the system piece by piece behind a routing layer is slower to start and far more likely to finish.
- Working with us·4 min
What custom software actually costs in India
Custom software development in India typically ranges from roughly $15,000 for a focused MVP to $250,000 and above for an enterprise platform. The number is driven by integration surface and compliance requirements far more than by feature count.
- Working with us·3 min
What government clients require from a software vendor
Public sector work is not enterprise work with more paperwork. It is evaluated against published criteria, audited afterwards, and built to outlive the vendor who delivered it. The requirements that disqualify bidders are usually documentation, accessibility and data residency rather than technical capability.
- AI & machine learning·3 min
Building AI agents that are safe to deploy inside an enterprise
An agent that can act is a system with write access, and it should be designed like one. The controls that matter are least-privilege tools, reversible actions, a human gate on anything irreversible, and evaluation that runs before deployment rather than after complaints.
- Security·4 min
ISO 27001, SOC 2 and GDPR: what an Indian vendor actually needs
ISO 27001 certifies that you run an information security management system. SOC 2 reports on whether your controls actually operated over a period. GDPR is law, not a certificate. Most Indian vendors are asked for all three and need them in a specific order.
- AI & machine learning·3 min
RAG or fine-tuning? A decision framework
Use retrieval-augmented generation for knowledge that changes and must be cited. Use fine-tuning for fixed format, tone and specialised task behaviour. Most production systems need both, and the split should follow an evaluation rather than a preference.
- Mobile·3 min
Flutter or React Native, and when to go native
Flutter renders its own UI and suits animation-heavy, visually consistent apps. React Native maps to native components and suits teams with existing React expertise. Both are production-grade — team skills usually decide it, and native is worth it only for deep platform capability.
- Security·3 min
What a VAPT engagement actually includes
VAPT combines a broad vulnerability assessment with manual penetration testing that attempts to exploit findings and establish real impact. A genuine engagement produces reproduction steps, business impact and a retest — not a scanner export with a logo on it.
- Web & performance·3 min
Core Web Vitals, and why most corporate sites fail them
Core Web Vitals are three field metrics Google uses to measure loading, responsiveness and visual stability. Most corporate sites fail them for the same handful of reasons, and most of those reasons are fixable without a redesign.
- Blockchain·3 min
Do you actually need a blockchain?
A blockchain earns its cost only when multiple parties who do not fully trust each other must agree on shared state, assets must move without an intermediary, or an outside party must verify history independently. Otherwise a database is cheaper, faster and correctable.
Have a question we have not written about?
Ask it directly. If the answer is useful to other people, it usually becomes the next article.