+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Blog

Practical insights on cloud, security, data, and AI from the engineers doing the work.

Filter
Website development cost in India in 2026

If you have collected three quotes for a website and they read ₹18,000, ₹95,000 and ₹4 lakh, you are not being cheated by two of them. You have asked three companies a question that has no single answer, and each has assumed a different project. This page sets out what each price band actually buys in India, what the recurring costs are, and the three questions that make quotes comparable.

Keep reading
IT Strategy

Aug 20, 2026 5 min read

Website development cost in India in 2026

Real price bands for brochure sites, CMS builds, e-commerce and custom applications in India — plus the running costs most quotes leave out, and why two quotes for the same brief can differ by five times.

Read article
Mobile app development cost in India in 2026

Most founders get their first app quote and cannot tell whether it is reasonable. The range is genuinely enormous, and unlike a website, there is very little you can compare it against. This page sets out the three bands app projects actually fall into, what moves a project between them, and the one budgeting mistake that costs more than any negotiation will save you.

Keep reading
IT Strategy

Aug 20, 2026 4 min read

Mobile app development cost in India in 2026

What an app actually costs to build in India — the three complexity bands, developer rates, the platform decision that changes the number most, and the maintenance budget nine out of ten proposals leave out.

Read article
ERP implementation cost in India in 2026

Most ERP budget conversations go wrong in the first meeting, because everyone compares licence prices. On the major platforms, implementation is typically sixty to seventy per cent of the first year's budget. Comparing licences is therefore comparing the smaller third of the cost, and the platform that looks cheapest on that basis is frequently not.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

ERP implementation cost in India in 2026

Three-year totals for SAP, Odoo and Zoho at 100 users, why implementation is 60 to 70 per cent of the first budget, and the single decision that causes most ERP failures.

Read article
ISO 27001 certification cost in India in 2026

ISO 27001 is the certification European, APAC and Middle Eastern buyers ask for, and Indian companies routinely delay it because nobody will give them a number. Published Indian pricing for 2026 puts a typical startup or mid-market company of ten to a hundred employees at ₹2–4 lakh for year one — considerably less than most people assume, and less than the equivalent SOC 2 exercise.

Keep reading
Security

Aug 20, 2026 3 min read

ISO 27001 certification cost in India in 2026

Year-one and three-year costs by company size, why quotes vary so wildly, the internal time nobody budgets for, and the commercial case that makes the whole thing straightforward.

Read article
E-commerce website cost in India in 2026

An e-commerce build costs between ₹50,000 and ₹2.5 lakh in India, most commonly WooCommerce with a payment gateway. That range is wide because four things move it, and because the build price is only part of what an online store costs you.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

E-commerce website cost in India in 2026

What an online store costs to build and to run in India — the Shopify versus WooCommerce arithmetic over three years, the India-specific compliance costs generic quotes miss, and the features to leave out of version one.

Read article
IT AMC cost in India: why nobody will quote you a price

Search for IT annual maintenance contract pricing in India and you will find almost nothing specific. Vendors explain that it depends on location, equipment age and service level — which is true, and also conveniently keeps you without a benchmark when the negotiation starts.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

IT AMC cost in India: why nobody will quote you a price

AMC rates are almost never published in India. Here is how to build your own benchmark, the contract terms that decide what the price actually means, and the distinction most buyers get wrong.

Read article
How long does software development take?

Timeline questions get vague answers because the honest answer depends on things the supplier cannot see yet. Here are the realistic ranges, and — more usefully — the three variables that actually decide where within them you land.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

How long does software development take?

Realistic timelines for apps, websites, e-commerce and ERP — plus the three things that move a schedule more than engineering does, two of which are on your side of the table.

Read article
CRM implementation cost in India in 2026

CRM is quoted per user per month, which makes it look simple and hides where the money goes. The licence is frequently the smaller half of year one, and the number a finance director should be approving is four times larger than the one on the vendor's pricing page.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

CRM implementation cost in India in 2026

Licence prices, implementation bands, migration and integration costs — and the three-year total for a fifteen-user SME, which comes to roughly four times the licence fee alone.

Read article
AI chatbot development cost in India in 2026

Chatbot quotes are unusual in one respect: the build cost is often the smaller number. A rule-based bot costs a fraction of an LLM bot to build and almost nothing to run. An LLM bot costs more to build and then charges you for every conversation, forever. Choosing on build price alone is how businesses end up with an annual bill larger than the project.

Keep reading
Data & AI

Aug 20, 2026 3 min read

AI chatbot development cost in India in 2026

Build costs for rule-based, NLP and LLM chatbots in India — plus the monthly running cost that decides which one you should actually pick, and how to cut it by 60 to 80 per cent.

Read article
Website maintenance cost in India in 2026

Website maintenance is the line most businesses skip and most regret. It is also the line where you are least able to tell whether you are getting anything, because a well-maintained site and a neglected one look identical right up until the moment they do not.

Keep reading
IT Strategy

Aug 20, 2026 3 min read

Website maintenance cost in India in 2026

What maintenance costs monthly and annually in India, what a real contract includes, what is billed on top, and how to tell whether you are paying for work or for availability.

Read article
You cannot protect data you have not classified

Security programmes usually start with tools. A DLP product, an encryption policy, an access review. Each of them asks the same question in its configuration screen: which data is sensitive? And that is where the programme stalls, because nobody has answered it.

Keep reading
Security

Aug 20, 2026 1 min read

You cannot protect data you have not classified

Every security control assumes you know which data matters. Most organisations do not, and that is why the controls end up applied evenly to everything or to nothing.

Read article
Privileged access management when you do not have a security team

Most breaches escalate the same way. An attacker gets ordinary access, finds a credential with more privilege, and uses it. The controls that stop this are unglamorous and mostly free.

Keep reading
Security

Aug 20, 2026 1 min read

Privileged access management when you do not have a security team

Administrator credentials are the shortest path from a phishing email to a full breach. Controlling them does not require an enterprise product.

Read article
Object storage costs: what tiering actually saves

Object storage is priced to look inexpensive. A few paise per gigabyte per month invites a culture of keeping everything. Several years in, the bucket holds every log file, every image variant, every database export ever taken, and the line item is no longer small.

Keep reading
Cloud

Aug 20, 2026 1 min read

Object storage costs: what tiering actually saves

Storage looks cheap per gigabyte, which is why it quietly becomes one of the largest lines on a cloud bill.

Read article
Storing time-series data without your database falling over

Time-series data has a particular profile: writes are constant and append-only, reads are almost always over a time range, and old data is queried less as it ages. A relational database will accept this workload happily for a while and then become the bottleneck.

Keep reading
Engineering

Aug 20, 2026 2 min read

Storing time-series data without your database falling over

Sensor readings, metrics and event counts share a shape that general-purpose databases handle badly once the volume arrives.

Read article
Building location features for Indian addresses and delivery zones

Location features fail in India for a reason that has nothing to do with the mapping library. Addresses here are frequently descriptive rather than structured — a landmark, a lane, a building name that the postal system recognises and no geocoder does. A pin dropped by the user is often more reliable than the text they typed.

Keep reading
Engineering

Aug 20, 2026 1 min read

Building location features for Indian addresses and delivery zones

Maps, geofences and serviceability checks look simple until they meet Indian addressing.

Read article
Do you need a customer data platform, or four tools talking to each other?

A customer data platform promises to collect behavioural and transactional data from every channel, resolve it to individual people, and make those profiles available to marketing and support tools. When it works, it is genuinely useful. It also costs a great deal and depends entirely on data you may not have in usable shape.

Keep reading
Data

Aug 20, 2026 1 min read

Do you need a customer data platform, or four tools talking to each other?

The pitch is a single view of the customer. The reality is usually a expensive integration project with a dashboard on top.

Read article
Operationalising consent under the DPDP framework

India's Digital Personal Data Protection framework treats consent as the primary basis for processing personal data, with limited exceptions. That single sentence has architectural consequences most teams underestimate, because consent is not a checkbox — it is a state that changes over time and must be provable.

Keep reading
Compliance

Aug 20, 2026 1 min read

Operationalising consent under the DPDP framework

Writing a consent notice is the easy part. Recording, honouring and withdrawing consent is a system, not a page.

Read article
Carbon reporting is arriving in IT procurement

Sustainability reporting has moved from voluntary to structured for large listed Indian companies through SEBI's Business Responsibility and Sustainability Reporting requirements. Those companies increasingly push the question down their supply chain, and software vendors are part of that chain.

Keep reading
Business

Aug 20, 2026 1 min read

Carbon reporting is arriving in IT procurement

Enterprise buyers and European customers are starting to ask about emissions in vendor questionnaires. Most Indian IT firms have no answer prepared.

Read article
Sharding a database: the last resort, and how to delay it

Sharding means splitting rows across multiple database servers so no single machine holds everything. It works, and it is close to irreversible. Every subsequent feature has to respect the shard boundary, and any query spanning shards becomes an application-level join.

Keep reading
Engineering

Aug 20, 2026 1 min read

Sharding a database: the last resort, and how to delay it

Splitting data across servers solves a scaling problem and creates a permanent complexity problem. Exhaust the alternatives first.

Read article
Migrating between Google Workspace and Microsoft 365

Both vendors provide migration tooling that moves mail, calendars and contacts competently. If email were the whole job, this would be a weekend. It is not, and the parts that hurt are the parts nobody inventories before starting.

Keep reading
IT Services

Aug 20, 2026 1 min read

Migrating between Google Workspace and Microsoft 365

The mailboxes move fine. It is the shared drives, the permissions and the things people built in the old system that cause the pain.

Read article
Choosing an identity provider you will not want to leave

An identity provider authenticates users and tells your applications who they are. Once several applications depend on it, replacing it means reconfiguring every one, migrating credentials that in many cases cannot be exported, and asking users to re-enrol their second factors. Choose accordingly.

Keep reading
Security

Aug 20, 2026 1 min read

Choosing an identity provider you will not want to leave

Identity sits under every application you own. Changing it later touches all of them, so the selection deserves more thought than it usually gets.

Read article
Managed detection or your own security monitoring?

Detecting an intrusion requires someone looking at alerts at three in the morning. Covering every hour of every week with reasonable handover and leave cover takes a team, not a person, and that team needs to be busy enough to stay sharp. Below a certain size, building this in house produces an expensive rota that is bored most of the time and inexperienced when it matters.

Keep reading
Security

Aug 20, 2026 2 min read

Managed detection or your own security monitoring?

Twenty-four hour security monitoring needs at least five people to staff properly. Most mid-sized firms cannot justify that, which is what the managed market exists for.

Read article
Choosing a warehouse management system in India

Warehouse management demos are all impressive. The system that fails is rarely the one with fewer features — it is the one that assumed conditions your warehouse does not have.

Keep reading
Business

Aug 20, 2026 1 min read

Choosing a warehouse management system in India

Warehouse software fails on the floor, not in the demo. The questions that predict success are about scanning, connectivity and returns.

Read article
Data catalogues and lineage: knowing where a number came from

Every organisation with more than a few data pipelines reaches the same moment: two reports show different revenue figures, and resolving it takes days of tracing transformations backwards through jobs nobody has looked at in a year.

Keep reading
Data

Aug 20, 2026 1 min read

Data catalogues and lineage: knowing where a number came from

When two dashboards disagree, the argument is never about the dashboards. It is about which pipeline produced which number, and nobody can say.

Read article
Feature stores: solving a problem you may not have yet

A feature store holds the computed inputs to machine learning models and serves them consistently to both training and inference. The problem it addresses is genuine: a feature calculated one way in a training notebook and another way in production code produces a model that performs worse in the real world than in evaluation, and the cause is extremely difficult to find.

Keep reading
AI

Aug 20, 2026 2 min read

Feature stores: solving a problem you may not have yet

The training-serving skew problem is real. Buying a feature store before you have felt it is usually premature.

Read article
MLOps for teams without a platform group

The gap between a model that works in a notebook and one that runs reliably in production is mostly engineering, and most of that engineering is unremarkable — versioning, reproducibility, deployment, monitoring. The industry's tooling is built for scale that few teams have.

Keep reading
AI

Aug 20, 2026 1 min read

MLOps for teams without a platform group

Most MLOps advice is written for organisations with a dedicated platform team. Here is the version for the team that has three engineers and a model in production.

Read article
Designing billing systems that survive a tax rate change

GST rates and classifications change. When they do, every billing system in the country has the same week: finding where the rate lives, changing it, and discovering what broke.

Keep reading
Engineering

Aug 20, 2026 2 min read

Designing billing systems that survive a tax rate change

Rates change, slabs get reclassified, and invoices raised last quarter must keep their old numbers. Hard-coded rates make this a crisis instead of a configuration change.

Read article
Barcode and label printing: the unglamorous part of retail software

Label printing defeats more retail and warehouse projects than any algorithm. The reason is that the web platform was not designed for it, and the workarounds each have a cost.

Keep reading
Engineering

Aug 20, 2026 1 min read

Barcode and label printing: the unglamorous part of retail software

Printing a label seems trivial until the browser, the driver and the printer disagree about margins and every label comes out shifted.

Read article
React Native, Flutter or native: choosing without regret

The technical differences between the options are smaller than the discussions suggest. All three ship credible applications. The decision that actually matters is which team you can hire and keep, and what your roadmap demands of the platform.

Keep reading
Engineering

Aug 20, 2026 2 min read

React Native, Flutter or native: choosing without regret

The cross-platform question is really a hiring question and a roadmap question wearing engineering clothes.

Read article
Choosing a BI tool your team will actually open

Business intelligence tools are evaluated on features and abandoned for other reasons. Six months after launch, the dashboards nobody opens outnumber the ones that changed a decision, and the licence renewal becomes an awkward conversation.

Keep reading
Data

Aug 20, 2026 1 min read

Choosing a BI tool your team will actually open

Most BI projects fail on adoption, not capability. The tool that gets used beats the tool that scored highest on the evaluation matrix.

Read article
Email archiving and legal hold: what happens when a dispute starts

Email is where the record of a commercial relationship actually lives. When a contract dispute, an employment claim or a regulatory question arises, the correspondence is the evidence, and the ability to produce it — or the failure to — shapes the outcome.

Keep reading
Compliance

Aug 20, 2026 2 min read

Email archiving and legal hold: what happens when a dispute starts

The day a dispute begins is the day deletion has to stop. Most organisations discover they cannot do that selectively.

Read article
Change Advisory Boards: making them fast instead of theatre

The Change Advisory Board exists to catch the change that would cause an outage before it happens, and in most organisations it has drifted into something else: a weekly meeting where a long list of changes is read out, nobody has read the details in advance, and everything is approved because objecting to something you haven't reviewed feels presumptuous. The board exists, the meeting happens, and it prevents almost nothing.

Keep reading
IT Strategy

Aug 19, 2026 2 min read

Change Advisory Boards: making them fast instead of theatre

A weekly CAB meeting that rubber-stamps forty changes in an hour isn't governance, it's a delay with a meeting attached. Here's what a CAB should actually be doing…

Read article
Freshservice vs ServiceNow vs Jira Service Management for Indian mid-market

ServiceNow is the platform enterprises buy, and it is genuinely capable of modelling almost any process an organisation could want — which is exactly the problem for a mid-market buyer. The implementation effort and licensing cost are built around large, complex estates with dedicated administrators, and a fifty-person company adopting it is usually paying for capability it will never configure, let alone use.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Freshservice vs ServiceNow vs Jira Service Management for Indian mid-market

The three tools solve overlapping problems at very different price points and very different implementation efforts. Choosing by feature list alone is how a fifty-person company ends up paying for ServiceNow…

Read article
IT asset management: tracking what you actually own

IT asset management sounds like inventory and is really about accountability. A spreadsheet listing every laptop, monitor and phone is not an asset register if nobody updates it when a device is issued, returned, or lost — it's a snapshot of the day it was created, and every day after that it grows less accurate.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

IT asset management: tracking what you actually own

Most companies discover their asset register is fiction when a laptop goes missing and nobody can say who had it last. Building a register that stays true is simpler than the software vendors suggest…

Read article
Service catalogs people can actually find things in

A service catalog exists to let someone request what they need without knowing which team owns it or what the internal process is called. Most catalogs fail this test because they're organised by department — IT, HR, Facilities — which requires the requester to already know who handles their problem, which is exactly the knowledge the catalog was supposed to remove the need for.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Service catalogs people can actually find things in

A service catalog with ninety options, organised by department rather than by what someone is trying to do, gets abandoned for email within a month. The fix is writing for the requester, not the org chart…

Read article
Ticket prioritization: a matrix that survives contact with reality

The standard priority matrix — impact against urgency, producing a P1 through P4 — looks rigorous and gets overridden constantly in practice, because it doesn't account for the thing that actually determines how a ticket gets treated: who raised it and how loudly. A P3 ticket from a senior executive routinely jumps the queue ahead of a P2 from someone junior, and pretending the matrix is what's driving prioritization is dishonest to everyone using it.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Ticket prioritization: a matrix that survives contact with reality

Every helpdesk has a priority matrix on paper and a different one in practice, because the paper version doesn't account for who's asking. Here's a version that does…

Read article
First-contact resolution: the metric that actually predicts helpdesk quality

Average handle time is the metric most helpdesks track and the one most easily gamed, because an agent under pressure to keep it low learns to close tickets fast rather than resolve them properly, and the same problem returns as a second ticket a week later. The metric improves while the actual experience of being supported gets worse.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

First-contact resolution: the metric that actually predicts helpdesk quality

Average handle time gets watched and gamed. First-contact resolution is harder to fake and correlates much more closely with whether users are actually happy with support…

Read article
Shadow IT: finding the tools nobody approved

Shadow IT exists because the approved path for adopting a new tool is slower than a team's need for it. A marketing team wanting a design tool this week will not wait six weeks for procurement to review it — they'll sign up with a company card, and by the time IT finds out, customer assets and possibly customer data are already inside a tool nobody vetted for security or data residency.

Keep reading
Security

Aug 19, 2026 1 min read

Shadow IT: finding the tools nobody approved

By the time IT hears about a tool, three teams have been using it for a year and company data is already inside it. Finding shadow IT before it becomes a security incident is cheaper than cleaning up after one…

Read article
Knowledge-centered service: writing solutions once

Most helpdesks treat documentation as a task someone will do later, separately from actually resolving tickets, which means it competes with ticket volume for attention and reliably loses. The result is the same category of issue solved from scratch repeatedly by different agents, each one unaware that a colleague solved the identical problem last month.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Knowledge-centered service: writing solutions once

The same issue gets solved from scratch by three different agents in the same week because nobody wrote it down the first time. KCS makes documenting the fix part of fixing it, not a separate task…

Read article
Problem management: finding root cause instead of firefighting repeat incidents

Incident management and problem management solve different questions and get conflated constantly. Incident management asks how do we restore service right now, and closes the ticket the moment the symptom is gone. Problem management asks why does this keep happening, and it's a question that has no place inside an active incident because answering it properly takes longer than the business can tolerate being down.

Keep reading
IT Strategy

Aug 19, 2026 2 min read

Problem management: finding root cause instead of firefighting repeat incidents

The same server restarts every Friday and IT keeps restarting it, because incident management closes the ticket the moment service is restored. Problem management asks the question nobody has time for during the incident…

Read article
Major incident management: running the war room properly

The instinct during a serious outage is to pull in everyone who might be able to help, and beyond a certain point that instinct actively slows recovery. A call with fifteen people, all capable engineers, produces cross-talk, duplicated investigation, and a fix that's harder to coordinate — not because any individual is unhelpful, but because coordination overhead grows faster than the value each additional person adds.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Major incident management: running the war room properly

A major outage brings fifteen people into a call, all trying to help, and the fifteenth person joining is what actually slows the fix down. Running a war room well is a discipline separate from fixing the problem…

Read article
IT service continuity management vs disaster recovery — the difference

The two terms get used interchangeably and they answer genuinely different questions. Disaster recovery is a technical capability: can this system be restored, and how quickly. IT service continuity management is broader and organisational: if a major disruption happens, can the business keep functioning, and what does that require beyond restoring servers — alternate work locations, manual fallback processes, communication to customers, and a clear decision on which systems must come back first.

Keep reading
Cloud

Aug 19, 2026 1 min read

IT service continuity management vs disaster recovery — the difference

Disaster recovery gets your systems back. IT service continuity management gets the business back — and the second one requires knowing things the IT team alone cannot answer…

Read article
Self-service portals that actually reduce ticket volume

A self-service portal is sold internally on the promise of reduced ticket volume, and most fail to deliver it because they're built around what IT wants to offer rather than what users are actually asking for. Look at your ticket history before building anything — the top ten or fifteen request types by volume are the ones that need a genuinely good self-service path, and everything else can wait.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Self-service portals that actually reduce ticket volume

Most self-service portals get built, launched, and quietly abandoned by users within a month, because they were designed to look comprehensive rather than to actually solve the top requests…

Read article
AIOps: where AI genuinely helps IT operations

AIOps vendors pitch autonomous remediation — infrastructure that heals itself without a human in the loop — and for most organisations that's not where the near-term value actually is. What AI genuinely does well in IT operations today is correlation and noise reduction: taking the hundreds of alerts a busy infrastructure estate generates and identifying which handful are actually related to one underlying event, rather than autonomously fixing anything.

Keep reading
AI

Aug 19, 2026 1 min read

AIOps: where AI genuinely helps IT operations

AIOps gets pitched as autonomous infrastructure management. What it's actually good at, today, is noise reduction — and treating it as anything more sets up a disappointing rollout…

Read article
Release management: coordinating deployments across multiple teams

Modern engineering practice favours teams deploying independently and frequently, and that's correct for most changes — the CI/CD guidance elsewhere on this site makes the case for it clearly. Release management as a discipline exists for the smaller category of changes where independence stops being enough: when two teams' changes touch the same system in the same window, or when a change is significant enough that the business needs advance notice regardless of how well-tested it is.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Release management: coordinating deployments across multiple teams

Four teams deploying independently, on their own schedules, is fine until two of their changes interact badly on the same afternoon and nobody connects the two until customers are already affected…

Read article
Request fulfilment: automating the approvals nobody reads

Approval workflows exist to add a human decision point where one is genuinely needed, and in practice most organisations route far more requests through them than that. A manager facing forty routine access requests a week for tools their team already uses is not making forty considered decisions — they're clicking approve as fast as possible because being the reason a colleague can't do their job for three days is worse than the theoretical risk of an ungranted access request slipping through.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

Request fulfilment: automating the approvals nobody reads

A manager approving forty software access requests a week isn't reviewing them, they're clicking approve because the alternative is being the bottleneck. Automating the ones that don't need judgement is where the time actually goes…

Read article
IT chargeback and showback: making departments see their IT cost

When IT cost sits in one central budget line with no visibility into which department is driving it, every department behaves rationally by requesting more IT resource than they would if they actually saw the price attached — because from their perspective it's free. Chargeback and showback are the two mechanisms for fixing that, and they differ in one important way: chargeback actually bills the department for what they consume, showback simply reports it without moving money.

Keep reading
IT Strategy

Aug 19, 2026 1 min read

IT chargeback and showback: making departments see their IT cost

IT is treated as a free, unlimited resource by every department that doesn't see the bill, and that's exactly why every department asks for more of it than they'd request if the cost were visible…

Read article
Availability management: defining uptime targets that mean something

A stated uptime target like 99.9% sounds precise and rigorous, and most people quoting it haven't actually calculated what it permits: roughly 43 minutes of downtime per month, or about 8.7 hours a year. Whether that's an acceptable target depends entirely on the system it applies to and when the downtime occurs, and a single blanket target across every system in an organisation is almost always wrong for most of them.

Keep reading
IT Strategy

Aug 19, 2026 2 min read

Availability management: defining uptime targets that mean something

'99.9% uptime' sounds like a strong commitment until you calculate what it actually permits — over forty minutes of downtime a month, which may or may not be acceptable depending on when it happens…

Read article
Choosing between GPT, Claude, Gemini and open-source models for a specific task

Public leaderboards rank models on broad benchmarks that rarely resemble what a specific product actually needs the model to do. A model ranking highly on general reasoning benchmarks can underperform a lower-ranked model on your specific task — structured extraction from a particular document format, say, or a narrow classification job — because leaderboard rankings average across a wide spread of tasks, and your task may sit far from that average.

Keep reading
AI

Aug 19, 2026 2 min read

Choosing between GPT, Claude, Gemini and open-source models for a specific task

Model comparison threads online argue about which is 'best' as if that's a single answer. For a specific production task, the right model is rarely the one topping a general leaderboard…

Read article
Multimodal AI: when combining text, image and voice actually helps

A multimodal model that accepts text, images and sometimes audio in a single request is genuinely useful when the task actually requires combining information across those modes — reading a scanned invoice where the layout and the text both carry meaning, or answering a question about what's visible in a photograph. It's a poor fit when a product simply has an image somewhere in its workflow and the team defaults to sending it to the model because the capability exists, when a much cheaper text-only or vision-specific pipeline would do the job.

Keep reading
AI

Aug 19, 2026 2 min read

Multimodal AI: when combining text, image and voice actually helps

Multimodal is a genuine capability and also a feature checkbox teams reach for because it sounds advanced, on products where the extra modality adds cost and complexity without adding value…

Read article
Synthetic data for training: when it helps and when it quietly breaks a model

Synthetic data — generating training examples rather than collecting them from real usage — is genuinely valuable where real data is scarce, sensitive, or expensive to label: rare edge cases that barely occur naturally, or scenarios where using real customer data for training raises privacy concerns the synthetic version sidesteps entirely. Used deliberately for these gaps, it's a real technique with real value.

Keep reading
AI

Aug 19, 2026 2 min read

Synthetic data for training: when it helps and when it quietly breaks a model

Generating training data to fill gaps a real dataset can't cover is a legitimate technique, and it's also how teams quietly train a model to be excellent at recognising its own generator's patterns rather than reality…

Read article
Red-teaming your own AI system before someone else does

Red-teaming an AI system means deliberately trying to make it behave badly, before shipping, rather than discovering the failure modes from real users after launch. It's broader than the prompt injection testing covered elsewhere on this site — that's one specific attack category. Red-teaming also probes for the system producing harmful, biased, or simply embarrassing outputs under adversarial or unusual input, and for the system being manipulated into behaviour outside its intended scope through means that have nothing to do with hidden instructions in content.

Keep reading
AI

Aug 19, 2026 2 min read

Red-teaming your own AI system before someone else does

Prompt injection testing checks whether a system follows malicious instructions hidden in content. Red-teaming is broader — actively trying to make the system fail in every way a motivated user might attempt…

Read article
How long you must keep records: the Indian retention landscape

Retention periods in India are not set by a single statute. Company records, tax records, GST records, employment records and sector-specific records each have their own requirement, and the periods do not align. A software system with one global retention setting will inevitably be wrong for some category of data.

Keep reading
Compliance

Aug 19, 2026 2 min read

How long you must keep records: the Indian retention landscape

Different laws set different clocks on the same document. Systems that apply one retention rule to everything satisfy none of them.

Read article
Delivering video to Indian audiences without burning bandwidth

Adding video to a product looks like a storage problem and is actually a delivery problem. A single high-resolution file served to everyone will buffer on the connections a large share of Indian users have, and will consume data that many of them are counting.

Keep reading
Engineering

Aug 19, 2026 1 min read

Delivering video to Indian audiences without burning bandwidth

Video is the largest thing most applications ship. In a market with variable connectivity and data cost sensitivity, how you encode it decides whether it gets watched.

Read article
Patch management for a Windows fleet you didn't design

Inheriting an unmanaged Windows fleet is common in Indian mid-market companies that grew faster than their IT function did — laptops purchased at different times, imaged inconsistently or not at all, and patched whenever an individual user happened to click 'update now'. The instinct is to push a mandatory update to everything at once, and that instinct is what causes an outage rather than fixing one.

Keep reading
Security

Aug 18, 2026 1 min read

Patch management for a Windows fleet you didn't design

You inherited two hundred laptops with inconsistent builds, and half of them haven't been patched properly in a year. Here's how to get from that to a working patch cycle without an outage…

Read article
Remote monitoring and management tools for running an MSP practice

A managed service provider's entire business model depends on servicing many clients' infrastructure with a small team, and that only works with a remote monitoring and management platform doing the watching that a human otherwise would. Without one, 'managed' means someone remembers to check periodically, which does not scale past a handful of clients and does not catch problems before a client notices them.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Remote monitoring and management tools for running an MSP practice

An MSP managing client infrastructure without an RMM platform is running on hope. Choosing one is less about features and more about how many clients you can actually service per technician…

Read article
Progressive Web Apps for Indian retail: when they beat a native app

Indian retail brands routinely commission a native app because a competitor has one, without examining whether their actual usage pattern justifies it. A Progressive Web App — a website that can be added to a home screen, cached for offline use, and can send push notifications on Android — delivers most of what retail actually needs from an app at a fraction of the build and maintenance cost.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Progressive Web Apps for Indian retail: when they beat a native app

A native app costs several times what a PWA costs and gets deleted the moment storage runs low. For a lot of Indian retail, the web app was always the better answer…

Read article
Jamstack and static-first sites for content-heavy businesses

A content-heavy site — a blog, documentation, most marketing pages — doesn't need to query a database on every request, because the content changes rarely and is the same for every visitor. Building one on a full server-rendered framework with a live database connection is solving a problem the site doesn't have, and paying in server cost and attack surface for flexibility nobody uses.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Jamstack and static-first sites for content-heavy businesses

A blog, a documentation site, or a marketing site rebuilt on a database-backed framework because that's what the team knew is paying for dynamic infrastructure it never uses…

Read article
Headless CMS: choosing one for an Indian content team

A headless CMS stores and delivers content through an API rather than rendering pages itself, which lets the same content power a website, a mobile app and anything else through one editing interface. The appeal to engineering is real — no monolithic platform to maintain, no plugin ecosystem to patch — but the decision that actually determines whether it succeeds is whether the people writing content every day can use it comfortably.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Headless CMS: choosing one for an Indian content team

A headless CMS separates content from presentation, which sounds like a developer decision and is actually decided by whether your content team can use it without filing a ticket every time…

Read article
WebAssembly: where it earns its complexity

WebAssembly lets code written in languages like Rust, C++ or Go run in the browser at close to native speed, and the pitch — near-native performance on the web — makes it tempting to reach for on any project with a performance complaint. Most web applications' performance problems are not computational; they're network latency, unoptimised rendering, or too much JavaScript shipped to the client, none of which WebAssembly fixes.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

WebAssembly: where it earns its complexity

WebAssembly gets proposed for problems JavaScript already solves adequately, and adopted for the wrong reasons more often than the right ones. Here's where it's actually worth the build complexity…

Read article
Server-Sent Events vs WebSockets: picking the simpler one

WebSockets have become the default answer for 'we need real-time updates,' and they're genuinely the right tool when the client needs to send frequent messages back to the server — a chat application, a collaborative editor, a multiplayer game. A large share of real-time features don't actually need that: they need the server to push updates to the client, one direction only, which is a simpler problem with a simpler solution already built into every browser.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Server-Sent Events vs WebSockets: picking the simpler one

Teams reach for WebSockets by default for any real-time feature, and half the time a much simpler technology already built into every browser would have done the job…

Read article
Edge functions and Indian latency

Most Indian applications run their backend out of a single region — commonly Mumbai — which serves users near that region well and users in the northeast or far south with a round trip that's noticeably longer, even within the same country. Edge functions run code at points of presence distributed geographically, closer to wherever the request originates, cutting that round trip for the parts of the logic that can run there.

Keep reading
Cloud

Aug 18, 2026 2 min read

Edge functions and Indian latency

A backend in Mumbai serves a user in Kochi acceptably and a user in Guwahati noticeably slower. Edge functions move the computation closer to the user rather than moving the user's request further…

Read article
Dark mode done properly, not just inverted colours

The fastest way to ship dark mode is a CSS filter that inverts every colour on the page, and it produces a genuinely unpleasant result: images invert into unnatural colours, shadows that should recede now appear to glow, and a white card floating on a previously-white background becomes a dark card with none of the visual hierarchy the light version had. Users notice this immediately even if they can't articulate why the dark mode feels wrong.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

Dark mode done properly, not just inverted colours

Most dark mode implementations are a CSS filter that inverts everything, and the result is a product that's technically dark and genuinely unpleasant to look at. Doing it properly is a design exercise, not a toggle…

Read article
Browser extensions: building and distributing one

Building a browser extension is technically approachable — a manifest file, some scripts, a small interface — and the parts that actually determine whether it succeeds are the review process and the permissions it asks for, both of which are largely outside the developer's control once the extension is submitted. Chrome's Manifest V3 in particular restricted what extensions can do with background processes, and any extension design predating that shift needs re-architecting rather than a minor patch.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

Browser extensions: building and distributing one

A browser extension is a small, self-contained piece of software with an outsized review process and a permission model that will define whether anyone trusts it enough to install…

Read article
Endpoint detection and response for a small IT team

Traditional antivirus works by matching files against a known list of malicious signatures, which means it's structurally unable to catch anything genuinely new. Endpoint detection and response tools work differently — watching behaviour on the device and flagging patterns that look malicious regardless of whether the specific threat has been seen before, which catches a meaningfully wider category of attack.

Keep reading
Security

Aug 18, 2026 2 min read

Endpoint detection and response for a small IT team

Antivirus catches known threats. EDR is built to catch the ones nobody's seen before — and for a small team, the deciding factor is whether anyone has time to actually respond to what it finds…

Read article
Mobile device management: BYOD in an Indian office

Bring-your-own-device is the reality in most Indian companies whether or not it was ever decided deliberately — an employee simply adds their work email to their personal phone, and from that moment, company data lives on a device IT has no control over, no visibility into, and no ability to wipe if the phone is lost or the employee leaves under difficult circumstances.

Keep reading
Security

Aug 18, 2026 1 min read

Mobile device management: BYOD in an Indian office

Employees using their own phones for work email is the default in most Indian companies, and it's rarely a deliberate policy decision so much as something nobody ever formalised…

Read article
VPN and remote access design after hybrid work became permanent

A traditional VPN was designed on the assumption that most employees work from the office and occasionally connect remotely — a small, predictable slice of traffic. Hybrid work inverted that assumption without most companies redesigning the infrastructure to match, and the result is a VPN concentrator sized for occasional use now carrying most of the company's daily traffic, which is why it's slow and why it's become a single point of failure that didn't matter as much when it was lightly used.

Keep reading
Security

Aug 18, 2026 2 min read

VPN and remote access design after hybrid work became permanent

The VPN most companies still run was designed for the occasional remote worker, not for half the company connecting through it every day. That design mismatch is where the slowness and the risk both come from…

Read article
Wi-Fi and LAN design for a growing office

Office Wi-Fi complaints almost always get diagnosed as a signal strength problem — 'we need a stronger router' — and the actual cause at growing headcount is usually device density rather than signal. A single access point can serve a signal strong enough to show full bars across an entire floor while genuinely struggling once forty or fifty devices are simultaneously trying to use it, because the access point's actual constraint is how many concurrent connections it can serve well, not how far its signal reaches.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Wi-Fi and LAN design for a growing office

The Wi-Fi that worked fine for thirty people falls over at ninety, and the failure isn't about signal strength, it's about how many devices one access point can actually serve well…

Read article
Backup software selection: what actually restores

Backup software is chosen almost entirely on how easy backing up looks in a demo, because that's the part vendors show. The feature that actually matters — restoration — is rarely demonstrated with the same enthusiasm, because restoration is where the genuine complexity and the genuine differentiation between products lives, and it's harder to make look impressive in a fifteen-minute sales call.

Keep reading
Cloud

Aug 18, 2026 2 min read

Backup software selection: what actually restores

Every backup product's marketing page emphasises how easy it is to back up. The question that actually matters — how easy and how fast is it to restore — is the one to test before buying, not after you need it…

Read article
Micro-frontends: when splitting the frontend is worth it

Micro-frontends split a single web application into independently deployable pieces, each owned and shipped by a different team, composed together at runtime into what the user experiences as one product. The pitch is compelling on paper — teams ship independently, on their own schedules, without coordinating a single monolithic frontend release — and it solves a genuinely real problem for organisations with several substantial teams working on one large product.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

Micro-frontends: when splitting the frontend is worth it

Micro-frontends solve a team coordination problem, not a technical one, and adopting them for technical reasons alone usually produces more complexity than the single frontend they replaced…

Read article
CSS architecture: utility-first vs component-scoped styles

Utility-first CSS — applying many small, single-purpose classes directly in markup, as Tailwind popularised — lets a developer build a screen quickly without leaving the markup to write separate stylesheet rules, and once a team is fluent in the utility vocabulary, that speed advantage is real and consistent. The trade is that the markup itself becomes visually dense, and design intent lives implicitly in a long string of utility classes rather than in a named, readable component style.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

CSS architecture: utility-first vs component-scoped styles

The utility-first versus component-scoped argument gets fought as a matter of taste, and it's actually a trade between how fast you can build a screen and how easy that screen is to change six months later…

Read article
Progressive enhancement: building for the browser that fails

Modern frontend development defaults to building the entire experience in JavaScript, which works well for the visitor whose connection is stable and whose script loads cleanly, and fails completely for the visitor whose doesn't — a poor mobile connection dropping mid-load, an aggressive corporate firewall stripping scripts, an ad blocker or privacy extension interfering more broadly than intended. For that visitor, a JavaScript-dependent site isn't degraded, it's blank.

Keep reading
IT Strategy

Aug 18, 2026 1 min read

Progressive enhancement: building for the browser that fails

JavaScript fails to load for a meaningful share of real visitors — a flaky connection, an ad blocker, a corporate network — and most modern sites simply show nothing when it does…

Read article
Accessibility testing automation: catching issues before a human review

Automated accessibility testing tools reliably catch a genuine but limited subset of accessibility issues — missing alt text, insufficient colour contrast, form inputs without labels, malformed heading hierarchy. Published figures generally put this at somewhere around a third of real-world issues, which sounds like a modest number until you consider what it actually buys: catching that third continuously, on every pull request, for close to no ongoing cost, rather than catching it once a year during an expensive manual audit.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

Accessibility testing automation: catching issues before a human review

Automated accessibility scanners catch roughly a third of real issues, which sounds unimpressive until you realise that third is cheap to fix continuously rather than expensive to fix once a year…

Read article
Font loading strategy: the invisible performance cost

Custom web fonts are a small file that most teams add without considering the loading behaviour they introduce by default. Left at browser defaults, text using a custom font is often invisible entirely until the font file finishes downloading — a behaviour called the flash of invisible text — which on a slow connection means a visitor stares at a blank area where text should be for a genuinely noticeable delay, even though the content itself was ready instantly.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

Font loading strategy: the invisible performance cost

A custom web font makes a site look more polished and, done carelessly, makes text invisible for a full second while the font downloads — a trade most teams never notice they made…

Read article
CLI tool design: building a command-line tool developers actually adopt

A command-line tool built to automate an internal task gets used enthusiastically by the person who wrote it and largely ignored by everyone else on the team, and the reason is rarely that the underlying automation is wrong — it's that CLI usability has its own discipline, distinct from application development, and it's usually skipped when the tool was built quickly to solve one person's immediate problem.

Keep reading
IT Strategy

Aug 18, 2026 2 min read

CLI tool design: building a command-line tool developers actually adopt

Most internal CLI tools get built once, used by their author, and ignored by everyone else — not because the tool is bad, but because command-line interface design has its own discipline that gets skipped…

Read article
Vector databases: choosing one and what changes as you scale

For most teams building their first retrieval-augmented feature, pgvector — a vector extension on a Postgres database you likely already run — is the pragmatic starting point rather than a dedicated vector database. It avoids adding a new system to operate, keeps vector search alongside your existing relational data so queries can combine both naturally, and is genuinely adequate for embedding volumes many teams never actually exceed.

Keep reading
AI

Aug 18, 2026 2 min read

Vector databases: choosing one and what changes as you scale

pgvector on Postgres is the right answer for most teams starting out, and it stops being the right answer at a scale most teams reach later than they expect and earlier than they're prepared for…

Read article
AI-assisted code review: what it catches and what it misses

AI code review tools, run automatically on every pull request, reliably catch a specific and genuinely useful category of issue: obvious bugs, inconsistent patterns against the rest of the codebase, missing error handling, and style inconsistencies — largely the same territory static analysis and linting already cover, but explained in plain language rather than a terse rule violation, which makes the feedback more actionable for whoever's reading it.

Keep reading
AI

Aug 18, 2026 2 min read

AI-assisted code review: what it catches and what it misses

An AI reviewer catches the class of issue a linter would eventually catch, phrased more helpfully. It doesn't catch the thing a senior engineer catches by knowing why the code exists…

Read article
Explainability: what "why did it do that" actually requires you to build

When an AI system makes or influences a consequential decision — a credit decline, a content moderation action, a flagged transaction — someone will eventually ask why, and 'the model determined this' is not an answer that satisfies a customer, a regulator, or often the person's own manager. Building the capability to answer that question properly is a design requirement that has to be planned before the system ships, not retrofitted once the first dispute arrives and there's nothing to point to.

Keep reading
AI

Aug 18, 2026 2 min read

Explainability: what "why did it do that" actually requires you to build

A customer disputes an AI-driven decision and asks why. If the honest answer is 'the model said so,' that's not an explanation, and building the ability to give a real one has to happen before the dispute, not during it…

Read article
The cost of AI hallucination: measuring business impact, not just accuracy

Accuracy percentages get reported as if they're the whole story, and the actual business cost of a wrong answer depends entirely on what happens next — a fact covered from the technical evaluation angle in the piece on evaluating an AI vendor's accuracy claims, and worth returning to specifically from the cost side, because the same accuracy figure can represent wildly different financial exposure depending on the use case.

Keep reading
AI

Aug 18, 2026 2 min read

The cost of AI hallucination: measuring business impact, not just accuracy

A ninety-five per cent accuracy figure sounds reassuring until you price what the other five per cent actually costs — and that cost varies by a hundredfold depending on what the wrong answer causes someone to do…

Read article
Why your Android notifications do not arrive on Indian phones

A notification system that works perfectly in testing and silently fails for a third of users is one of the more demoralising bugs to chase. The usual cause is not your code. It is manufacturer-level battery management deciding your app should not run.

Keep reading
Engineering

Aug 18, 2026 1 min read

Why your Android notifications do not arrive on Indian phones

Manufacturer battery optimisation kills background work aggressively, and the devices that do it most are the ones your users own.

Read article
App size is a conversion metric

Teams treat application size as an engineering hygiene issue. In markets where storage is limited and data costs money, it is a business metric. A user who taps install and watches a progress bar crawl has a decision point that a smaller app never gave them.

Keep reading
Engineering

Aug 18, 2026 1 min read

App size is a conversion metric

Every megabyte is a reason to abandon the install — on a metered connection, on a full phone, on a slow network.

Read article
Hosting government workloads: MeitY empanelment

If you build software for central or state government bodies or public sector undertakings, where it runs is a procurement question before it is an engineering one. The Ministry of Electronics and Information Technology operates an empanelment scheme, administered through the STQC directorate, that certifies which cloud providers may serve government customers. Most central and state cloud procurement defaults to empanelled providers, with narrow alternative paths for certain defence and intelligence workloads. Private sector buyers are free to use anyone.

Keep reading
Cloud

Aug 17, 2026 2 min read

Hosting government workloads: MeitY empanelment

Your provider being empanelled is not the same as the service you want being empanelled. That distinction has stopped more government projects than any technical problem.

Read article
IRDAI's cyber security rules and insurance software

The IRDAI issued its Information and Cyber Security Guidelines on 24 April 2023, and their scope is considerably wider than the word insurer suggests. They apply to regulated entities across the sector: insurers, brokers, foreign reinsurance businesses, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers, common service centres and the Insurance Information Bureau of India. If you build software for any of those, your client is inside the perimeter and your product is part of how they comply.

Keep reading
Security

Aug 17, 2026 2 min read

IRDAI's cyber security rules and insurance software

The guidelines reach web aggregators, marketing firms and third-party administrators — not just insurers. If you build for any of them, they reach your product.

Read article
Aadhaar eSign or DSC: signing documents in India

Any Indian product that needs a legally binding signature — a loan agreement, a rental contract, an insurance proposal, an employment offer — eventually faces the same choice between two mechanisms, both recognised under the IT Act's Second Schedule, that behave completely differently in a user journey. Getting the choice right is largely about who is signing and how often.

Keep reading
Security

Aug 17, 2026 2 min read

Aadhaar eSign or DSC: signing documents in India

One takes thirty seconds on a phone and the other takes weeks and a USB stick. They are both legally valid, and choosing wrongly kills your conversion rate.

Read article
Pricing SaaS for the Indian market

Founders selling software in India routinely take a price that works in the US, convert it, apply a discount, and conclude that Indian buyers are unwilling to pay for software. The conclusion is wrong and the method is the reason. Indian buyers pay for software; they buy it on a different structure, with different expectations about what is included, and a converted-and-discounted foreign price satisfies none of them.

Keep reading
Cloud

Aug 17, 2026 2 min read

Pricing SaaS for the Indian market

Taking a dollar price and converting it produces a number nobody here will pay. The fix is not a discount, it is a different pricing shape.

Read article
Why your enterprise pilot never converts

A large customer agrees to a pilot. Your team builds it, it works, the users are complimentary, the demonstration goes well — and then the conversation goes quiet and reappears six months later as a request for another pilot with a different department. This is the most common way enterprise deals fail, and it almost always traces back to what was agreed before the work started.

Keep reading
Cloud

Aug 17, 2026 2 min read

Why your enterprise pilot never converts

The pilot succeeded, everyone was pleased, and nothing was purchased. That outcome is designed in at the start, usually by agreeing to a pilot with no decision attached.

Read article
IT and security for a twenty-person company

A company of twenty people has usually arrived there without ever deciding how its technology should work. Accounts were created as needed, access was granted by whoever asked, laptops were bought individually, and the shared drive grew organically. Nothing is broken, so nothing gets attention — until the first security questionnaire from a customer, or the first departure that turns awkward.

Keep reading
Security

Aug 17, 2026 2 min read

IT and security for a twenty-person company

Nobody owns IT, everyone has admin rights, and the ex-employee still has access to the shared drive. Four decisions fix most of it.

Read article
Running a proof of concept that decides something

A proof of concept is commissioned to reduce uncertainty and usually reduces none, because it was scoped to demonstrate rather than to test. Someone builds a working example of the technology, everyone agrees it works, and the actual question — will this hold up in our environment, at our volume, against our data — remains exactly as open as it was. The difference between a useful proof of concept and a demonstration is that the useful one could fail.

Keep reading
Cloud

Aug 17, 2026 2 min read

Running a proof of concept that decides something

Most proofs of concept prove that the technology exists, which nobody doubted. A useful one is built to fail.

Read article
Building a partner channel that actually sells

Partner channels are attractive because they look like leverage: other companies selling your product to customers you could not reach. They frequently deliver nothing, and the failure is consistent enough to be predictable. A firm signs a run of partner agreements, celebrates the count, and discovers a year later that two partners produced everything and the rest produced a logo on a slide.

Keep reading
Cloud

Aug 17, 2026 2 min read

Building a partner channel that actually sells

Signing twenty partners feels like progress and usually produces nothing. Two who genuinely sell are worth more than all of them.

Read article
Building a team in India beyond Bengaluru

Bengaluru is the default answer for engineering in India and it is not always the right one. We are based here, so read this accordingly, but the honest position is that the city solves one specific problem — depth of senior people who have operated systems at scale — and charges a premium for it whether or not that is the problem you have.

Keep reading
Cloud

Aug 17, 2026 2 min read

Building a team in India beyond Bengaluru

We are in Bengaluru and we would still tell some companies to hire elsewhere. The deciding factor is what kind of scarcity you face.

Read article
When your key engineer resigns

The resignation you fear is the one from the person who understands the part of the system nobody else does. In India that arrives with a notice period — often thirty days, sometimes sixty or ninety — which is genuinely generous compared with many markets and is still less time than it feels like once you subtract handover of current work, leave they will take, and the disengagement that follows any resignation.

Keep reading
Cloud

Aug 17, 2026 2 min read

When your key engineer resigns

The notice period is the only window you get, and most of it is wasted on a handover document nobody can use afterwards.

Read article
Dark patterns: what Indian e-commerce may not do

In 2023 the Central Consumer Protection Authority notified Guidelines for the Prevention and Regulation of Dark Patterns, naming thirteen specific interface behaviours as prohibited. The list is worth reading as a product document rather than a legal one, because most of the items are things a growth team has been asked to build at some point: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised advertisements, nagging, trick question, SaaS billing, and rogue malware.

Keep reading
Security

Aug 17, 2026 2 min read

Dark patterns: what Indian e-commerce may not do

Thirteen interface patterns are now named in law as unfair trade practices. Several of them are things product teams were taught to build.

Read article
RBI's IT governance rules for banks and NBFCs

The Reserve Bank issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices on 7 November 2023. It is the framework that sits above the more specific rules on digital lending and payment data, and it governs how a regulated financial entity organises technology as a whole. For a software firm, it matters because it determines who at your client can approve what, and how much evidence they need from you.

Keep reading
Security

Aug 17, 2026 2 min read

RBI's IT governance rules for banks and NBFCs

This is the direction that puts a board committee on top of your technology decisions. If your client is a regulated lender, it shapes how they can work with you.

Read article
Accessibility law in India: RPwD and government sites

Indian product teams generally encounter accessibility for the first time in a foreign customer's procurement questionnaire, and conclude it is an export requirement. It is not only that. The Rights of Persons with Disabilities Act, 2016, administered by the Ministry of Social Justice and Empowerment, is a non-discrimination law that applies to both the public and private sectors, and its scope extends beyond web content to information and communication technology more broadly.

Keep reading
Cloud

Aug 17, 2026 2 min read

Accessibility law in India: RPwD and government sites

India has had a statutory accessibility obligation covering the private sector since 2016. Most product teams here have never been told about it.

Read article
When a stranger emails to say you have a bug

One day an email arrives from someone you have never heard of saying they found a security flaw in your product. What happens in the next few hours determines a great deal: whether you learn about your other flaws from researchers or from attackers, and whether this particular person works with you or writes it up publicly. Most companies handle this badly, and the worst version — responding with a legal threat — reliably converts a helpful stranger into a hostile one with an audience.

Keep reading
Security

Aug 17, 2026 2 min read

When a stranger emails to say you have a bug

How you answer that first email decides whether the finder helps you quietly or publishes it. Most companies answer badly, and some answer with a lawyer.

Read article
Telling customers you are down

Every system fails eventually, and customers know that. What they judge you on is not whether you had an incident but what it was like to be your customer during one. The companies people stay with are the ones where, within a few minutes, there was somewhere to look that said yes, this is us, we know, here is what we are doing. The companies people leave are the ones where support said everything looks fine on our end while nothing worked.

Keep reading
Cloud

Aug 17, 2026 2 min read

Telling customers you are down

During an outage, silence costs you more than the outage does. Customers forgive downtime and remember being left to guess.

Read article
Surviving the festive peak

Indian consumer businesses do not have a smooth annual curve. They have a handful of days — the festive sale window, a big cricket fixture, a payday, a campaign launch — where traffic is a multiple of normal and arrives in minutes rather than hours. That shape defeats the standard advice, because autoscaling responds to load that has already arrived, and by the time capacity appears the queue has built and the first thousand customers have seen an error page.

Keep reading
Cloud

Aug 17, 2026 2 min read

Surviving the festive peak

Indian traffic is not seasonal in the way autoscaling assumes. It is a wall arriving at a known minute, and autoscaling is too slow for a wall.

Read article
The vendors your vendors use

Ask any engineering team to list every third party that touches customer data and the first answer is usually three or four names. The real list is longer: the cloud provider, the error tracker, the analytics platform, the email service, the support desk, the session recording tool, the chat widget, the observability vendor, the payment gateway, the SMS provider, and whichever AI service somebody wired in last quarter. Every one of them is a subprocessor, and under the DPDP framework and any serious enterprise contract, their handling of the data is your accountability.

Keep reading
Security

Aug 17, 2026 2 min read

The vendors your vendors use

Your customer's data is sitting in nine companies they have never heard of. Under DPDP and every enterprise contract, that is your responsibility.

Read article
Moving between cloud providers

Moving from one cloud to another gets discussed as though it were the same exercise as migrating from a data centre, and it is not. The workloads are already containerised or virtualised, already defined in code, already operated by people who understand cloud. What makes it hard is different: the managed services you have built on do not have identical equivalents, the identity model is not portable, and the data has to physically move at a price the other provider sets and you do not.

Keep reading
Cloud

Aug 17, 2026 2 min read

Moving between cloud providers

This is a different project from moving off-premises to the cloud, and the thing that decides it is the egress bill nobody modelled.

Read article
A privacy policy that matches your product

Almost every Indian company's privacy policy was assembled from a template, and almost none of them accurately describe what the product does. They over-promise in some places and are silent in others, and both are problems now rather than merely untidy — under the DPDP framework, the notice you give is the basis on which you are permitted to process data, and a notice describing a different product does not authorise what you are actually doing.

Keep reading
Security

Aug 17, 2026 2 min read

A privacy policy that matches your product

Most Indian privacy policies were copied from a template and describe a product nobody built. Under DPDP that gap is the liability.

Read article
Security training people do not ignore

Security awareness training exists in most organisations as an annual compliance exercise: a slide deck, a multiple-choice quiz, a completion certificate for the auditor. It reliably produces a hundred per cent completion rate and no measurable change in behaviour, because a person who watched a video in April is not more suspicious of an email in September. The exercise satisfies the requirement and misses the point.

Keep reading
Security

Aug 17, 2026 2 min read

Security training people do not ignore

An annual slide deck with a quiz at the end changes nobody's behaviour. What works is shorter, more frequent and considerably less comfortable.

Read article
Building video KYC into a financial product

Video-based Customer Identification Process began as a pandemic accommodation and has become the standard remote onboarding route for Indian financial institutions. It is not a video call with a screenshot. The RBI has progressively tightened what a compliant session must contain, and the requirements shape the architecture far more than the video streaming does.

Keep reading
Security

Aug 17, 2026 2 min read

Building video KYC into a financial product

The video call is the easy part. Liveness, geotagging, an Indian IP check and a reviewer on your own payroll are what the regulator is actually looking for.

Read article
Bharat Bill Payment System: how it fits together

Bharat Bill Payment System is the interoperable rail for recurring bill payments in India — electricity, gas, water, telecom, insurance premiums, loan instalments and a widening list beyond. For a product team it is attractive because it turns hundreds of separate biller integrations into one connection. The RBI issued revised directions governing it with effect from 1 April 2024, and understanding the role structure is the first step in deciding how, or whether, to participate.

Keep reading
Cloud

Aug 17, 2026 2 min read

Bharat Bill Payment System: how it fits together

Two roles, one network, and an escrow requirement that decides whether you participate directly or build on somebody who does.

Read article
Designing a credit decisioning engine

A credit decisioning engine looks from the outside like a model that outputs a score. In practice the model is a modest component inside a system whose real requirements are explainability, auditability and the ability to change policy safely. Teams that build the model first and the surrounding machinery afterwards end up rebuilding, usually at the point where the business wants to change a rule and nobody can predict what will happen.

Keep reading
Data & AI

Aug 17, 2026 3 min read

Designing a credit decisioning engine

The model is the small part. What decides whether the system survives is being able to explain, two years later, why a specific application was declined.

Read article
Fraud detection without blocking real customers

Fraud teams report what they prevented. What they rarely report, because it is invisible, is what they blocked that was legitimate — the customer whose card was declined, who tried once more, and then bought somewhere else. For most Indian merchants the cost of false positives exceeds the cost of the fraud, and a fraud system that is not measuring both numbers is optimising half the problem.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Fraud detection without blocking real customers

Every rule that stops a fraudster also stops some genuine buyers. The number nobody measures is how many, and that is usually the larger loss.

Read article
Voice and IVR in Indian languages

Voice is how a very large number of Indians prefer to interact with a service, particularly outside the metros, and it is where most product teams' assumptions break most completely. A speech system that performs well in a demonstration meets accented speech, background noise, code-switching mid-sentence and a call quality that varies by the second, and its accuracy falls off a cliff that no benchmark predicted.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Voice and IVR in Indian languages

Speech systems tuned on clean American English meet a Marathi speaker on a moving bus, and the transcript is fiction.

Read article
Choosing a CRM or ERP for an Indian SMB

A mid-sized Indian business choosing its first proper CRM or ERP is making a decision it will live with for five to ten years, usually on the basis of three demonstrations that all looked good. Demonstrations are designed to look good. What separates a system that gets adopted from one that gets abandoned alongside the old spreadsheets is a smaller set of questions, most of which are specific to operating here.

Keep reading
Cloud

Aug 17, 2026 2 min read

Choosing a CRM or ERP for an Indian SMB

The demonstration always works. What decides the outcome is whether the system handles GST, your pricing quirks, and the way your sales team actually operates.

Read article
Implementation is a discipline, not a handover

Most software businesses put their best people on sales and their least experienced on implementation, then are surprised when customers who signed enthusiastically do not renew. The pattern is consistent: the deal is won on a vision, handed to a team that was not in those conversations, and delivered as a configuration exercise. The customer gets working software and never gets the outcome they bought.

Keep reading
Cloud

Aug 17, 2026 2 min read

Implementation is a discipline, not a handover

Software companies obsess over winning the deal and treat what happens next as logistics. That gap is where renewals are lost.

Read article
Writing a tender response that wins

Bidding for large or public sector work is a different skill from selling, and Indian firms lose a great deal of winnable business to the mechanics of it rather than the substance. The single largest cause is disqualification on eligibility or documentation — a missing certificate, an unsigned page, a turnover threshold not evidenced, an earnest money deposit submitted incorrectly — which means the technical proposal that took three weeks was never read.

Keep reading
Cloud

Aug 17, 2026 2 min read

Writing a tender response that wins

Most responses are disqualified on paperwork before anyone reads the technical section. That is a solvable problem and firms lose to it repeatedly.

Read article
Last-mile delivery software in Indian conditions

Last-mile logistics software built on assumptions that hold in Europe or North America performs badly in India, and the reasons are not about algorithm quality. They are about the inputs: addresses that do not geocode, roads that are not passable at the width the map assumes, recipients who are not where the address says, and a delivery model where cash frequently changes hands at the door.

Keep reading
Cloud

Aug 17, 2026 2 min read

Last-mile delivery software in Indian conditions

Optimal routing assumes addresses resolve to coordinates and roads are traversable as mapped. Neither reliably holds here.

Read article
Reconciliation: the system nobody designs

Any product that moves money ends up with three or more records of the same event: your database, the payment provider's record, and the bank statement. Those three will disagree. Not occasionally — routinely, for entirely ordinary reasons, including timing differences at day boundaries, refunds processed asynchronously, chargebacks, provider fees netted from settlements, and transactions that succeeded on one side and timed out on the other. Reconciliation is the system that explains the differences, and in most companies it is not a system at all. It is a person with a spreadsheet.

Keep reading
Cloud

Aug 17, 2026 2 min read

Reconciliation: the system nobody designs

Every payments product eventually employs someone whose whole job is a spreadsheet that explains why three systems disagree. That job was a design decision.

Read article
GST's Invoice Management System: what it changes

The Invoice Management System went live on the GST portal from 1 October, and it changed the shape of input tax credit reconciliation from a reporting exercise into a workflow. Every outward supply your suppliers report in GSTR-1, IFF or GSTR-1A now appears on your IMS dashboard for you to act on. Inward reverse charge supplies and transactions ineligible for input tax credit bypass IMS entirely and flow straight to GSTR-3B.

Keep reading
Cloud

Aug 17, 2026 2 min read

GST's Invoice Management System: what it changes

Doing nothing is now a decision. An invoice you never looked at is deemed accepted, and its credit lands in your return whether it should or not.

Read article
Integrating with India's credit bureaus

India has four credit information companies operating under the Credit Information Companies (Regulation) Act, 2005 and regulated by the RBI: TransUnion CIBIL, Equifax India, Experian India and CRIF High Mark. Any lending product integrates with at least one, and understanding that they are not interchangeable is the starting point — each holds what its member institutions reported to it, so the same borrower can look materially different depending on which you query.

Keep reading
Data & AI

Aug 17, 2026 3 min read

Integrating with India's credit bureaus

Four bureaus, four formats, four views of the same borrower. Which one you pull decides what you see, and none of them sees everything.

Read article
What payroll software must actually handle in India

Payroll looks like arithmetic and is really a compliance system with an arithmetic component. In India a single monthly run touches provident fund, employees' state insurance, professional tax, income tax deduction at source, labour welfare fund in some states, and gratuity provisioning — each with its own thresholds, its own filing, and in several cases its own state-level variation. Software that computes a net figure correctly and cannot produce the returns has solved the easy half.

Keep reading
Cloud

Aug 17, 2026 2 min read

What payroll software must actually handle in India

Salary times twelve is the easy part. The deductions, the state variations and the returns are where payroll software is either right or useless.

Read article
Getting your app onto Indian phones

Distribution decisions for an Indian consumer app are made under constraints that Western product teams rarely face. A large share of your target users hold devices with limited storage that is already close to full, on data plans they are conscious of, and they uninstall applications routinely to make room. That reality should shape the build long before it shapes the marketing.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Getting your app onto Indian phones

Install size, storage pressure and a store review you do not control matter more here than in any market your framework was designed for.

Read article
The admin tool nobody budgets for

Every product has an internal side — the screens support, operations and finance use to answer questions, fix mistakes and unblock customers. It is almost never designed, rarely reviewed, and frequently consists of whatever a developer built quickly two years ago plus direct database access for the things it cannot do. It is also the interface through which your customers' problems actually get resolved, which makes its quality a customer-facing concern wearing an internal disguise.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The admin tool nobody budgets for

Your support team's tooling is the interface through which every customer problem is solved, and it is usually the worst software in the company.

Read article
Churn: measuring it honestly first

Subscription businesses discuss churn constantly and define it loosely, which is why so much effort aimed at it achieves nothing. Before any intervention, three distinctions have to exist in your data: customers who chose to leave, customers whose payment failed, and customers who downgraded but stayed. They have completely different causes and completely different remedies, and a single churn percentage hides all of it.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Churn: measuring it honestly first

Most churn work starts with retention campaigns and should start with a definition, because half of it is not churn at all.

Read article
Notifications: one system, four channels

Most products accumulate notification channels rather than designing them. Email came first, SMS was added for OTPs, push arrived with the mobile app, and WhatsApp was bolted on because that is where Indian customers reply. Each was built by whoever needed it, with its own templates, its own sending code and its own idea of when to send. The customer experiences the result as noise, and the business cannot answer basic questions like how many messages we send a person per week.

Keep reading
Cloud

Aug 17, 2026 2 min read

Notifications: one system, four channels

Email, SMS, push and WhatsApp get built separately by different teams, and the customer receives the same message four times.

Read article
Hiring and running QA properly

Quality assurance in Indian software teams is frequently organised as a stage: developers finish, testers verify, defects come back. It is a familiar arrangement and it produces predictable pathologies — defects found at the most expensive moment, an adversarial relationship between two groups who need each other, and a testing phase that gets compressed whenever the schedule slips, which is exactly when it is most needed.

Keep reading
IT Strategy

Aug 17, 2026 3 min read

Hiring and running QA properly

A tester at the end of the pipeline finds bugs too late to be cheap and gets blamed for the ones that escape. That is a structural problem, not a staffing one.

Read article
Starting a marketplace with nobody on it

A marketplace is the most attractive business model to describe and the hardest to start, because on day one it is worth nothing to either side. Buyers arrive, find nothing, and leave. Sellers list, sell nothing, and stop. The engineering is largely a solved problem — catalogue, search, orders, payments, ratings — and building it well does nothing whatsoever to solve the actual problem, which is that an empty market has no value.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Starting a marketplace with nobody on it

Buyers will not come without sellers and sellers will not come without buyers, and the technology is the least interesting part of solving that.

Read article
Renegotiating with a vendor you cannot easily leave

Every organisation eventually faces a renewal with a supplier it depends on and is not entirely happy with — a platform embedded in operations, a development partner who holds the knowledge, a system nobody wants to migrate. The renewal conversation goes badly for buyers who approach it as a complaint, because dissatisfaction is not leverage. What determines the outcome is whether you could realistically leave, and how confident the vendor is in their answer to that question.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Renegotiating with a vendor you cannot easily leave

Your leverage at renewal is not how unhappy you are. It is whether leaving is genuinely possible, and both sides know the answer.

Read article
Export filing is changing for software exporters

Every Indian company exporting software or IT-enabled services carries an obligation most engineers have never heard of and most founders regard as the accountant's problem. Export declarations must be filed, and export proceeds must be realised within a stated window, or the tax treatment of invoices you have already booked as zero-rated changes. Two significant things have happened to that regime, and one of them takes effect in six weeks.

Keep reading
IT Strategy

Aug 17, 2026 3 min read

Export filing is changing for software exporters

The realisation window moved from nine months to fifteen, and the filing mechanism itself changes on 1 October. If you export software, both affect your cash.

Read article
When one client is most of your revenue

Services firms grow by getting good at serving somebody, and the natural consequence is that one relationship becomes very large. It rarely feels like a risk while it is happening — the work is good, the client is happy, and turning down more of it to protect a ratio feels like an absurd reason to refuse revenue. The risk becomes visible at exactly the moment it is least manageable.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

When one client is most of your revenue

A client at sixty per cent of revenue is not a client. It is an employer with none of the obligations of one, and everyone in the arrangement knows it.

Read article
Releasing your own code as open source

Open sourcing an internal library is proposed for good reasons — engineering reputation, recruiting, giving something back, and occasionally a strategic wish to make a format or a protocol standard. All of those are real. What gets underestimated is that publishing code is the beginning of an obligation rather than the completion of a task, and a repository that goes quiet after four months does more reputational harm than never having published.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Releasing your own code as open source

Publishing is free. Everything after publishing is not, and most abandoned repositories were abandoned by companies who only budgeted for the publishing.

Read article
A design system, or just a component library

Teams build component libraries and call them design systems. The library is the visible part — buttons, inputs, modals, tables — and it is the smaller half. A design system is the set of decisions that make those components consistent: the spacing scale, the type scale, the colour roles, the interaction patterns, and the rules about which component to use for which job. Without those, you have a folder of components that will diverge, because every new screen requires a fresh judgement.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

A design system, or just a component library

Most teams build the components and skip the decisions, which is why the fourth product still looks like a different company made it.

Read article
When to hire a designer, and what to ask for

Engineering-led companies typically hire their first designer late, and hire them for the wrong job. The brief is usually to make the product look better, which treats design as decoration applied at the end. What a good designer actually changes is what gets built — which problems are worth solving, what the flow should be, and which of the four features someone requested was the real need. Hired as a decorator, they will decorate, and the company will conclude that design is a nice-to-have.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

When to hire a designer, and what to ask for

Hiring a designer to make screens prettier wastes them. The value is in what gets built, which is decided before any screen exists.

Read article
Scope creep is a symptom, not a behaviour

Every project overruns and the usual explanation is scope creep, framed as a client failing to stick to what they agreed. That framing is comfortable for suppliers and mostly wrong. Requirements change because building software teaches everyone things they did not know at the start — including the client, who could not have described the right thing before seeing the wrong one. A process that treats learning as misbehaviour is fighting the nature of the work.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Scope creep is a symptom, not a behaviour

Blaming the client for changing their mind misreads what happened. They learned something, which is what a project is for.

Read article
Your first data hire

The first data hire in most companies is a data scientist, because that is the title everyone has heard of, and it is usually the wrong one. A data scientist joining a company with no reliable data infrastructure spends their first year cleaning exports, writing queries for other people, and rebuilding the same dashboard — work they are overqualified for and did not join to do. They leave within eighteen months and the company concludes that data was oversold.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Your first data hire

Hiring a data scientist into a company with no reliable pipeline gives you an expensive person maintaining a spreadsheet.

Read article
Insurance an IT services firm actually needs

Insurance is the least interesting item in a software firm's operations and it appears in almost every enterprise contract. Buyers require suppliers to carry specified cover at specified limits, and the requirement is easy to agree to and awkward to discover you do not meet — typically at the point of signature, when the deal is waiting and the policy takes weeks to arrange.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Insurance an IT services firm actually needs

Enterprise contracts increasingly require cover you may not hold, and the clause specifying it is usually agreed by someone who did not check.

Read article
The first forty-eight hours of a breach

The first hours of a security incident are the ones that determine everything afterwards, and they are the hours in which organisations behave worst — because nobody has decided in advance who does what, and the people who could decide are asleep or in a meeting. Writing this down on a calm day is the entire preparation, and almost nobody does it.

Keep reading
Security

Aug 17, 2026 2 min read

The first forty-eight hours of a breach

The reporting clock in India starts at six hours, which is shorter than the time most teams spend deciding whether it counts.

Read article
Choosing a licence for software you build

Every piece of software you publish carries a licence, including when you do not choose one — code published with no licence is, in most jurisdictions, all rights reserved, meaning nobody may legally use it. That is rarely the intent, and it is the commonest licensing mistake: a repository made public with the assumption that public means usable, which it does not.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Choosing a licence for software you build

The licence decides who may use your work and what they owe you. Picking one by copying whatever the last project used is a decision made by accident.

Read article
Checking a software company is genuine

The Indian software services market has thousands of genuine firms and a meaningful number whose websites are considerably more impressive than their capabilities. Photographs of a leadership team who do not exist, client logos never worked with, certifications never held, and case studies describing projects that did not happen — all of it is easy to produce and none of it is verified by anyone. Before paying a deposit to a firm you found online, four checks are worth twenty minutes.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Checking a software company is genuine

Everything on a website can be invented — the team, the clients, the certifications, the reviews. Four checks take twenty minutes and cost nothing.

Read article
What belongs in a software maintenance contract

The software is delivered, everyone is pleased, and a maintenance agreement is signed with little attention because the interesting part is over. It is the document that governs the next several years of the relationship, and it is usually two pages saying the supplier will provide support and fix defects. Both of those terms need defining or the first disagreement will be about what was promised.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

What belongs in a software maintenance contract

Most maintenance agreements say the supplier will fix bugs. Almost none define bug, and that single missing word is where the arguments start.

Read article
Securing a WordPress site properly

A large share of Indian business websites run on WordPress, and a large share of those get compromised at some point — usually turned into a host for spam pages, a redirect to somewhere else, or a crypto miner. The owner discovers it when Google flags the site or a customer mentions it. Almost none of these compromises exploit WordPress core, which is maintained carefully; they come through plugins, themes and credentials.

Keep reading
Security

Aug 17, 2026 3 min read

Securing a WordPress site properly

Sites are almost never hacked through WordPress itself. They are hacked through a plugin nobody updated and an admin password somebody reused.

Read article
GSP or direct: connecting to the GST system

Any software that files returns, generates e-invoices or produces e-way bills on behalf of Indian businesses has to connect to government systems, and there are two routes. A GST Suvidha Provider is an authorised intermediary that holds the connection and exposes a friendlier interface to you. Alternatively, larger taxpayers can obtain direct API access. Most product companies use a GSP, and understanding why is worth ten minutes before the architecture is decided.

Keep reading
Cloud

Aug 17, 2026 2 min read

GSP or direct: connecting to the GST system

You can integrate with the GST portal directly or through an intermediary. The decision looks technical and is really about who you want to be on the phone to at month-end.

Read article
Signs it is time to replace your ERP

ERP replacement is rarely triggered by a failure. The system still runs, still produces invoices, still closes the month. What has happened instead is that the organisation has quietly built a layer of human effort around it, and the cost of that layer has grown past the cost of replacing the software — but because it is distributed across people's ordinary work, nobody adds it up.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Signs it is time to replace your ERP

The system still works, which is why nobody raises it. The cost shows up as five people doing work the software was bought to remove.

Read article
Why your website does not appear on Google

A business builds a website, waits, searches for itself and finds nothing. The usual conclusion is that it needs SEO, and money gets spent on content and links. Frequently the actual cause is that Google has not indexed the site at all, and no amount of content fixes that. There are four things to check first, and each takes minutes.

Keep reading
IT Strategy

Aug 17, 2026 3 min read

Why your website does not appear on Google

Before assuming you need SEO, check the four things that stop a site being indexed at all. Any one of them makes everything else pointless.

Read article
Card tokenisation: what you may no longer store

The rule is short and absolute. From 1 October 2022, no entity in the card payment chain other than card issuers and card networks may store card-on-file data. That covers merchants, payment aggregators, gateways and anyone else in the flow. If your product holds a card number to make the next purchase easier, it is not a convenience feature — it is non-compliant, and it is a category of finding that ends conversations with any regulated partner.

Keep reading
Security

Aug 17, 2026 2 min read

Card tokenisation: what you may no longer store

Since October 2022 no merchant, gateway or aggregator may hold card-on-file data. Products built before that, or ported from abroad, frequently still do.

Read article
The Aadhaar Data Vault: who needs one

An Aadhaar Data Vault is centralised, restricted-access storage for every Aadhaar number an entity has collected, held inside its own secure infrastructure. The requirement originated in UIDAI circular 11020-205/2017 of 25 July 2017, was revised by Circular No. 8 of 2025 on 18 July 2025, and the accompanying FAQs were updated on 3 November 2025. If you build for anyone handling Aadhaar, the 2025 revision is the version to work from.

Keep reading
Security

Aug 17, 2026 2 min read

The Aadhaar Data Vault: who needs one

If you authenticate against UIDAI you must hold Aadhaar numbers in a vault with reference keys and dedicated HSMs. If you only do offline verification, you are exempt — and that distinction is worth getting right.

Read article
The labour codes and what HR software must change

India's four labour codes came into force on 21 November 2025: the Code on Wages 2019, the Code on Social Security 2020, the Industrial Relations Code 2020, and the Occupational Safety, Health and Working Conditions Code 2020. They consolidate a large body of older legislation, and two of the changes go directly at logic embedded in nearly every Indian payroll system.

Keep reading
Cloud

Aug 17, 2026 3 min read

The labour codes and what HR software must change

Basic pay must now be at least half of total compensation, and fixed-term staff qualify for gratuity after one year. Both break assumptions built into most Indian payroll systems.

Read article
When an Indian enterprise wants it on-premise

A large Indian bank, insurer, manufacturer or government body eventually asks whether your SaaS product can run inside their data centre. Refusing loses a deal that may be worth more than your entire self-serve business. Agreeing casually is worse, because a single-tenant deployment inside somebody else's infrastructure changes your engineering, your support model and your release cadence, and companies that discover this after signing spend two years paying for the discovery.

Keep reading
Cloud

Aug 17, 2026 2 min read

When an Indian enterprise wants it on-premise

Refusing costs you the deal. Agreeing without changing how you build costs you the next two years.

Read article
Getting empanelled as a vendor to an Indian bank

Selling software to an Indian bank, NBFC or insurer is not a sales process in the ordinary sense — it is an onboarding process that a sales conversation eventually triggers. Regulated entities are required to conduct due diligence on their technology suppliers, and that requirement flows down to you as a document pack, an audit, and a set of contractual terms that are largely non-negotiable. Firms that treat this as paperwork to handle after the deal is agreed lose quarters to it.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Getting empanelled as a vendor to an Indian bank

The technical evaluation is the short part. Most firms are eliminated on documentation they could have prepared months earlier.

Read article
Measuring whether engineering is getting better

Every engineering organisation past a certain size is asked to demonstrate that it is improving, and most answer with velocity — a count of story points completed per sprint. It is the wrong number for a simple reason: it measures how the team estimates, not what it delivers, and it can be improved by estimating more generously. Any metric a team can move without changing the outcome will be moved.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Measuring whether engineering is getting better

Story points measure estimation, not delivery. Four numbers actually describe whether a team is improving, and none of them is velocity.

Read article
Search and sorting in Indian languages

A product that supports Indian languages usually means one that displays them. Searching and sorting them is a different problem, and it is where the support turns out to be superficial. The assumptions baked into most databases and search libraries — that sorting is byte order, that a word is a sequence of letters separated by spaces, that users type in the script the content is stored in — hold poorly for Indic text.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Search and sorting in Indian languages

Alphabetical order does not mean anything in Devanagari the way your database assumes, and users type Hindi in Latin letters half the time.

Read article
Reaching users who have no smartphone

Product decisions in Indian software are made on the assumption of a smartphone with a data connection, and for a great many use cases that assumption is fine. For others — agricultural supply chains, rural financial services, blue-collar workforce management, government schemes — a significant portion of the people the product exists to serve either do not have a smartphone, share one within a household, or have one they cannot reliably keep charged and connected. Designing only for the app excludes them entirely.

Keep reading
IT Strategy

Aug 17, 2026 3 min read

Reaching users who have no smartphone

A meaningful share of the Indian market cannot install your app, and for some products they are the market.

Read article
Estimating cloud cost before you build

Cloud cost is treated as something you find out rather than something you decide. A system is designed, built, deployed, and the bill arrives with a number nobody predicted. That is avoidable — not to the rupee, but to the order of magnitude, which is the part that matters. And the exercise is worth doing before building rather than after, because the estimate frequently changes the architecture.

Keep reading
Cloud

Aug 17, 2026 2 min read

Estimating cloud cost before you build

Most teams discover their running cost in month two. It is estimable in an afternoon, and the estimate frequently changes the design.

Read article
White-labelling your product for a partner

Sooner or later a larger company proposes selling your product as theirs. For a small software business that is genuinely attractive — distribution you could not buy, a customer base you could not reach, and revenue without a sales team. It is also a structural decision rather than a cosmetic one, and the version that goes badly is the one agreed as though it were a branding exercise.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

White-labelling your product for a partner

A partner wants your product under their name. It looks like a logo change and it is a decision about who owns the customer.

Read article
New listing rules for Indian e-commerce

The Legal Metrology (Packaged Commodities) Amendment Rules, 2026 were notified on 13 February 2026 and took effect on 1 July 2026. They insert Rule 6(10A), which requires e-commerce entities to display imported products through a searchable filter and to provide a sortable filter based on country of origin. If you run or build an Indian e-commerce platform and that filter does not exist, the compliance date has passed and this is a remediation item rather than something to schedule.

Keep reading
Cloud

Aug 17, 2026 2 min read

New listing rules for Indian e-commerce

Imported products now need a searchable, sortable country-of-origin filter. The deadline was 1 July, which means this is remediation rather than planning.

Read article
Telecom cyber security rules: who they catch

The Telecommunications (Telecom Cyber Security) Rules, 2024 were notified on 21 November 2024 and apply to telecommunication entities broadly — service providers, network operators, equipment manufacturers and importers. For a software firm the relevance is indirect but real: if your client is any of those, these rules shape what they can accept from a supplier and what they will require of you.

Keep reading
Security

Aug 17, 2026 2 min read

Telecom cyber security rules: who they catch

Six hours to notify, twenty-four to detail, and a security officer who must be an Indian citizen and resident. If you build for telecom, your client carries all of it.

Read article
Colocation or cloud for an Indian business

Cloud is the default and colocation is treated as something companies are migrating away from. For a subset of Indian businesses that framing is wrong, and the subset is larger than the cloud conversation suggests. A workload that runs at a steady, predictable level, twenty-four hours a day, with substantial storage and heavy data transfer, is close to the worst case for cloud pricing and close to the best case for owning hardware in somebody else's data centre.

Keep reading
Cloud

Aug 17, 2026 2 min read

Colocation or cloud for an Indian business

Owning the hardware is cheaper per unit of compute and more expensive per unit of attention. Which matters more depends on how steady your load is.

Read article
When a customer asks for all their data

Two versions of this request arrive and they are frequently confused. An individual exercising a right under the DPDP framework or GDPR asks for the personal data you hold about them. An enterprise customer leaving, or preparing to, asks for the data their organisation put into your product. Both are obligations, they have different scopes and formats, and a product that handles one badly usually handles both badly.

Keep reading
Security

Aug 17, 2026 2 min read

When a customer asks for all their data

Under DPDP and every enterprise contract you must be able to produce it. Most products can produce some of it, from the systems somebody remembered.

Read article
Treating your API as a product

Companies open an API because a customer asked, and then discover they have taken on obligations nobody scoped. External integrators write code against it and that code runs in their production. From the moment the first one goes live, your ability to change the interface is constrained by people you cannot deploy for, and that is the defining property of an API as a product rather than as a feature.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Treating your API as a product

An API you expose to customers is a product with users, support costs and a compatibility promise. Most are shipped as a feature and then discovered to be neither.

Read article
A career ladder for a team of twelve

Small engineering teams avoid career frameworks because they feel like corporate machinery for a company of twelve. The consequence is not the absence of a ladder but an invisible one: titles awarded to whoever raised it, salaries set by who negotiated hardest, and promotion decisions defended after the fact. In the Indian market, where people move for a title as readily as for money, that invisibility is a retention problem rather than an administrative one.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

A career ladder for a team of twelve

Without one, promotion goes to whoever asks, pay drifts by negotiating skill, and your best engineer leaves because they cannot see a next step.

Read article
Architecture review that is not theatre

Organisations institute architecture review to stop expensive mistakes and frequently get a ceremony instead. An engineer presents a diagram, senior people ask a few questions, approval is granted, and nobody's decision changed. The cost is real — the delay, the preparation, the meeting — and the benefit is close to zero, because a design cannot be meaningfully assessed by people encountering it for the first time in a room.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Architecture review that is not theatre

A meeting where a senior person approves a diagram after fifteen minutes of looking at it produces approval, not review.

Read article
Should a services firm specialise?

Almost every Indian software services firm describes itself the same way: custom development, cloud, AI, mobile, data, security, across every industry. The reason is understandable — turning away work is painful and the pipeline is uncertain. The consequence is that a buyer comparing three firms sees three identical capability lists and is left with price as the only differentiator, which is the competition nobody wins.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Should a services firm specialise?

Saying you do everything for everyone means competing on price against everyone. Specialising costs you deals you would have lost anyway.

Read article
Selling to Indian SMBs is a different business

A software company with an Indian product eventually faces a choice it often makes by accident: whether it is selling to small and mid-sized businesses or to enterprises. They are not two segments of one market. They buy differently, pay differently, expect different support, and require a different company shape. Serving both from one set of processes produces a product too heavy for the small buyer and too light for the large one.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Selling to Indian SMBs is a different business

The same product sold to a fifteen-person firm and a fifteen-thousand-person one requires different pricing, support, onboarding and patience. Trying to do both usually means doing neither well.

Read article
Software for teams working in the field

Field service software — for installation, maintenance, inspection, surveying, collections — is built by people sitting at desks with good connectivity, for people standing in a factory, a basement, a rooftop or a village with one bar of signal. The gap between those two situations produces a consistent set of failures, and most of them are foreseeable rather than surprising.

Keep reading
Cloud

Aug 17, 2026 2 min read

Software for teams working in the field

Engineers, surveyors and technicians work in basements, on rooftops and in places with no signal. Software designed at a desk fails them in specific, predictable ways.

Read article
Building a telemedicine product in India

The Telemedicine Practice Guidelines, issued in 2020 by the Ministry of Health and Family Welfare, are the legal basis on which registered medical practitioners may consult patients remotely in India. Only physicians registered with the National Medical Commission or a State Medical Council may practise under them, which means the first thing a platform must do is verify registration rather than accept a claimed qualification.

Keep reading
Cloud

Aug 17, 2026 2 min read

Building a telemedicine product in India

Which drugs a doctor may prescribe depends on whether the consultation was video, audio or text. That single rule should shape your product before anything else.

Read article
STPI, SEZ or neither: choosing a structure

An Indian company exporting software chooses between three structures, and most choose by default rather than by analysis. A Special Economic Zone unit sits inside a notified enclave with fiscal incentives. An STPI unit operates under the Software Technology Parks scheme, which is not location-restricted. A non-STPI or Domestic Tariff Area entity operates under ordinary tax and compliance rules with no special incentives. The differences are large enough to be worth an afternoon before incorporating anything.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

STPI, SEZ or neither: choosing a structure

One gives duty-free imports with moderate paperwork. One gives a tax holiday with the heaviest compliance in Indian industry. One gives nothing and asks nothing.

Read article
The 45-day rule: getting paid, and paying

Section 43B(h) of the Income Tax Act took effect from 1 April 2024, applicable from assessment year 2024-25, and it changed the economics of late payment in India. Where a buyer pays a micro or small enterprise beyond the statutory time limit, the deduction for that expense is allowed only in the year the payment is actually made — not the year the service was delivered. For a buyer with a March year end, paying an invoice late moves the deduction into the next financial year and increases this year's taxable profit.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The 45-day rule: getting paid, and paying

If you are a registered small enterprise, your customer loses their tax deduction by paying you late. That is considerably more leverage than a polite reminder.

Read article
Running more than one payment gateway

Indian payment gateways are broadly reliable and they are not perfectly reliable, and the failures cluster in the worst possible places: during a festive sale, at the end of the month, on the day a campaign lands. A business whose checkout can only route through one provider has accepted that its revenue stops when that provider has a problem. For anything past a modest volume, a second gateway is not sophistication, it is ordinary continuity planning.

Keep reading
Cloud

Aug 17, 2026 2 min read

Running more than one payment gateway

Gateways have bad days. If your checkout depends on exactly one, so do your revenues — and the outage always lands during your busiest hour.

Read article
Changing payment gateway without losing customers

Switching payment provider is usually motivated by rates, reliability or a feature the incumbent lacks, and it is scoped as an integration project. The integration is the straightforward part. What makes these migrations difficult is everything that already exists at the old provider — tokenised cards, active recurring mandates, in-flight disputes and settlement history — none of which transfers automatically.

Keep reading
Cloud

Aug 17, 2026 2 min read

Changing payment gateway without losing customers

The saved cards and the active mandates do not come with you, and that is the part that decides whether the migration is survivable.

Read article
Refunds and chargebacks as an operational system

Payment flows get attention because revenue depends on them. Refunds get a button and a hope. The result in most Indian products is that a refund is initiated, the customer sees nothing for several days, contacts support twice, and support cannot say where the money is — because the system recorded that a refund was requested and nothing about what happened next.

Keep reading
Cloud

Aug 17, 2026 2 min read

Refunds and chargebacks as an operational system

Taking money is designed carefully and giving it back is usually an afterthought, which is why refunds generate more support tickets than payments do.

Read article
Why your referral programme is losing money

Referral bonuses, first-order discounts, cashback and affiliate commissions are among the most effective growth levers available in the Indian market, and among the most reliably exploited. Within weeks of launch, coordinated groups will be extracting value at a scale the launching team did not model — and because this is classified as growth spend rather than fraud, it frequently runs for months before anyone measures it properly.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Why your referral programme is losing money

Growth incentives in India get industrialised within weeks. The people gaming them are more organised than the team that launched the programme.

Read article
Continuity planning for an Indian office

Business continuity discussions in software companies concentrate on infrastructure — multi-zone deployment, backups, failover. Those matter and they are not what stops an Indian services firm working. What stops it is a flooded arterial road during monsoon, a building-wide power failure with a generator that was never load-tested, a fibre cut affecting the office park, or a civic disruption that makes commuting unsafe for a day.

Keep reading
Cloud

Aug 17, 2026 2 min read

Continuity planning for an Indian office

Cloud redundancy is well understood. The failure that actually stops an Indian services firm is water, power, or the road to the office.

Read article
The bench: the cost nobody plans for

In a services firm, people are the cost and billable time is the revenue, so the gap between them — engineers on the bench, waiting for the next project — is where margin goes. It is also poorly measured in most Indian firms, because utilisation is reported as an average across the company, which conceals both the person who has been unassigned for six weeks and the team working unsustainable hours on a late delivery.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The bench: the cost nobody plans for

Engineers between projects are the single largest controllable cost in a services business, and the instinct that fixes it usually makes it worse.

Read article
Quoting fixed price without losing money

Fixed price is what most Indian buyers want, and for a supplier it is a bet on your own estimate. The bet is winnable on well-defined work and close to unwinnable on vague work, and the commonest cause of an unprofitable services project is a fixed price quoted against a brief that could be interpreted three ways. The discipline is not better estimating; it is declining to quote fixed price on work that is not fixed.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Quoting fixed price without losing money

Clients prefer fixed price and suppliers keep agreeing to it on briefs that cannot support it. The discipline is in what you refuse to quote.

Read article
Subcontracting part of a project safely

Services firms subcontract for good reasons — a specialisation they lack, a capacity spike, a geography they cannot cover. It is normal and it is manageable. What causes trouble is that the client's contract is with you, so the subcontractor's quality, security posture, confidentiality and delivery are all your liability, while their work is the part of the project you have least visibility of.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Subcontracting part of a project safely

Your client contracted with you. Whatever the subcontractor does or fails to do is yours, including the parts you cannot see.

Read article
A bug backlog of four hundred is a decision

Every product past a certain age has a bug backlog too large to read. Nobody planned it: bugs were reported, triaged as low priority, and left. The list grows monotonically because nothing removes items except fixing them, and the low-priority ones are never the most valuable work available. Eventually the backlog is a place where reports go to be forgotten, and the team knows it, which changes how they treat new reports.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

A bug backlog of four hundred is a decision

Nobody chose to have four hundred open bugs. It accumulated because closing one felt optional and reporting one felt free.

Read article
A help centre that actually reduces tickets

Companies build a help centre by documenting the product feature by feature, publishing it, and observing that ticket volume does not fall. The reason is that the documentation is organised the way the product is built, and users arrive with a problem described in their own words. A section titled Account Settings does not answer why can't I log in, and a user who fails to find an answer in ninety seconds contacts support and never returns to the help centre.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

A help centre that actually reduces tickets

Most help centres are written from the product's structure and consulted by nobody. Write from the ticket queue instead.

Read article
When a client escalation reaches your CEO

A client escalation that reaches the head of the company almost never arrives because a technical issue was unusually hard. It arrives because the client stopped believing that the people they were dealing with had it under control. That belief is lost gradually — a missed update, a date that moved without explanation, an answer that turned out to be optimistic — and the escalation is the moment the accumulated doubt becomes an action.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

When a client escalation reaches your CEO

By the time it arrives at the top, the technical problem is rarely the problem. Something in the communication failed weeks earlier.

Read article
Shipping software into a network with no internet

Some Indian deployments — defence, certain government systems, parts of critical infrastructure, occasionally a bank's most sensitive environment — run on networks with no route to the internet. Delivering software into one is a different discipline from ordinary on-premise work, and the difficulty is not security engineering. It is that every convenience your build and runtime quietly depend on has to be identified and removed.

Keep reading
Security

Aug 17, 2026 2 min read

Shipping software into a network with no internet

No package downloads, no licence check, no telemetry, no remote support. Every convenience your build depends on has to be removed first.

Read article
What a security incident would actually cost you

Requests for security investment fail in a predictable way. Engineering describes risk qualitatively, leadership hears a preference competing against customer features, and the features win. The problem is not that leadership is careless; it is that one side is describing a possibility and the other is allocating money, and possibilities do not compete well against roadmap items. The fix is to model one specific incident properly.

Keep reading
Security

Aug 17, 2026 2 min read

What a security incident would actually cost you

Security budgets are argued in adjectives and refused in numbers. Modelling one plausible incident changes that conversation permanently.

Read article
The handover from sales to delivery

Projects that disappoint rarely fail in the build. They fail at the seam between the people who sold the work and the people who do it. The deal was won on a series of conversations, a demonstration, and a set of impressions the client formed about what they were buying. What crosses to delivery is a signed scope document, which contains a fraction of that and none of the impressions.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The handover from sales to delivery

The deal was won on a conversation the delivery team never heard, against expectations nobody wrote down. That gap is where most unhappy projects begin.

Read article
Safe harbour: the obligations you may not know you have

The Information Technology Act defines an intermediary very broadly: any person who receives, stores, transmits or provides a service in respect of an electronic record on behalf of another person. That covers web hosts, internet service providers, search engines, e-commerce platforms and social media, and it catches a great many products whose founders have never thought of themselves as intermediaries — anything with user-generated content, reviews, listings, comments or file sharing.

Keep reading
Security

Aug 17, 2026 2 min read

Safe harbour: the obligations you may not know you have

If users can post anything on your platform, you are probably an intermediary — and failing one due diligence requirement removes your protection from what they post.

Read article
Hiring your first product manager

The first product manager in a small company is usually hired because engineering is asking what to build next and the founder has run out of hours to answer. That framing produces a coordinator: someone who writes tickets, chases updates and runs standups. It is a real job and it is not what a product manager is for, and hiring at product manager salary for it is expensive administration.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Hiring your first product manager

Hired to run the backlog, they become a ticket clerk. Hired to decide what not to build, they earn their salary in the first quarter.

Read article
User research that survives Indian politeness

User research in India runs into a cultural pattern that quietly invalidates a great deal of it: participants are reluctant to criticise something to the face of the person who made it, particularly across a status gap. Ask an Indian user whether they liked your product and you will frequently be told yes, sincerely and warmly, by someone who will never open it again. Research that does not account for this produces confident, wrong conclusions.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

User research that survives Indian politeness

People here will tell you your product is very good and then never use it again. Designing around that is the whole skill.

Read article
The first five minutes decide everything

Companies attack churn with retention campaigns aimed at customers who are already leaving, which is the most expensive point of intervention available. The decision was mostly made in the first session. A user who reached the thing your product does well, and did it, behaves completely differently from one who signed up, looked around, and closed the tab — and the difference persists for the life of the account.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The first five minutes decide everything

Most churn is decided in the first session, months before the cancellation. Onboarding is where retention work actually happens.

Read article
Moving users from your old product to your new one

A company rebuilds its product, ships something genuinely better, and receives complaints. This surprises teams every time and it should not. Existing users did not experience the old product's flaws the way you did — they learned around them, built habits, and became fast. What you shipped removes their expertise and asks them to be beginners again, and the improvement has to be large enough to pay for that.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Moving users from your old product to your new one

You rebuilt it because the old one was bad. Your users had learned the bad one, and to them your improvement is a loss.

Read article
Shutting down a product without burning customers

Discontinuing a product is a normal commercial decision and it is handled badly often enough that doing it well is a differentiator. Customers who built a process on your software are being told to stop, and how you manage that is observed by everyone else you sell to. A company that ends a product carelessly has told its remaining customers something about what happens if their product becomes unprofitable.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Shutting down a product without burning customers

How you end a product is watched by every customer of every other product you sell.

Read article
A/B testing when you do not have the traffic

Split testing is treated as the mature way to make product decisions, and for a consumer product with substantial traffic it is. For a B2B product with four hundred accounts, or a young marketplace with a few thousand monthly users, the arithmetic does not work: detecting a realistic improvement requires far more observations than you will collect in a reasonable period, and a test stopped early because the numbers looked good is not evidence of anything.

Keep reading
Data & AI

Aug 17, 2026 2 min read

A/B testing when you do not have the traffic

Most Indian B2B products will never have the volume for a significant test, and running one anyway produces confident nonsense.

Read article
Moderating user content on an Indian platform

Any Indian platform carrying user content — reviews, listings, comments, profiles, uploads — needs a moderation capability, and the requirement is set partly by law and partly by what your users will tolerate. The legal floor comes from the IT Rules: acknowledge a grievance within twenty-four hours, resolve within fifteen days, act on a court order or government notification within thirty-six hours, and within twenty-four for the most serious categories. Missing those puts your safe harbour at risk.

Keep reading
Security

Aug 17, 2026 2 min read

Moderating user content on an Indian platform

Twenty-two official languages, statutory takedown clocks, and a safe harbour you lose by being slow. Automated filtering alone will not carry it.

Read article
What an enterprise buyer looks for on your website

An enterprise buyer researching a supplier does something specific and predictable, and most Indian software websites are not built for it. They are not persuaded by the value proposition on the homepage. They are establishing whether you are real, whether you are competent, and whether the procurement process is going to be painful — and they form that judgement in about ten minutes across four or five pages.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

What an enterprise buyer looks for on your website

They are not reading your homepage copy. They are checking whether you look like a company that will still exist in three years.

Read article
Choosing the two numbers your company runs on

Companies build dashboards by adding every metric anyone asks for, and end up with a screen that describes the business comprehensively and changes no decision. The problem is not measurement, it is that a metric only matters if there is an action attached to it moving. Forty numbers cannot each have an owner and a response, so none of them do.

Keep reading
Data & AI

Aug 17, 2026 2 min read

Choosing the two numbers your company runs on

A dashboard with forty metrics is a dashboard nobody acts on. Most companies need one number for health and one for growth.

Read article
When the direction changes every three weeks

Engineering teams in young companies frequently work under a founder whose direction changes often. Some of that is correct — a founder who never changes course in response to evidence is a worse problem — and some of it is the avoidance that comes from a hard problem being replaced by a fresh one. From inside the team the two are indistinguishable, and the indistinguishability is what destroys morale.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

When the direction changes every three weeks

Some of it is genuine learning and some of it is avoidance. The team cannot tell the difference, and that is what does the damage.

Read article
Running a remote-first team in India

Hiring across Indian cities rather than within one removes the constraint that determines most engineering hiring here: whether a good candidate is willing to commute to your office. The pool becomes national, salaries outside the metros are lower, and attrition is often lower too. What it costs is everything that was previously handled implicitly by proximity, and the companies that struggle are the ones that did not replace those things deliberately.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Running a remote-first team in India

The talent pool widens enormously and so does the number of things that were previously handled by people being in the same room.

Read article
When the client wants AI in it

A client asks for AI in their product. Sometimes the requirement is real and well-formed. Frequently the request is a board expectation, a competitor's announcement, or a genuine problem described in the vocabulary currently available. Building what was asked for, without establishing which of those it is, produces a feature that demonstrates well and changes nothing — and the client concludes that AI did not work for them.

Keep reading
Data & AI

Aug 17, 2026 2 min read

When the client wants AI in it

The request is usually genuine and the requirement underneath it is usually something simpler. Finding that out is the whole job.

Read article
Build or buy the tools you run on

Every engineering team eventually proposes building something it could buy — a deployment tool, a monitoring layer, an internal wiki, a ticketing system, a feature flag service. The arguments are consistent and often sincere: the commercial option is expensive, it does not fit our workflow, and we could build a simpler version in two weeks. The two weeks is the part that is almost never true.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Build or buy the tools you run on

Engineers reliably underestimate the cost of the internal tool and overestimate the pain of the product they could have bought.

Read article
A customer advisory board that is not theatre

A customer advisory board is a small group of customers who meet periodically to discuss where your product should go. Done casually, it becomes a session where you present the roadmap and customers nod, which produces a pleasant meeting and no information. Done deliberately, it is the cheapest access to informed judgement about your market that exists.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

A customer advisory board that is not theatre

Assembled to make customers feel heard, it becomes a quarterly presentation. Assembled to settle real decisions, it earns its place.

Read article
Running a beta that tells you something

Beta programmes are usually run to find bugs before launch and to generate a feeling of momentum. Both are fine and neither is the valuable outcome. The valuable outcome is discovering whether people will actually use the thing, repeatedly, when it is not new — and a beta designed for coverage rather than for depth cannot answer that.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Running a beta that tells you something

A hundred users who signed up out of curiosity and never returned have told you nothing. Twelve who use it weekly have told you everything.

Read article
When a competitor undercuts you

A competitor drops their price, your sales team starts losing deals on cost, and the pressure to respond is immediate. In Indian software and services this happens constantly, because the market has a wide range of firms with different cost bases and different definitions of an acceptable margin. Matching is the instinctive response and it is usually a decision to compete on the one dimension where you cannot win permanently.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

When a competitor undercuts you

Matching is the fastest response and usually the wrong one, because in the Indian market there is always someone able to go lower.

Read article
Saying no to a customer

Small companies say yes reflexively, particularly in a competitive market, and particularly to large customers. It feels like service and it is frequently the opposite: a yes to something you cannot do well produces a late delivery, a compromised product, or a feature nobody else wants that you maintain forever. The disappointment is deferred rather than avoided, and it arrives after the money has been spent.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Saying no to a customer

Agreeing to everything is not customer service. It is a decision to disappoint them later, at a worse moment, with more money spent.

Read article
The engineer in the sales call

At some point in an enterprise sale, the buyer brings an architect or a security lead into the room. Their job is to establish whether the capability described in the proposal exists. The supplier's instinct is to send whoever presents best, and the better instinct is to send the person who would actually do the work — because the buyer's technical person can tell the difference within a few questions, and the discovery that they were being managed is worse than any weakness they might have found.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

The engineer in the sales call

Buyers bring their technical people to test whether your capability is real. What they are assessing is not the answer, it is how you handle not knowing.

Read article
Choosing who to sell to first

Founders resist choosing a segment because the Indian market is enormous and narrowing feels like discarding opportunity. The effect is the opposite. A product described for all businesses has to be described generically, which means no particular buyer recognises their own problem in it, which means each sale is a fresh act of persuasion. A product for a specific kind of buyer sells itself partway before anyone speaks.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Choosing who to sell to first

A product for everyone is bought by nobody, and in a market as large as India the temptation to stay broad is strongest exactly when narrowing matters most.

Read article
FSSAI rules that shape a food platform's software

Any e-commerce food business operator in India must hold a valid FSSAI licence or registration, and cannot trade on any platform without it. For a platform that is a two-sided obligation: your own status, and verification that every seller listing food holds theirs. Collecting a licence number at onboarding, validating it, and tracking its expiry is the minimum, and platforms that treat it as a free-text field discover the gap when a regulator asks.

Keep reading
Cloud

Aug 17, 2026 2 min read

FSSAI rules that shape a food platform's software

A product must have 30% of its shelf life or 45 days remaining at delivery. That is not a policy, it is an inventory and fulfilment rule your system has to enforce.

Read article
Freelancer, agency or your own team

An Indian business needing software has three routes and usually compares them on hourly rate, which is the least informative axis available. A freelancer, an agency and an in-house team are not the same thing at different prices — they carry different risk, different continuity and different amounts of work that you have to do yourself. Knowing which of those matters most to you decides it more cleanly than any quote.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Freelancer, agency or your own team

The rates differ by a factor of four and so does what you are actually buying. Comparing them on price alone guarantees the wrong choice.

Read article
Custom software or something off the shelf

A business with a problem asks whether to buy software or have it built. Custom development firms have an obvious incentive in answering that, so treat what follows accordingly — but the honest position is that a large share of the enquiries we receive describe problems a configured product solves better and cheaper. Recommending against a build is occasionally the right recommendation, and firms that never do it are not giving advice.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Custom software or something off the shelf

We build custom software, and we tell a meaningful share of enquirers to buy a product instead. Here is the line we draw.

Read article
Getting your existing software audited

Businesses commission a technical audit for a small number of recurring reasons: changes have become slow and expensive and nobody can say why, the vendor who built it is unresponsive or gone, an investor or buyer has asked questions, or something broke badly enough to prompt the question of what else might. All four are legitimate, and what the audit should produce differs depending on which one you have.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Getting your existing software audited

You inherited a system nobody can explain and a vendor whose estimates keep growing. An audit tells you what you actually own.

Read article
Digital transformation, translated

Digital transformation is sold as a programme and bought as an aspiration, which is why so many of these initiatives produce a strategy document, a pilot, and no change to how the business operates. The phrase has no fixed meaning, so the first useful step is to refuse it and ask what specifically is supposed to be different in eighteen months.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Digital transformation, translated

The phrase means whatever the person selling it needs it to mean. For a mid-sized Indian company it should mean four specific things.

Read article
Budgeting IT for the year ahead

IT budgeting in mid-sized Indian companies is frequently done by taking last year's spend and adding a percentage. It produces a number that is approximately right and is wrong in the specific places that matter, because IT cost does not grow smoothly — it steps, when a licence tier is crossed, when a contract renews at a new rate, when hardware reaches end of support, or when headcount pushes you into a different pricing band.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

Budgeting IT for the year ahead

Most IT budgets are last year's number plus a bit. That misses the two things that actually move: renewals you forgot and capacity you will outgrow.

Read article
You are paying for software nobody uses

Software subscriptions are bought by individuals to solve immediate problems and are almost never cancelled. A tool adopted for a project that ended. Seats for people who have left. Two products doing the same job because two teams chose separately. A plan upgraded during a busy quarter and never downgraded. Each was reasonable, none is reviewed, and collectively they are usually a meaningful share of a company's software spend.

Keep reading
IT Strategy

Aug 17, 2026 2 min read

You are paying for software nobody uses

Subscriptions accumulate one reasonable decision at a time and are never reviewed, because each is individually too small to bother with.

Read article
ARM instances: real savings, with conditions

All the major cloud providers now offer ARM-based instances alongside x86, priced lower for comparable specifications. For workloads that run well on them, the saving is straightforward and permanent. The question is whether yours does.

Keep reading
Cloud

Aug 17, 2026 1 min read

ARM instances: real savings, with conditions

The price difference is genuine. Whether you can take it depends on your dependencies, and the only way to know is to try.

Read article
Reserved capacity: committing without regretting it

Cloud providers offer substantial discounts in exchange for committing to a level of usage over one or three years. The discount is real and the trap is equally real: a commitment made on optimistic growth assumptions becomes a bill for capacity you are not using.

Keep reading
Cloud

Aug 17, 2026 1 min read

Reserved capacity: committing without regretting it

Discounts for commitment are the largest lever on a cloud bill and the easiest to over-pull.

Read article
ITIL 4 for Indian IT teams: what to adopt and what to skip

ITIL 4 arrives as a large book of practices, and the instinct of a newly appointed IT manager is to implement all of it, because that is what the certification implied was correct. Six months later most of the documentation is unused, the process nobody asked for is being worked around, and the framework has acquired a reputation inside the company as bureaucracy rather than discipline.

Keep reading
IT Strategy

Aug 16, 2026 1 min read

ITIL 4 for Indian IT teams: what to adopt and what to skip

ITIL 4 is a large, mature framework built for organisations with dedicated process owners. Most Indian IT teams don't have that, and adopting it wholesale is how the framework dies within a year…

Read article
The FTP server nobody owns is your biggest quiet risk

Ask an IT team what the oldest running server is and the answer is often a file transfer host. It exchanges data with banks, logistics partners, payroll providers. Its credentials predate the current staff. Its logs, if any, go back a week.

Keep reading
Security

Aug 16, 2026 1 min read

The FTP server nobody owns is your biggest quiet risk

Almost every established company has one. It exchanges files with partners, it has credentials from a decade ago, and nobody is quite sure what would break if it stopped.

Read article
Using DigiLocker for document verification

Onboarding flows that ask users to photograph a document create work on both sides. The user finds a document and takes a picture in poor light; someone or something at your end tries to read it and decide whether it is genuine. Neither step is reliable.

Keep reading
Engineering

Aug 16, 2026 1 min read

Using DigiLocker for document verification

Users uploading photographs of documents is slow, error-prone and hard to verify. Fetching the issued document directly solves all three.

Read article
Building a CMDB that doesn't go stale

Most CMDB projects begin with an enthusiastic discovery exercise, a populated database, and a demonstration to leadership showing every server, application and dependency mapped cleanly. Eighteen months later the database describes an estate that no longer exists, because servers were decommissioned without anyone updating the record, and a new application was deployed by a team that had never heard of the CMDB.

Keep reading
IT Strategy

Aug 15, 2026 1 min read

Building a CMDB that doesn't go stale

A configuration management database is accurate on the day it launches and wrong within a quarter, because nobody designed a reason for it to stay current. Here's what actually keeps one honest…

Read article
Credit on UPI: what changes for merchants

UPI began as an account-to-account rail, and a great deal of merchant software was written assuming that. The extension of UPI to credit — RuPay credit cards and pre-sanctioned credit lines linked to a UPI handle — changes some of those assumptions in ways that surface at reconciliation time rather than at checkout.

Keep reading
Business

Aug 15, 2026 1 min read

Credit on UPI: what changes for merchants

A UPI transaction funded by a credit line behaves differently from one funded by a bank account, and merchant systems often assume they are the same.

Read article
Automating input tax credit reconciliation

Input tax credit depends on your suppliers doing their part. If a supplier has not reported an invoice, the credit does not appear in your auto-populated statement, and claiming it anyway creates an exposure. Finding the gaps is a matching exercise across two datasets that rarely agree on formatting.

Keep reading
Business

Aug 15, 2026 1 min read

Automating input tax credit reconciliation

Credit you cannot claim is cash you have already spent. The matching work behind it is exactly the kind of thing software should do.

Read article
Fixed-price or time-and-materials: which contract to sign

Most buyers assume fixed-price is the safe option and time-and-materials is the one where a vendor runs up the meter. That instinct is understandable and it is usually wrong. Both models are legitimate; the failures come from applying one to work that has the shape of the other. It is worth understanding what each actually does before you decide which to insist on.

Keep reading
IT Strategy

Aug 14, 2026 3 min read

Fixed-price or time-and-materials: which contract to sign

Both models are honest. Choosing the wrong one for your project is what turns a good partnership into a dispute…

Read article
GST on software exports: what changed in 2026

Every IT and software service supplied in India carries GST at 18%. There is no concessional rate for the sector and no composition scheme, whatever a consultant tells you. Custom development, SaaS subscriptions, AMC contracts, consulting and support all sit at the same rate, classified under SAC codes in the 9983 family — 998314 for software development and SaaS platforms, 998313 for IT consulting and support, 998315 for hosting and cloud infrastructure. If your turnover crosses five crore rupees you must use the full six-digit code on every invoice, and it is worth doing from the start regardless.

Keep reading
Security

Aug 14, 2026 3 min read

GST on software exports: what changed in 2026

Software services carry 18% GST, but exports are zero-rated if you meet five conditions — and a Finance Act 2026 change quietly fixed the rule that had been costing intermediaries their export status.

Read article
Data residency rules for Indian fintech

On 6 April 2018 the Reserve Bank of India issued a circular requiring every payment system operator to store payment system data within India. It is a short document and it has not changed much since, which is precisely why teams skim it, assume they understand it, and then discover during an audit that a logging pipeline or an analytics tool has been quietly shipping regulated data to another continent for three years.

Keep reading
Security

Aug 14, 2026 3 min read

Data residency rules for Indian fintech

The RBI's payment data localisation directive is short, old and widely misunderstood. Most of the compliance failures we see are architectural decisions made years before anyone read the circular.

Read article
CERT-In's six-hour breach reporting rule

CERT-In Direction No. 20(3)/2022, issued on 28 April 2022 and effective sixty days later, requires organisations to report specified cyber incidents within six hours of noticing them, or of being made aware of them. Six hours is the number everyone remembers and almost nobody has planned for. It is shorter than a working day, shorter than most escalation chains, and considerably shorter than the time an engineering team typically spends establishing whether something is an incident at all.

Keep reading
Security

Aug 14, 2026 3 min read

CERT-In's six-hour breach reporting rule

Six hours is not enough time to write a process. If you have not decided in advance who reports and on what evidence, the deadline passes while people are still deciding whether it counts.

Read article
What an RBI payment aggregator licence requires

A surprising number of Indian software products drift into being payment aggregators without anyone deciding to. If your platform collects money from a customer and later passes it to a merchant — a marketplace, a booking product, a services platform taking payment on behalf of providers — you are handling funds that are not yours, and the Reserve Bank has a specific view about who is allowed to do that. The framework began with the PA-PG guidelines of 17 March 2020 and was expanded in November 2024 to bring offline payment aggregators and cross-border aggregators inside the perimeter.

Keep reading
Security

Aug 14, 2026 3 min read

What an RBI payment aggregator licence requires

Handling other people's money on your platform makes you a payment aggregator, whether you intended it or not. The capital and architecture requirements are specific, and the penalty for operating without authorisation is per-day.

Read article
The EU AI Act and Indian software exporters

Indian software companies tend to read the EU AI Act as somebody else's regulation. It is not. Like the GDPR before it, the Act reaches providers outside the Union when the system or its output is used within it. A Bengaluru firm shipping an AI feature inside a product sold to European customers is a provider under the Act, and the fact that no part of the company is in Europe changes nothing about that.

Keep reading
AI

Aug 14, 2026 2 min read

The EU AI Act and Indian software exporters

The Act applies by where the output lands, not where the company sits. If your AI feature is used in Europe, the dates below are yours — and one of them was twelve days ago.

Read article
GST e-invoicing: what integration involves

E-invoicing under GST is mandatory for businesses with aggregate annual turnover above five crore rupees. It applies to business-to-business transactions and exports. Banking, insurance, NBFCs, goods transport agencies, passenger transport and multiplexes are exempt, as are business-to-consumer sales. If you build billing software, an ERP, or any product that issues invoices on behalf of Indian businesses, this is not an optional module — it determines whether your customer's invoices are legally valid.

Keep reading
Cloud

Aug 14, 2026 2 min read

GST e-invoicing: what integration involves

An invoice without a valid IRN is not a valid invoice, and your customer cannot claim credit on it. That single fact is why e-invoicing integration is a billing-critical path, not a reporting feature.

Read article
ISO 27001 or SOC 2: which your buyer wants

The question is usually framed as which standard is stronger. That is the wrong frame. Both exist to give a buyer confidence that you manage information security deliberately, and the honest deciding factor is which document your prospective customers ask for in procurement. That is largely geographic. ISO 27001 is accepted in more than 160 countries and is the default expectation across Europe, APAC, the Middle East and Latin America. SOC 2 is primarily a North American expectation, with growing recognition in the UK, Australia and Israel.

Keep reading
Security

Aug 14, 2026 2 min read

ISO 27001 or SOC 2: which your buyer wants

They are not competing standards and you do not have to pick the better one. You have to pick the one your customers keep asking for, which is mostly a question of geography.

Read article
Answering an enterprise security questionnaire

At some point a deal you thought was closing produces a spreadsheet with several hundred rows, sent by a security team you have not met, with a response deadline that assumes you have done this before. The questions cover encryption, access control, incident response, subprocessors, business continuity, secure development, physical security and a dozen other areas, and roughly a third of them do not apply to your product at all.

Keep reading
Security

Aug 14, 2026 2 min read

Answering an enterprise security questionnaire

A three-hundred-question spreadsheet arrives late in a deal and stalls it for six weeks. The fix is not answering faster — it is answering once and reusing it.

Read article
Who owns the code when you outsource

The most common misconception in outsourced development is that signing a non-disclosure agreement settles the intellectual property question. It does not. An NDA governs what each side may reveal about the other. Ownership of what gets built is a separate matter, requiring an explicit assignment, and a contract can be entirely silent on it while looking thorough. If your agreement does not contain the words assigning ownership of deliverables to you, the default position may not be what you assume.

Keep reading
Cloud

Aug 14, 2026 2 min read

Who owns the code when you outsource

An NDA protects your secrets. It does not give you the code. Those are two different clauses and a surprising number of contracts contain only the first.

Read article
Source code escrow: when a client demands it

A large customer buying critical software from a smaller vendor eventually asks what happens if that vendor disappears. Source code escrow is the traditional answer: the source is deposited with a neutral third party and released to the customer on defined trigger events — insolvency, cessation of business, or persistent failure to meet support obligations. As a way of making a procurement committee comfortable, it works. As a way of actually recovering a system, it usually does not, and it is worth understanding why before either side signs.

Keep reading
Cloud

Aug 14, 2026 2 min read

Source code escrow: when a client demands it

Escrow is a reasonable request and a mostly useless product, because the deposit is almost never the thing that would actually let you recover.

Read article
Taking over a project from another vendor

A takeover starts from an unusual position: the client is unhappy, often with reason, and is inclined to describe the incumbent's work as worse than it is. Believing that description uncritically is the first mistake, because it leads to promising a rewrite that is neither necessary nor affordable. The second mistake is the opposite — assuming the code is fine and the problem was purely relationship management. Both errors come from the same source, which is starting work before completing an inventory.

Keep reading
Cloud

Aug 14, 2026 2 min read

Taking over a project from another vendor

Most rescue projects fail in the first three weeks, and almost never for technical reasons. They fail because nobody established what actually exists before promising what comes next.

Read article
Staff augmentation or a managed team

Staff augmentation places engineers under your management. You set priorities, run standups, review their work and own the result. A managed team is different: the vendor owns delivery of an agreed outcome, brings its own lead, and is accountable for how the work gets done. Both are legitimate. The failure mode is buying one and expecting the other, which happens often enough to be the default outcome when nobody names it explicitly.

Keep reading
Cloud

Aug 14, 2026 2 min read

Staff augmentation or a managed team

The difference is not headcount or rate. It is who is accountable for the outcome, and buying the wrong one produces a team nobody is actually running.

Read article
Where your cloud bill actually goes

A cloud bill is not a list of what you use. It is a list of what you are charged for, organised for billing rather than for understanding, and the gap between those two things is where the money goes. Teams that set out to reduce spend usually start with instance sizes, because that is the line item they recognise. It is rarely where the surplus is.

Keep reading
Cloud

Aug 14, 2026 2 min read

Where your cloud bill actually goes

Nobody overspends on compute by accident. They overspend on things nobody is looking at — and the bill is organised to make those invisible.

Read article
What UPI integration actually involves

The first thing to understand about UPI is that you almost certainly cannot participate in it directly. NPCI owns and operates the network, approves every participant and audits its members. Banks connect as Payment Service Providers — they register users, link accounts to UPI identifiers and authenticate customers. An application company sits a level below that, as a Third Party Application Provider, and a TPAP is explicitly a service provider to a PSP rather than an independent member. It participates in UPI through the PSP bank, not alongside it.

Keep reading
Security

Aug 14, 2026 3 min read

What UPI integration actually involves

You cannot join UPI directly. Everything about the integration follows from that one structural fact, including who your customer complains to when a payment fails.

Read article
Building on the Account Aggregator framework

India's Account Aggregator framework moves financial data between institutions with the customer's explicit consent, and it has quietly become usable infrastructure rather than a pilot. As of early 2026 there were seventeen licensed Account Aggregators, thirteen of them with live integrations, and more than 135 financial information providers on the network: 72 banks spanning private, public, small finance, regional rural, foreign and cooperative institutions, 57 insurers, both depositories, the two major registrars, three NPS record keepers, six NBFCs, forty asset management companies via the RTAs, GSTN and CCIL.

Keep reading
Security

Aug 14, 2026 2 min read

Building on the Account Aggregator framework

The rails are real and the coverage is better than most people assume — but the exclusions are specific, and they are the ones that break a lending product.

Read article
Integrating with ONDC: what it takes

The most useful sentence anyone can hear about ONDC is that it is a protocol rather than a platform. Selling on Amazon means joining somebody's marketplace and accepting its rules. ONDC instead standardises how buyer-facing and seller-facing software talk to each other, so that independent applications can interoperate without any of them owning the network. Every design decision in the integration follows from that, and teams that approach it as another sales channel to plug in tend to underestimate it.

Keep reading
Cloud

Aug 14, 2026 2 min read

Integrating with ONDC: what it takes

ONDC is a protocol, not a marketplace. That distinction is the whole story, and it is why integrating feels less like adding a channel and more like joining a network.

Read article
WhatsApp Business API: costs and constraints

WhatsApp is where Indian customers actually reply, which is why almost every consumer product here eventually builds on the WhatsApp Business Platform. The economics changed materially on 1 July 2025, when Meta moved from conversation-based pricing to per-message billing. Anything designed or costed against the old model needs revisiting, because the levers that reduce spend are now completely different ones.

Keep reading
Cloud

Aug 14, 2026 2 min read

WhatsApp Business API: costs and constraints

Meta switched to per-message billing in July 2025, and the twenty-four hour service window is now the single biggest lever on what your messaging costs.

Read article
Building for users on a poor connection

A product built in Bengaluru is usually built on a fast, stable connection, by engineers with current hardware, in a room where the network never wavers. The people who determine whether it grows are frequently on an intermittent mobile connection, on a device several generations old, with limited storage and an operating system that aggressively kills background processes. The gap between those two experiences is where most Indian consumer products quietly lose their users, and it does not show up in any dashboard that measures averages.

Keep reading
Cloud

Aug 14, 2026 2 min read

Building for users on a poor connection

Most Indian software is tested on office wifi by people holding recent phones. The users who decide whether it succeeds are neither.

Read article
Migrating off Tally or an on-prem ERP

A business that has run on Tally or an on-premise ERP for ten years is not running on software. It is running on software plus a decade of accumulated convention: how a particular ledger is used, which fields were repurposed for something they were not designed for, what a specific narration prefix means, and which reports are trusted versus which are politely ignored. The migration project is mostly about surfacing that, and teams that scope it as a data transfer discover this in month three.

Keep reading
Cloud

Aug 14, 2026 2 min read

Migrating off Tally or an on-prem ERP

The software is rarely the hard part. The hard part is that a decade of business rules live in one accountant's head and in the way the data was entered.

Read article
Setting up a GCC in Bengaluru

Global capability centres in Bengaluru have moved a long way from the cost-arbitrage back offices of twenty years ago, and the ones being built now are generally intended to own products rather than support them. That intent is the single strongest predictor of whether the centre succeeds, because it determines who is willing to join it. Senior engineers in this market have options, and they can tell within one interview loop whether a role involves deciding anything.

Keep reading
Cloud

Aug 14, 2026 2 min read

Setting up a GCC in Bengaluru

The centres that work are the ones given real ownership of something. The ones that struggle were set up to execute decisions made elsewhere, and staffed accordingly.

Read article
India or Eastern Europe for development

We build software in India, so read this knowing where it comes from. The comparison is worth making honestly anyway, because a buyer who picks the wrong geography for their situation ends up unhappy with a supplier who was never going to fit, and that helps nobody. The decision turns on three things: the time zone you need to work in, the size of team you need, and how specialised the skills are.

Keep reading
Cloud

Aug 14, 2026 2 min read

India or Eastern Europe for development

We are an Indian firm, so treat this with appropriate suspicion — but the honest comparison has more to do with team size and time zones than with skill.

Read article
AWS, Azure or Google Cloud for an Indian company

Every few months a team asks us to compare the three major clouds so they can choose correctly. The honest answer is that for the overwhelming majority of Indian businesses, all three will run the workload competently, all three have multiple Indian regions, and the feature differences that generate the most argument are the ones that matter least to the decision. AWS operates regions in Mumbai and Hyderabad, Microsoft Azure has regions across western, central and southern India, and Google Cloud runs regions in Mumbai and Delhi. Data residency, for most purposes, is satisfied by any of them.

Keep reading
Cloud

Aug 14, 2026 2 min read

AWS, Azure or Google Cloud for an Indian company

All three have Indian regions, all three will run your workload, and the technical comparison is mostly a distraction from the two things that actually decide it.

Read article
Document processing with AI: what works

Pulling structured fields out of invoices, purchase orders, contracts, claim forms and bank statements is one of the few AI applications with an obvious and immediate return, which is why every organisation with a back office is trying it. It is also an area where the demo is dramatically easier than the product, and the gap between them catches out teams who judged feasibility from the demo.

Keep reading
AI

Aug 14, 2026 2 min read

Document processing with AI: what works

Extraction demos are easy and extraction products are hard, and the difference is entirely about what happens to the ten per cent the model gets wrong.

Read article
Building a lending app under the 2025 Directions

The RBI issued the Digital Lending Directions, 2025 on 8 May 2025, consolidating years of scattered guidance into one framework. Most provisions took effect immediately, the requirement to register digital lending applications with the RBI through the CIMS portal applied from 15 June 2025, and the rules governing multi-lender arrangements applied from 1 November 2025. If you are building or maintaining a lending product, this is the document your architecture is judged against.

Keep reading
Security

Aug 14, 2026 2 min read

Building a lending app under the 2025 Directions

Money must move directly between the borrower and the lender's account, with no intermediary in the path. That one rule invalidates a large number of otherwise sensible product designs.

Read article
Aadhaar eKYC: what you can actually use

The single most common misconception in Indian product onboarding is that Aadhaar verification is a service you sign up for. It is not. Online Aadhaar authentication is restricted to entities licensed as Authentication User Agencies, Know Your Customer User Agencies or sub-KUAs under the UIDAI framework, and that licensing is generally available to regulated entities rather than to private companies at large. A software product that is not itself a bank, NBFC or similarly notified entity cannot independently authenticate against the Aadhaar database, however many vendors offer to arrange it.

Keep reading
Security

Aug 14, 2026 2 min read

Aadhaar eKYC: what you can actually use

Most private companies cannot perform Aadhaar authentication at all. Knowing which door is open to you before designing the onboarding flow saves a rebuild.

Read article
ABDM integration for health software

The Ayushman Bharat Digital Mission is India's national digital health framework, with the National Health Authority acting as certifying body. For anyone building or selling hospital or clinic software here, ABDM compliance has moved from optional differentiator to procurement requirement, and the integration is a larger piece of work than most vendors budget for.

Keep reading
AI

Aug 14, 2026 2 min read

ABDM integration for health software

Certification is per-software but deployment is per-facility, and confusing the two is why hospital rollouts stall after the vendor declares success.

Read article
Selling software to government through GeM

The Government e-Marketplace is the unified portal through which central and state government bodies and public sector undertakings buy, and it has removed most of the intermediary layer that used to sit between a vendor and a public buyer. For an Indian IT firm it is a substantial addressable market that requires no relationship-building to enter — only registration and the patience to learn how procurement actually works there.

Keep reading
Cloud

Aug 14, 2026 2 min read

Selling software to government through GeM

The registration is free and takes an afternoon. What takes longer is understanding that above five lakh rupees you are entering a reverse auction, and pricing accordingly.

Read article
How Indian SaaS companies bill overseas

An Indian SaaS company selling abroad has two problems that a domestic one does not: getting paid in another currency, and proving to the Indian system that the payment was what you say it was. Founders usually solve the first and discover the second at the end of the financial year, when someone asks for documentation that nobody was collecting.

Keep reading
Cloud

Aug 14, 2026 2 min read

How Indian SaaS companies bill overseas

Collecting the money is the easy half. Proving where it came from, in the right currency, with the right paperwork, is what determines whether your export status holds.

Read article
Preparing for technical due diligence

When an investor or acquirer sends in a technical diligence team, founders tend to prepare by trying to make the codebase look good. This is the wrong preparation and it is also impossible in the available time. Diligence teams have seen many codebases and expect none of them to be clean. What they are actually assessing is whether the engineering leadership has an accurate picture of their own system, because a team that knows its weaknesses can be planned around and a team that does not cannot.

Keep reading
Cloud

Aug 14, 2026 2 min read

Preparing for technical due diligence

Nobody expects a clean codebase. They expect you to know where the problems are, which is a completely different and much easier bar to clear.

Read article
ESOPs for an Indian engineering team

Equity is offered to Indian engineers far more often than it is understood by them, and the gap does most of the damage. A grant letter with a number of options, a strike price and a vesting schedule means very little to someone who has not been through a liquidity event, and a company that treats the grant as self-explanatory usually finds that it neither retains nor motivates. Explaining the instrument properly is not a legal task, it is a management one.

Keep reading
Cloud

Aug 14, 2026 2 min read

ESOPs for an Indian engineering team

An option grant that the recipient cannot value, cannot exercise affordably and cannot sell is not compensation. It is a document.

Read article
What a fractional CTO actually does

A company with a product but no senior technical leadership has a specific and expensive problem: decisions with long consequences are being made by people optimising for this week. Which platform, which architecture, which vendor, which hire, what to build in-house — each gets settled by whoever is nearest, and the cost arrives eighteen months later. A fractional or part-time CTO exists to take those decisions, and understanding that is the difference between the arrangement working and it disappointing everyone.

Keep reading
Cloud

Aug 14, 2026 2 min read

What a fractional CTO actually does

Hired to write code, the arrangement fails. Hired to make decisions that keep costing you money to defer, it is one of the better-value roles a young company can buy.

Read article
Hiring engineers when you are not technical

A non-technical founder hiring their first engineers is being asked to judge something they cannot evaluate directly, and most respond in one of two unhelpful ways. Some outsource the judgement entirely to a recruiter, whose incentive is placement rather than fit. Others try to compensate by learning enough to run a technical interview, which produces a superficial screen that a well-prepared weak candidate passes and a strong quiet one fails. Neither works, and the way out is to stop trying to assess what you cannot.

Keep reading
Cloud

Aug 14, 2026 3 min read

Hiring engineers when you are not technical

You cannot assess technical depth and you should stop trying. You can assess reasoning, honesty and whether someone can explain things to you — and those predict more than you would expect.

Read article
Writing a software brief that gets good answers

Organisations often write a deliberately loose requirements document, reasoning that it invites suppliers to propose creative approaches. What it actually does is select for suppliers comfortable quoting on incomplete information — which is not the same population as suppliers who will deliver well. The careful ones either decline or price in the uncertainty, so you end up choosing between an optimistic number from someone guessing and a defensive number from someone hedging, with no basis to compare them.

Keep reading
Cloud

Aug 14, 2026 2 min read

Writing a software brief that gets good answers

A vague brief does not get you flexible proposals. It gets you proposals from firms willing to guess, which is a different and much worse selection.

Read article
DLT registration: why your OTPs are not arriving

Every Indian engineering team eventually hits the same bug: OTPs work in testing, work for some users, and vanish for others, while the SMS provider's dashboard reports successful delivery. The cause is almost always DLT. Under TRAI's TCCCPR 2018 regulation, telecom operators maintain a distributed ledger registry of who is allowed to send commercial messages, under what sender name, and with exactly what text. Outbound SMS is scrubbed against that registry in real time, and anything that does not match a registered template is blocked.

Keep reading
Cloud

Aug 14, 2026 2 min read

DLT registration: why your OTPs are not arriving

Indian carriers match your outgoing message against a pre-registered template character by character. Change one word and it is silently dropped, with a success response from your provider.

Read article
Recurring payments under the 2026 e-mandate rules

The Reserve Bank issued the Digital Payments – E-mandate Framework, 2026 on 21 April 2026, effective immediately, consolidating eight separate circulars issued between 2019 and 2024 into a single document. For anyone running a subscription business in India, this is now the reference. The substantive changes are modest — grievance redressal detail and card re-issuance mapping, plus adjustments from stakeholder feedback — but having one document instead of eight is itself worth the re-read.

Keep reading
Security

Aug 14, 2026 2 min read

Recurring payments under the 2026 e-mandate rules

The RBI consolidated eight circulars into one framework in April. If your subscription product was built against the older patchwork, the thresholds and notification rules are worth re-reading.

Read article
SEBI's CSCRF: what it asks of your systems

SEBI's Cybersecurity and Cyber Resilience Framework arrived as circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 on 20 August 2024, and has been amended twice since — on 30 April 2025 and 28 August 2025. It applies to twenty-two categories of regulated entity, spanning stock exchanges, clearing corporations, depositories, brokers, asset managers, custodians and alternative investment fund managers. If you build or operate software for any of them, the framework is now part of your delivery obligations whether or not it is named in the contract.

Keep reading
Security

Aug 14, 2026 2 min read

SEBI's CSCRF: what it asks of your systems

Which tier your client falls into decides almost everything — twice-yearly red teaming or an annual self-certification. Establishing that first prevents scoping the wrong project.

Read article
E-way bill integration: rules that bite

An e-way bill is required when a single consignment exceeds fifty thousand rupees in value, or when the aggregate value of consignments in one vehicle does. That is the interstate rule; intrastate thresholds vary by state, ranging from fifty thousand up to two lakh, which is the first thing an engineer discovers is not a single number. Normally the supplier generates it, but the recipient may where they transport goods themselves, and where an unregistered supplier sells to a registered buyer, compliance falls on the buyer.

Keep reading
Cloud

Aug 14, 2026 2 min read

E-way bill integration: rules that bite

Validity is computed from distance, Part B cannot be re-entered, and from August this year ship-to GSTIN became mandatory. Each of those is a design constraint, not a form field.

Read article
Low-code or custom: choosing honestly

We build custom software, so treat what follows accordingly — but the honest position is that a large share of what businesses ask us for should not be built from scratch. An internal approval workflow, a data collection form feeding a report, a lightweight CRM for a team of fifteen: building these bespoke is often an expensive way to arrive somewhere a configured platform reaches in a fortnight. Recommending against a project is occasionally the right recommendation.

Keep reading
Cloud

Aug 14, 2026 2 min read

Low-code or custom: choosing honestly

Low-code is genuinely faster until the moment it isn't, and the useful skill is recognising in advance which side of that line your project sits on.

Read article
Moving from services to a product

Almost every services firm eventually tries to build a product. The logic is sound: services revenue is linear in headcount, product revenue is not, and the team has already built the same thing four times for four clients. The attempt usually fails, and it fails in a consistent way that is worth understanding before starting rather than after.

Keep reading
Cloud

Aug 14, 2026 2 min read

Moving from services to a product

Services revenue funds the attempt and quietly kills it, because every month the highest-value use of an engineer's time is a client project rather than the product.

Read article
Replacing a process that runs on spreadsheets

A great deal of Indian business runs on spreadsheets that have grown for years — an order book, a production plan, a commission calculation, a reconciliation. When a company asks for software to replace one, the instinct is to treat the spreadsheet as a mess to be swept away. That is the wrong reading. It is the most accurate specification of the business process that exists anywhere in the organisation, including in anyone's head, and the first task is to read it properly rather than replace it quickly.

Keep reading
Cloud

Aug 14, 2026 2 min read

Replacing a process that runs on spreadsheets

The spreadsheet is not the problem to solve. It is the specification, and it is a better one than anything the client will write for you.

Read article
Designing SLAs that survive a bad month

Support agreements are usually negotiated in a comfortable moment and invoked in an uncomfortable one, which means the words matter far more than they seem to at signing. The most common defect is not a target that is too aggressive — it is a target that cannot be measured, or that measures something neither party actually cares about.

Keep reading
Cloud

Aug 14, 2026 2 min read

Designing SLAs that survive a bad month

An SLA everyone agrees to and nobody measures is not an agreement. It is a document that will be read for the first time during an argument.

Read article
Modelling Indian names, addresses and phones

Most data models used in Indian software were inherited from Western frameworks and encode assumptions that do not hold here. The failures are individually small and collectively constant: a name that will not save, an address that cannot be delivered to, a phone number rejected as invalid. Each generates a support ticket, and each is entirely avoidable at design time.

Keep reading
Cloud

Aug 14, 2026 2 min read

Modelling Indian names, addresses and phones

First name, last name, address line 1, ZIP. Four fields, four wrong assumptions, and every one of them produces a support ticket in India.

Read article
Running 24/7 support for global clients

Twenty-four hour support is one of the more attractive things an Indian firm can offer a Western client, because the time zone that complicates collaboration becomes an advantage the moment the requirement is coverage rather than conversation. It is also one of the easier commitments to sell and harder ones to run well, and the gap between the two shows up around month four.

Keep reading
Cloud

Aug 14, 2026 2 min read

Running 24/7 support for global clients

Selling round-the-clock support is easy. Staffing it so the night shift can actually resolve things, and so people stay, is the part that decides whether it works.

Read article
Tax collection and deduction obligations for e-commerce operators

An operator running a platform where other people sell picks up obligations that a direct seller does not have. Under GST there is a collection requirement on the value of supplies made through the platform; under income tax there is a deduction requirement on payments to participating sellers. Both are computed by the operator and both are reported by the operator.

Keep reading
Compliance

Aug 14, 2026 1 min read

Tax collection and deduction obligations for e-commerce operators

Running a marketplace makes you responsible for tax on other people's sales. That obligation has to be built into the payout engine, not bolted on.

Read article
A backup you have never restored is a hypothesis

Every organisation that has lost data had backups. The failure is almost never that no backup ran; it is that the backup did not contain what was needed, or could not be read, or took far longer to restore than anyone had assumed.

Keep reading
IT Services

Aug 14, 2026 2 min read

A backup you have never restored is a hypothesis

Backup jobs report success for years. The first genuine test is usually the worst possible day to discover a problem.

Read article
How to run technical due diligence on a development partner

Most selection processes evaluate a company through its sales function - a proposal, a capability deck, a reference call arranged by the vendor. All three are curated. Technical due diligence means evaluating the thing you are actually buying, which is a team's engineering judgement, and it takes about ninety minutes if you ask the right things.

Keep reading
IT Strategy

Aug 13, 2026 3 min read

How to run technical due diligence on a development partner

You can learn more from ninety minutes with a partner's engineers than from any proposal document…

Read article
Adding video calling: build, buy, or avoid

WebRTC makes a two-person video call surprisingly easy to prototype. Browsers handle capture, encoding and peer connection, and a working demo comes together quickly. That demo creates an expectation about effort that the rest of the work does not meet.

Keep reading
Engineering

Aug 13, 2026 2 min read

Adding video calling: build, buy, or avoid

The demo takes an afternoon. Everything after the demo is the project.

Read article
Software bills of materials: what buyers are starting to require

A software bill of materials is an inventory of the components in a piece of software — direct dependencies, transitive dependencies, versions and licences. The idea is old; the requirement to hand one over is new, and it is appearing in enterprise procurement and in regulated sectors.

Keep reading
Security

Aug 13, 2026 2 min read

Software bills of materials: what buyers are starting to require

A list of what is inside your software used to be an internal concern. It is increasingly a contractual deliverable.

Read article
What custom software actually costs in India in 2026

It is the first question every buyer asks and the one most development companies answer with a shrug and a discovery call. So here are the actual numbers. Rate surveys published across the Indian market in 2026 put junior developers (two to three years) at roughly $14-25 per hour depending on stack, mid-level engineers (three to six years) at $20-38, and senior engineers at $32-58. Full-stack sits at the upper end of each band. Specialists carry a premium: developers with production AI and LLM integration experience are commanding 25-40% above the equivalent general rate, which currently makes it the fastest-appreciating skill in the Indian market.

Keep reading
IT Strategy

Aug 12, 2026 3 min read

What custom software actually costs in India in 2026

Published rate cards give you an hourly number. Here's what actually determines the invoice, and how to compare two quotes that look nothing alike…

Read article
What a solution architect is actually for

In a services firm, the solution architect is the person who turns a client's stated problem into something that can be estimated, staffed and built. When the role works, projects start with a shared understanding of scope. When it does not, sales promises one thing and delivery discovers another.

Keep reading
Business

Aug 12, 2026 2 min read

What a solution architect is actually for

The role sits between sales and delivery, and both sides tend to misunderstand what it is meant to protect.

Read article
Charging for discovery, and why clients agree

Estimating a project properly takes real work — understanding the current systems, the constraints, the integrations, the people. Firms routinely do this unpaid, in the hope of winning the build. The cost is absorbed, the estimates are rushed because the work is unfunded, and the resulting number is the one everyone is held to.

Keep reading
Business

Aug 12, 2026 1 min read

Charging for discovery, and why clients agree

Free scoping is a subsidy paid by projects that close, on behalf of the ones that do not. A paid discovery phase changes the conversation on both sides.

Read article
What an MVP should and should not include

The phrase minimum viable product has been used loosely enough that it now means whatever the person saying it wants it to mean. To a founder under time pressure it means the cheapest version. To an engineer it often means the version without the difficult parts. Both readings produce something that answers no question, which is the only thing an MVP is actually for.

Keep reading
IT Strategy

Aug 11, 2026 3 min read

What an MVP should and should not include

Most MVPs fail for the opposite reason people expect - not too small, but too large in the wrong places…

Read article
Product analytics that does not send personal data to a third party

A standard analytics snippet, installed with defaults, captures page URLs, referrers, device details and often the contents of form fields and page elements. URLs frequently carry identifiers, email addresses and search terms. All of it goes to a third party, usually outside India.

Keep reading
Data

Aug 11, 2026 1 min read

Product analytics that does not send personal data to a third party

The default analytics setup collects more than most teams intend and sends it somewhere they have not thought about.

Read article
Getting GPU capacity for AI workloads in India

Teams starting AI work assume the question is cost. Often the first real obstacle is availability: the instance type you planned around is not available in the region you need, and the wait is measured in weeks.

Keep reading
AI

Aug 11, 2026 1 min read

Getting GPU capacity for AI workloads in India

Availability, not price, is usually the binding constraint — and the answer depends heavily on whether you are training or serving.

Read article
Dedicated team or project outsourcing: an honest comparison

There are two ways to buy engineering from an Indian partner, and they suit genuinely different situations. Project outsourcing means you define a piece of work and buy its delivery. A dedicated team means you rent engineers, month by month, and direct them yourself. Buyers usually compare the two on monthly cost, which is the least informative axis available.

Keep reading
IT Strategy

Aug 10, 2026 3 min read

Dedicated team or project outsourcing: an honest comparison

One model is cheaper per unit of work. The other is cheaper for work you can actually define. Most buyers pick by price and get it backwards…

Read article
Rolling out AI coding assistants without wrecking your codebase

AI coding assistants are now standard equipment on many teams. The measured effect on delivery speed varies widely between studies and between tasks, and the honest position is that the benefit is real for some work and marginal for other work. That uncertainty is a reason to roll out deliberately rather than not at all.

Keep reading
AI

Aug 10, 2026 1 min read

Rolling out AI coding assistants without wrecking your codebase

The productivity claims are contested. The governance questions are not, and they need answering before the licences are bought.

Read article
DNS: the single point of failure nobody owns

Ask who owns your domain registration and you will often get a pause. It was registered years ago, possibly by an agency, possibly on a personal credit card belonging to someone who has left. The renewal notice goes to an address nobody reads.

Keep reading
IT Services

Aug 10, 2026 1 min read

DNS: the single point of failure nobody owns

Every outage that takes down a company completely rather than partially tends to involve DNS, a lapsed registration, or an account nobody can log into.

Read article
The certificate expiry outage, and how to stop having it

TLS certificate expiry is one of the few outages with a known date in advance. It still catches organisations regularly, because the certificate that expires is rarely the main website — it is an internal API, a load balancer health check, a client certificate on an integration, or a mail server.

Keep reading
Engineering

Aug 9, 2026 1 min read

The certificate expiry outage, and how to stop having it

It is entirely preventable, it happens to everyone, and it always happens on the certificate nobody remembered existed.

Read article
Protecting your brand online without a large budget

A convincing imitation of your company costs an attacker a domain registration and an afternoon. The variants that matter are the ones a customer would not scrutinise: a hyphen added, a letter doubled, a different top-level domain, a homoglyph from another script.

Keep reading
Business

Aug 9, 2026 1 min read

Protecting your brand online without a large budget

Lookalike domains, fake profiles and cloned websites are cheap to create and cost the target real money in fraud and trust.

Read article
Integrating with point-of-sale systems in Indian retail

Point-of-sale integration is unforgiving because the failure is public. A slow response or an error is not a logged exception; it is a queue of customers watching a cashier apologise. That constraint should shape every design decision.

Keep reading
Engineering

Aug 8, 2026 1 min read

Integrating with point-of-sale systems in Indian retail

The counter is where the software meets reality: a queue, a card machine, a printer and a person who cannot wait for your API.

Read article
Knowing what stock you have, across every branch

A business with several branches usually knows how much stock each holds, on paper. Whether that number is accurate enough to tell a customer 'yes, we have it' is a different question, and the gap between the two is where the commercial value sits.

Keep reading
Business

Aug 8, 2026 1 min read

Knowing what stock you have, across every branch

Most multi-location businesses have inventory data. Few have inventory they trust enough to promise a customer.

Read article
Modernising a legacy system without betting the company on a rewrite

Every legacy system reaches a point where someone proposes replacing it. The argument is always persuasive: the code is unmaintainable, nobody understands it, each change takes weeks, and a clean rebuild on modern foundations would take eighteen months. The trouble is that the eighteen months is measured against a specification nobody has written, for a system whose behaviour nobody fully knows, while the original keeps changing underneath. Full rewrites are the most commonly attempted and most commonly abandoned modernisation strategy there is.

Keep reading
IT Strategy

Aug 07, 2026 3 min read

Modernising a legacy system without betting the company on a rewrite

The full rewrite is the most tempting option and the one that fails most often. There is a slower route that actually finishes…

Read article
Integrating your product with Indian accounting systems

Any business software that touches money eventually meets the question of how data reaches the accounting system. In India that usually means Tally, and increasingly also cloud packages such as Zoho Books, or an ERP for larger organisations. The integration effort varies enormously between them.

Keep reading
Engineering

Aug 7, 2026 2 min read

Integrating your product with Indian accounting systems

Whatever you build, the finance team will want it in their accounting package. How hard that is depends entirely on which package.

Read article
Choosing a customer support desk

Support desk software is a crowded market where every product demonstrates well. Freshdesk, Zoho Desk and Zendesk all handle a ticket competently. The decision usually comes down to channels, reporting and cost at your actual volume.

Keep reading
IT Services

Aug 7, 2026 1 min read

Choosing a customer support desk

The tools look similar in a demo. The differences that matter emerge at volume, in reporting, and in what happens to email threads.

Read article
Multi-tenant SaaS: the four decisions you cannot reverse cheaply

Building a SaaS product is a different discipline from building software, and the difference is concentrated in a handful of early decisions. They are easy to make casually because at one tenant they appear not to matter. By the fiftieth tenant, and particularly by the first enterprise buyer, they determine whether the platform grows or gets rebuilt.

Keep reading
IT Strategy

Aug 06, 2026 3 min read

Multi-tenant SaaS: the four decisions you cannot reverse cheaply

Most SaaS rewrites are caused by four choices made in the first month, usually without anyone realising a choice was being made…

Read article
API gateway, service mesh, or neither

An API gateway handles traffic arriving from outside — authentication, rate limiting, routing, request shaping. A service mesh handles traffic between your own services — encryption, retries, observability, traffic shifting. North-south and east-west, in the usual shorthand.

Keep reading
Engineering

Aug 6, 2026 1 min read

API gateway, service mesh, or neither

They solve different problems, they are frequently confused, and most teams need at most one of them.

Read article
Deciding which browsers and devices you support

Every team has a support matrix. Most have never written it down, which means it is whatever the developers happen to test on — recent Chrome on a good laptop — and everything else works by luck.

Keep reading
Engineering

Aug 6, 2026 1 min read

Deciding which browsers and devices you support

An unwritten support matrix means you support everything badly. A written one is a business decision with a cost attached.

Read article
India's DPDP Rules: what the 2026 and 2027 deadlines mean for your systems

India's Digital Personal Data Protection Rules were notified on 14 November 2025, starting an eighteen-month transition that ends on 13 May 2027. Between those two dates sit deadlines that most companies have not put in a plan, and penalties at the end of it reaching up to ₹250 crore for serious violations. The reason to act now is not the final date - it is that the engineering work involved has a longer lead time than the calendar suggests.

Keep reading
Security

Aug 05, 2026 3 min read

India's DPDP Rules: what the 2026 and 2027 deadlines mean for your systems

The soft-enforcement window closes this November. Most of the engineering work takes longer than the time remaining…

Read article
Testing on real devices without buying fifty phones

Emulators and simulators are fast, scriptable and essential for the development loop. They are also uniformly well-behaved, well-resourced and running recent software, which is exactly what your users' devices are not. A test suite that passes only on emulators is testing the code, not the product.

Keep reading
Engineering

Aug 5, 2026 2 min read

Testing on real devices without buying fifty phones

Emulators tell you the code runs. They do not tell you what happens on a three-year-old handset with low storage and an aggressive battery manager.

Read article
Fine-tuning, RAG or prompting: choosing the right one

Three techniques get proposed for almost every LLM problem, and they solve genuinely different failure modes. Choosing wrongly is expensive - not because the wrong one fails loudly, but because it half-works, which is worse. The distinction is easier to hold if you frame each one by the deficiency it corrects.

Keep reading
Data & AI

Aug 04, 2026 3 min read

Fine-tuning, RAG or prompting: choosing the right one

Teams reach for fine-tuning when they need retrieval, and retrieval when they need a better prompt. The decision is simpler than it looks…

Read article
Replacing nightly CSV files with real integration

In most companies of any age there is a scheduled job that writes a file, drops it somewhere, and another job that picks it up and loads it. It was the pragmatic answer when it was built and it has run for years. It is also, usually, the least observable and most failure-prone part of the estate - and the failures are silent, which is the part that costs money.

Keep reading
Cloud

Aug 03, 2026 3 min read

Replacing nightly CSV files with real integration

The batch file that runs at 2am is the most fragile thing in most enterprises, and the only one nobody is watching…

Read article
What SOC 2 actually costs an Indian company, and how long it takes

SOC 2 usually enters the conversation the same way: a large customer sends a security questionnaire, somewhere in it is a request for a SOC 2 report, and the deal stops moving. What follows is a fortnight of vendors quoting wildly different numbers and nobody explaining what the money is for. Here is the whole budget, broken into its parts, at 2026 Indian market rates.

Keep reading
Security

Jul 31, 2026 3 min read

What SOC 2 actually costs an Indian company, and how long it takes

Your first enterprise buyer asks for it, and nobody will tell you a number. Here is the full budget, line by line…

Read article
When you need a mobile app, and when a web page will do

The decision to build a native app is usually made before anyone examines whether it is necessary. Someone senior observes that competitors have one, or that customers are on phones, and the requirement arrives fully formed. But a mobile web experience and a native app cost very different amounts, carry very different maintenance burdens, and only one of them requires app store approval for every change. It is worth ten minutes of examination.

Keep reading
IT Strategy

Jul 30, 2026 3 min read

When you need a mobile app, and when a web page will do

Building an app costs several times what a mobile web experience costs, and about half the time it buys nothing…

Read article
12 questions to ask before hiring a software development company

Choosing a development partner is a decision made with very little information, usually under time pressure, by someone who will have to live with the consequences for years. Price, timeline and technology stack dominate the conversation because they are easy to compare across proposals. They are also the three things most likely to change. These are the questions we would ask instead, and we include them knowing they are uncomfortable to answer.

Keep reading
IT Strategy

Jul 29, 2026 3 min read

12 questions to ask before hiring a software development company

Most buyers ask about price, timeline and tech stack. The answers that actually predict how the project goes come from somewhere else…

Read article
The real cost of skipping automated tests

Automated testing is the first thing cut when a deadline tightens, and the reasoning is always the same: the feature is what the customer wants, tests are overhead, and we will add them later. It sounds like a trade of quality for speed. In practice it is a trade of speed later for speed now, at a poor exchange rate, and the bill arrives within months rather than years.

Keep reading
IT Strategy

Jul 28, 2026 3 min read

The real cost of skipping automated tests

Skipping tests does not save time. It moves the time from before release to after, where it costs several times as much…

Read article
HIPAA for Indian teams building healthcare software

Indian teams building software for US healthcare clients hit the same confusion early: the client says the system must be HIPAA compliant, and there is no exam to sit, no certificate to purchase and no body that issues approval. HIPAA is a law with requirements, not a certification scheme, and the vendors selling HIPAA certificates are selling their own assessment rather than anything official. What your client actually needs is evidence that specific obligations are met.

Keep reading
Security

Jul 27, 2026 3 min read

HIPAA for Indian teams building healthcare software

There is no HIPAA certification to buy. What your US healthcare client actually needs from you is different, and more concrete…

Read article
AI agents: where they genuinely help, and where they are hype

The pitch for AI agents is that instead of coding a process, you describe a goal, give the model some tools, and let it work out the steps. In demonstrations this is genuinely impressive. In production it separates sharply into cases where it earns its place and cases where it is an unreliable reimplementation of something a workflow engine has done deterministically for twenty years.

Keep reading
Data & AI

Jul 24, 2026 3 min read

AI agents: where they genuinely help, and where they are hype

Agents are being proposed for processes that need a workflow engine and a model, not autonomy. The distinction decides whether it works…

Read article
What your RTO and RPO actually commit you to

Recovery time objective and recovery point objective appear in most enterprise contracts and disaster recovery policies, usually as numbers somebody chose because they sounded responsible. RTO is how long you may take to restore service after a failure. RPO is how much data you may lose, measured in time. Both are commitments, and both have an architecture and a cost attached that is rarely traced back before signing.

Keep reading
Cloud

Jul 23, 2026 2 min read

What your RTO and RPO actually commit you to

Two numbers get written into contracts by people who have never tested whether they are achievable. Here is what each one really costs…

Read article
Why companies build software in Bengaluru - and when they should not

Bengaluru gets described in marketing copy as the Silicon Valley of India, which is the kind of phrase that stops conveying information. The useful version is more specific: the city has an unusually deep concentration of engineers who have operated production systems at scale, because the global product companies, the Indian IT majors and a large startup ecosystem have all been hiring into the same talent pool here for three decades. That depth is the actual asset, and it is why the city is a reasonable default for work involving architecture rather than execution.

Keep reading
IT Strategy

Jul 22, 2026 3 min read

Why companies build software in Bengaluru - and when they should not

An honest look at what Bengaluru is genuinely good at, what it costs, and the situations where somewhere else is the better answer…

Read article
Why ERP implementations stall short of adoption

ERP programmes rarely fail in a way that produces a headline. Far more often the system goes live, the project is declared complete, and eighteen months later the real work is still happening in spreadsheets alongside an expensive licence. The technology functions; the organisation simply did not move onto it. The reasons repeat across companies and industries.

Keep reading
IT Strategy

Jul 21, 2026 2 min read

Why ERP implementations stall short of adoption

The software usually works. The organisation goes back to its spreadsheets anyway, and the reasons are consistent…

Read article
Working with an offshore team across time zones

Companies working with Indian teams for the first time expect the time difference to be the hard part. It rarely is on its own. The difficulties that actually surface are decision latency and handover quality, and both have practical fixes that have nothing to do with asking anyone to work unsociable hours.

Keep reading
IT Strategy

Jul 20, 2026 2 min read

Working with an offshore team across time zones

Time zone difference is usually blamed for problems that are really about handover quality and decision latency…

Read article
Adding an AI copilot to a product that already exists

Adding an assistant to an existing product looks like a self-contained feature and behaves like a cross-cutting one. The model is the easy part - an API call. What takes the time is everything around it: what the assistant is allowed to see, what it is allowed to do, how it gets enough context to be useful, and what happens when it is confidently wrong in front of a paying customer.

Keep reading
Data & AI

Jul 17, 2026 2 min read

Adding an AI copilot to a product that already exists

The hard part is not the model. It is permissions, context and knowing when the assistant should refuse…

Read article
How to evaluate an AI vendor's accuracy claims

Every AI vendor quotes an accuracy figure and almost none of them explain what it measures. The number is usually true and frequently meaningless, because accuracy is only defined relative to a dataset, a task and a definition of correct. Four questions convert the claim into something you can act on, and any vendor doing serious work will welcome them.

Keep reading
Data & AI

Jul 16, 2026 2 min read

How to evaluate an AI vendor's accuracy claims

Ninety-five per cent accurate is not a fact until you know on what data, against whose answers, and measured how…

Read article
What Indian manufacturers get wrong about industrial IoT

Industrial IoT programmes on Indian factory floors tend to follow a recognisable arc: sensors are installed, a dashboard appears, executives are shown live machine data, and then nothing changes. Output is the same, downtime is the same, and eighteen months later the dashboard is open on a screen nobody looks at. The failure is almost never the sensors.

Keep reading
Cloud

Jul 14, 2026 2 min read

What Indian manufacturers get wrong about industrial IoT

Most IIoT projects collect enormous quantities of data and change no decision. The gap is not sensors…

Read article
What a cloud migration actually costs, and how to budget one

Cloud migration budgets fail in a specific way: the number covers moving the workloads and nothing else, and the project then spends its contingency on the parts nobody costed. So it is worth starting from what published 2026 figures actually say, and then being precise about what those figures do and do not include.

Keep reading
Cloud

Jul 13, 2026 3 min read

What a cloud migration actually costs, and how to budget one

Published per-workload figures are real but easy to misread. Here is what they include, what they leave out, and how the number changes in India…

Read article
Penetration testing: what it costs and how often you need it

Ask three firms to price a penetration test on the same web application and the quotes will differ by a factor of ten. That is not a market inefficiency you can arbitrage. At the bottom of that range you are buying an automated scanner report with a cover page, and at the top you are buying a senior tester spending two weeks trying to break your authorisation logic. Knowing which you are being offered is the entire skill in buying this.

Keep reading
Security

Jul 10, 2026 4 min read

Penetration testing: what it costs and how often you need it

Quotes for the same scope range from ₹25,000 to ₹4 lakh. The spread is not negotiating room — it is different work…

Read article
What a data warehouse costs to build and to run

Warehouse pricing looks transparent - every vendor publishes rates - and is in practice one of the harder things to forecast, because what you pay depends on how the thing is used rather than how much data you hold. It is worth starting with the published rates, then being clear about which of them actually drive a bill.

Keep reading
Data & AI

Jul 09, 2026 3 min read

What a data warehouse costs to build and to run

The platform bill is usually the smallest line. Here is where the money actually goes…

Read article
What it costs to run an LLM feature in production

Costing an LLM feature starts easy and gets difficult fast. The published rates are public and precise. What is not public - and this is the finding worth leading with - is almost everything downstream of them. When we went looking for citable figures on tokens consumed per request, or cost per user per month, we found that essentially every number in circulation traces back to blog posts performing arithmetic on the same public price lists. There is no observed data. Anyone quoting you a benchmark for cost per user is quoting a model, not a measurement.

Keep reading
Data & AI

Jul 07, 2026 4 min read

What it costs to run an LLM feature in production

Published token prices are the easy part. The numbers everyone quotes for cost per user are, on inspection, nobody's real data…

Read article
Hiring engineers in Bengaluru: what the market actually costs

Any figure you read for engineering salaries in Bengaluru depends almost entirely on who was counted. Indeed puts the average software engineer at around ₹10.4 lakh from 5,700 self-reported salaries. Recruitment platform data covering eight thousand tech roles puts engineers with two to three years at a product company between ₹14 and ₹28 lakh. Neither is wrong. Job-board data skews towards IT services and junior roles and usually captures base pay only; platform offer data captures active switchers at product companies and includes variable and equity. Mixing them produces nonsense, and a lot of published comparison is exactly that.

Keep reading
IT Strategy

Jul 06, 2026 3 min read

Hiring engineers in Bengaluru: what the market actually costs

Job boards and offer data disagree by a factor of two, and both are right about different populations…

Read article
Monolith or microservices: choosing honestly

The microservices decision is usually made for the wrong reason, which is that the codebase has become unpleasant to work in. Splitting it into services does make each piece smaller. It also converts every function call that crossed a module boundary into a network call that can fail, time out, or arrive twice, and it converts every schema change into a coordination problem between teams. You have not removed the complexity; you have moved it somewhere harder to debug.

Keep reading
IT Strategy

Jul 03, 2026 2 min read

Monolith or microservices: choosing honestly

Most teams that split into services were solving an organisational problem with an architectural tool, and got neither…

Read article
Do you actually need Kubernetes?

Kubernetes is genuinely good engineering that solves a genuine problem: running many containerised workloads across a fleet of machines, with automatic placement, self-healing and rolling updates. The question is not whether it works. It is whether the problem it solves is one you have, because the cost of running it is charged continuously and the benefit only arrives at a certain scale.

Keep reading
Cloud

Jul 02, 2026 2 min read

Do you actually need Kubernetes?

It is excellent at a problem most companies do not have, and it charges rent whether or not you have it…

Read article
Choosing a database for a new product

The default answer for a new product is PostgreSQL, and the useful discussion is about when that default breaks rather than about comparing feature matrices. Postgres handles relational data, JSON documents, full-text search, geospatial queries and vector similarity in one system, with transactions and constraints that stop bad data existing in the first place. Most products never outgrow it, and the ones that do outgrow one specific dimension of it rather than the whole thing.

Keep reading
IT Strategy

Jun 30, 2026 2 min read

Choosing a database for a new product

Start with Postgres. The interesting question is what would have to be true for that to be wrong…

Read article
Zero-downtime database migrations

Most database changes that cause outages do so because the schema and the application changed together. For a moment during deployment, old code is running against a new schema, or new code against an old one, and one of those combinations does not work. The technique that removes this entire class of failure is to make every change backwards compatible and to deploy it in stages, so that at no point is any running version of the code incompatible with the schema it sees.

Keep reading
Cloud

Jun 29, 2026 2 min read

Zero-downtime database migrations

The trick is never changing schema and code at the same time. Everything else follows from that…

Read article
Event-driven architecture: the pitfalls nobody mentions

Events decouple producers from consumers, and that is a genuine benefit: a service can publish that something happened without knowing or caring who reacts. The cost, which is rarely discussed with the same enthusiasm, is that no single place in the system describes what happens when an order is placed. The behaviour is distributed across every consumer, and understanding it means reading all of them.

Keep reading
IT Strategy

Jun 26, 2026 2 min read

Event-driven architecture: the pitfalls nobody mentions

Decoupling services is easy. Understanding what the system did last Tuesday is the hard part…

Read article
Caching: where it helps and where it hides bugs

Caching is the most reliably effective performance tool available and the one most likely to introduce a bug nobody can reproduce. Both facts come from the same property: a cache makes the system serve data that was true at some point rather than data that is true now. Whether that is fine or catastrophic depends entirely on the data, and that judgement is the whole discipline.

Keep reading
Cloud

Jun 25, 2026 2 min read

Caching: where it helps and where it hides bugs

A cache added to fix a slow query usually converts a performance problem into a correctness problem…

Read article
What "AI-first" actually means (and what it doesn't)

"AI-first" has become one of those phrases every vendor slaps on a homepage, which means it's mostly stopped meaning anything. So here's our operational definition, the one we actually hold ourselves to on every engagement: before we scope any project, we ask what part of it should be automated or augmented with AI, and we only rule it out after that question has a real answer - not by default.

Keep reading
AI

Jun 24, 2026 1 min read

What "AI-first" actually means (and what it doesn't)

Every vendor claims to be AI-first now. Here's the operational definition we actually hold ourselves to…

Read article
API versioning and deprecation done properly

Most API versioning discussions are about where the version goes - the URL, a header, a media type - which is the least consequential decision in the whole area. The consequential one is what you commit to when you publish version one, because every version you have ever released is a version you are maintaining until you can prove nobody uses it.

Keep reading
IT Strategy

Jun 23, 2026 2 min read

API versioning and deprecation done properly

Versioning is easy to add and almost impossible to remove. The discipline is in the retirement, not the release…

Read article
Vendor lock-in: the real risks and the imagined ones

Lock-in anxiety produces some of the most expensive architecture decisions in enterprise software: abstraction layers over cloud services, self-hosted alternatives to managed ones, portability requirements that constrain every design. The anxiety is not baseless, but it is usually pointed at the wrong things. Some dependencies are genuinely hard to leave; others are trivial and get treated as though they were not.

Keep reading
Cloud

Jun 22, 2026 2 min read

Vendor lock-in: the real risks and the imagined ones

Avoiding lock-in has its own price, usually paid in complexity you carry forever against a migration you never do…

Read article
Observability: what to instrument first

Observability tooling is easy to buy and easy to misapply. A common end state is a large monthly bill, dashboards nobody consults, alerts everyone has muted, and an incident where the first twenty minutes go on establishing what is actually wrong. The problem is almost never volume of data. It is that the wrong things were measured, in a form that cannot answer questions.

Keep reading
Cloud

Jun 19, 2026 2 min read

Observability: what to instrument first

Most teams have plenty of data and still cannot answer why it broke. The gap is what got measured, not how much…

Read article
Incident response for teams without an SRE

Published incident management frameworks assume a dedicated reliability team, a rota of incident commanders and a war room. Most companies running important software have none of those, and conclude that incident process is for larger organisations. The conclusion is wrong: four practices deliver nearly all the benefit and none of them requires a specialist.

Keep reading
Cloud

Jun 18, 2026 2 min read

Incident response for teams without an SRE

Most published incident process assumes a team you do not have. Four things make the difference at small scale…

Read article
On-call without burning out the team

On-call is where reliability practice meets human cost, and the cost is usually paid quietly until someone resigns. The failure is rarely the existence of a rota. It is a rota where the pages are frequent, unactionable, or arrive for systems the person on duty has no ability to fix, and where the hours spent awake at night are treated as free.

Keep reading
Cloud

Jun 16, 2026 2 min read

On-call without burning out the team

A rota that wakes people for things they cannot fix is how good engineers decide to work somewhere else…

Read article
Feature flags and progressive delivery

The single most useful idea in modern delivery is that deploying code and releasing a feature are different events. Deploy the code dark, behind a flag that is off. Turn it on for yourself, then for a few per cent of users, then for everyone - and turn it off in seconds if something is wrong. That decouples the risky moment from the deployment, and it is why teams that do this can deploy on a Friday afternoon without anyone becoming tense.

Keep reading
IT Strategy

Jun 15, 2026 2 min read

Feature flags and progressive delivery

Separating deploy from release removes most of the fear from shipping — and creates a mess if nobody cleans up…

Read article
Is your data actually ready for AI? A 6-point readiness audit

Almost every stalled AI project we're brought in to rescue has the same root cause, and it's not the model. It's that nobody checked whether the data underneath could actually support what leadership wanted to build. Here's the six-point audit we run before scoping any AI engagement.

Keep reading
AI

Jun 12, 2026 1 min read

Is your data actually ready for AI? A 6-point readiness audit

Most failed AI projects fail before a single model gets trained - because the data underneath was never checked…

Read article
Secrets management: the basics done properly

Almost every organisation has secrets in places they should not be, and almost every one believes it does not. The reason is that secrets spread by ordinary, reasonable actions: an engineer pastes a connection string into a chat to unblock a colleague, a config file gets committed during a rush, a credential is emailed to a contractor. None of these are negligence. They are what happens without a mechanism that makes the right path easier than the wrong one.

Keep reading
Security

Jun 11, 2026 2 min read

Secrets management: the basics done properly

The credential in the repository is the one you know about. The interesting question is which ones you do not…

Read article
Quantifying technical debt so it gets budgeted

Technical debt conversations fail in a predictable way. Engineering says the codebase is a mess and changes are painful; leadership hears a preference for tidiness competing against customer features, and chooses the features. The problem is not that leadership is short-sighted. It is that one side is speaking in adjectives and the other budgets in numbers.

Keep reading
IT Strategy

Jun 09, 2026 2 min read

Quantifying technical debt so it gets budgeted

Engineers describe it in adjectives and finance hears complaining. Translate it into time and it becomes a line item…

Read article
Code review that actually catches things

Code review in most teams has drifted into two failure modes at once: a rubber stamp on large changes nobody has capacity to read properly, and a pile of comments about naming and formatting on small ones. Both feel like process and neither catches the defects that matter. Fixing it is mostly about removing what machines should do and being explicit about what humans are for.

Keep reading
IT Strategy

Jun 08, 2026 2 min read

Code review that actually catches things

Most review comments are about formatting, which a tool should be doing. The valuable review asks different questions…

Read article
Documentation that survives the team that wrote it

Almost every team has documentation that is out of date, and concludes that documentation does not work. What actually failed is a particular kind of documentation: the kind that describes what the code does. That is guaranteed to rot, because the code changes and the prose does not, and a wrong document is worse than none because someone will trust it.

Keep reading
IT Strategy

Jun 05, 2026 2 min read

Documentation that survives the team that wrote it

Most documentation rots because it explains what the code already says. Write down the things code cannot express…

Read article
Why estimates fail on existing systems

Most teams are roughly competent at estimating greenfield work and reliably terrible at estimating changes to a system that already exists. The gap is not discipline, it is information. On new work you are estimating construction, which you can decompose. On existing systems you are estimating discovery, and you cannot decompose what you have not found yet.

Keep reading
IT Strategy

Jun 04, 2026 2 min read

Why estimates fail on existing systems

Teams estimate new work reasonably well and existing-system work badly, and the reason is structural…

Read article
How to choose a managed IT services partner: a founder's checklist

Every founder we talk to compares managed IT vendors on the same two axes: price and SLA response time. Those matter, but they're table stakes - they don't predict whether the relationship will still be working in year three.

Keep reading
IT Strategy

Jun 03, 2026 1 min read

How to choose a managed IT services partner: a founder's checklist

Most vendor comparisons focus on price and SLAs. The questions that actually predict a good partnership look different…

Read article
Accessibility: why it turns up in procurement

For most Indian product teams, accessibility arrives as a question in an enterprise procurement pack: does your product conform to WCAG 2.2 AA, and can you provide a conformance report. It is at that moment - deal in progress, months of work required - that teams discover accessibility is a design constraint rather than a feature, and that retrofitting it into a mature interface is among the more expensive corrections in software.

Keep reading
IT Strategy

Jun 02, 2026 2 min read

Accessibility: why it turns up in procurement

Most Indian teams first meet WCAG in a buyer's questionnaire, at the point where retrofitting is most expensive…

Read article
Core Web Vitals and performance budgets

Web performance discussions go wrong when everyone tests on a developer laptop, on office fibre, with a warm cache. Your actual visitors are frequently on a mid-range Android phone on mobile data with a cold cache, and the gap between those two experiences is a factor of five or more. Google's Core Web Vitals matter partly because they are a ranking signal, and mostly because they measure the second situation rather than the first.

Keep reading
IT Strategy

Jun 01, 2026 2 min read

Core Web Vitals and performance budgets

Your site is fast on your laptop and slow for the people you are trying to reach. Those are different measurements…

Read article
Build vs. buy: when a custom AI system beats an off-the-shelf tool

Every week there's a new SaaS tool promising to solve a workflow with AI out of the box. Sometimes that's the right call - and we'll tell a client to just buy the tool when it is. But there's a specific set of conditions where a custom-built system is worth the extra investment, and it's worth being precise about them rather than defaulting to either extreme.

Keep reading
AI

May 29, 2026 1 min read

Build vs. buy: when a custom AI system beats an off-the-shelf tool

The SaaS AI tools market is flooded. Here's the decision framework we walk clients through before recommending either path…

Read article
Background jobs: queues, retries and the work nobody sees

Every application of any size ends up with work that happens outside a request: sending email, generating reports, processing uploads, calling a slow third party. It is the least-observed part of most systems, because nobody is waiting for it and nothing obviously breaks when it fails. That combination is exactly why it is where quiet, expensive bugs accumulate.

Keep reading
Cloud

May 28, 2026 2 min read

Background jobs: queues, retries and the work nobody sees

The request path gets all the monitoring. The job queue is where the silent data-loss bugs live…

Read article
Rate limiting: protecting an API without blocking real users

Rate limiting exists to stop one caller consuming capacity everyone else needs - whether that caller is malicious, a runaway script, or an enthusiastic integration partner who wrote a loop without a delay. The difficulty is that the limit has to be low enough to protect you and high enough that legitimate heavy users never notice, and most teams set it by picking a round number.

Keep reading
Cloud

May 26, 2026 2 min read

Rate limiting: protecting an API without blocking real users

A limit set by guesswork either lets the abuse through or blocks your best customer. Both happen for the same reason…

Read article
Why your query is slow: reading an execution plan

When a query is slow, the common response is to add an index to whatever column appears in the WHERE clause and hope. Sometimes that works. Often it adds write cost and storage for no read benefit, because the planner was never going to use it. The database will tell you what it is actually doing if you ask, and asking takes one keyword.

Keep reading
Cloud

May 25, 2026 2 min read

Why your query is slow: reading an execution plan

Adding an index is the usual guess. Reading the plan tells you whether it would have helped…

Read article
Why most RAG chatbots hallucinate - and how we fix it

Retrieval-augmented generation (RAG) is pitched as the fix for LLM hallucination: ground the model in your own documents, and it can only answer from what's true. In practice, most RAG chatbots we're brought in to fix still hallucinate - just less obviously.

Keep reading
Data & AI

May 22, 2026 1 min read

Why most RAG chatbots hallucinate - and how we fix it

Retrieval-augmented generation is supposed to ground answers in your data. Here's why it still goes wrong, and what actually works…

Read article
Sessions or tokens: choosing how to authenticate

Somewhere in the last decade, JSON Web Tokens became the reflexive answer for authentication in new applications, including a great many that would have been better served by an ordinary session cookie. The reasoning offered is usually that tokens are stateless and therefore scale. The reasoning is true and the conclusion often does not follow, because statelessness is precisely what makes the hard problem hard.

Keep reading
Security

May 21, 2026 2 min read

Sessions or tokens: choosing how to authenticate

JWTs became the default answer to a question most applications were not asking…

Read article
File uploads: doing it properly at scale

The obvious way to accept a file is to post it to your application server, which validates it and writes it to storage. It works, it is easy to reason about, and it becomes a problem the moment files are large or users are numerous - because every upload occupies a request thread for its entire duration, and a hundred people uploading video on a slow connection can exhaust your server while it does no computation at all.

Keep reading
Cloud

May 19, 2026 2 min read

File uploads: doing it properly at scale

Uploads through your application server are the design that works in testing and falls over on launch day…

Read article
How to measure AI ROI without fooling yourself

The most common AI ROI conversation we have starts with a client telling us a new AI tool "feels faster" or "the team loves it," and ends with us asking for a number a CFO would accept. Vibes don't survive a budget review. Here's the framework that does.

Keep reading
AI

May 18, 2026 1 min read

How to measure AI ROI without fooling yourself

"It feels faster" isn't a metric. Here's the measurement framework that survives a skeptical CFO…

Read article
Search relevance: why exact matching disappoints users

In-product search usually starts as a LIKE query against a name column, which works for the person who knows exactly what the item is called and fails for everyone else. That gap is the entire problem: users type approximations, synonyms, misspellings, plurals and partial memories, and the database holds precise strings. Search is the work of connecting the two.

Keep reading
Data & AI

May 15, 2026 2 min read

Search relevance: why exact matching disappoints users

Users do not type what is in your database. Bridging that gap is the whole of search…

Read article
Dates and time zones: the bugs that appear in October

Time is the area where reasonable-looking code is most often subtly wrong, and where the wrongness surfaces long after release - a report covering the wrong window, a subscription charged a day early, a scheduled job that runs twice or not at all on one particular Sunday. Indian teams have a slight blind spot here, because India has a single time zone and no daylight saving, so local testing never reveals the problems.

Keep reading
IT Strategy

May 14, 2026 2 min read

Dates and time zones: the bugs that appear in October

Time handling fails quietly, in production, months after release, usually on a Sunday morning in spring or autumn…

Read article
5 cloud migration mistakes that cost enterprises millions

Every quarter we get called in to rescue a cloud migration that went sideways. The patterns are remarkably consistent, and every one of them is avoidable with a little upfront discipline. What follows is the list we now walk through with every client before a single workload moves.

Keep reading
Cloud

May 12, 2026 3 min read

5 cloud migration mistakes that cost enterprises millions

The hidden pitfalls we see most often - and a practical checklist to avoid them before you move a single workload…

Read article
Pagination that does not skip or repeat rows

Every list endpoint needs pagination, and nearly every one starts with LIMIT and OFFSET because it is the obvious translation of page numbers. It has two problems, both of which appear only at scale, which is why they arrive as production bugs rather than review comments.

Keep reading
Cloud

May 11, 2026 2 min read

Pagination that does not skip or repeat rows

OFFSET works until the data changes underneath you, and gets slower the deeper anyone goes…

Read article
AI governance doesn't need to be a committee - a lightweight framework for mid-market teams

Most AI governance frameworks are written for organizations with a dedicated AI ethics board and a compliance headcount most mid-market companies don't have. That doesn't mean governance is optional - ungoverned AI is how a well-intentioned pilot turns into a data-leak incident or a discrimination complaint. It means the framework needs to fit the team you actually have.

Keep reading
AI

May 08, 2026 1 min read

AI governance doesn't need to be a committee - a lightweight framework for mid-market teams

Enterprise AI governance frameworks assume a team you don't have. Here's what actually matters at mid-market scale…

Read article
Soft deletes: convenient, and a slow-growing problem

Soft deletion - marking a row as deleted rather than removing it - is one of the most common patterns in application databases, and one of the least examined. It solves a genuine problem: users delete things by mistake, and support wants to undo it. It also changes the meaning of every query in the system, and that consequence is rarely priced in at the time.

Keep reading
Data & AI

May 07, 2026 2 min read

Soft deletes: convenient, and a slow-growing problem

A deleted_at column is the easiest thing to add and the hardest thing to reason about two years later…

Read article
What an hour of downtime actually costs a mid-market company

When we ask clients what an hour of downtime costs them, most give a number that's either a guess or a figure from an old board deck. That's a problem, because it's the number that should be justifying every dollar spent on redundancy, monitoring, and incident response - and a guessed number leads to underinvestment.

Keep reading
Cloud

May 05, 2026 1 min read

What an hour of downtime actually costs a mid-market company

The number most teams use to justify uptime investment is guessed, not calculated. Here's how to actually model it…

Read article
Multi-region: when latency actually requires it

Multi-region deployment is proposed for two different reasons that need separating, because they have different solutions. One is latency: users far from your servers experience slow responses. The other is availability: you want to survive an entire region failing. Conflating them produces architectures that are expensive, complex, and no more reliable than what they replaced.

Keep reading
Cloud

May 04, 2026 2 min read

Multi-region: when latency actually requires it

Two regions can be less reliable than one, if the second was added without answering what the database does…

Read article
Calling third-party APIs without inheriting their outages

Every synchronous call to an external service is a dependency your availability is now multiplied by. Four services at 99.9% each, all required to serve a request, gives you 99.6% before your own code fails at anything. Most teams discover this arithmetic during an incident caused by a payment gateway or a mapping API rather than by anything they wrote.

Keep reading
Cloud

May 01, 2026 2 min read

Calling third-party APIs without inheriting their outages

Your uptime is capped by every service you call synchronously, unless you design for them failing…

Read article
Monorepo or many repos: choosing a code layout

The choice between a monorepo and many repositories is argued as a matter of taste, and it is really a question about where you want to pay for coordination. Splitting code across repositories makes each one simpler to reason about and makes any change crossing them considerably harder. Keeping everything together inverts that. Neither is free, and the right answer depends on facts about your own team that you can check, rather than on what a large technology company published about its setup.

Keep reading
IT Strategy

Apr 30, 2026 3 min read

Monorepo or many repos: choosing a code layout

The choice looks like taste and turns into tooling you will maintain for years…

Read article
Zero Trust in 2026: a practical roadmap for mid-market teams

Zero Trust has a branding problem: it sounds like a year-long, seven-figure re-platforming project, which is why most mid-market teams keep putting it in next year's budget. In reality it is a set of principles you can adopt incrementally - never trust, always verify, assume breach - and the order you adopt them in matters more than the tooling you buy.

Keep reading
Security

Apr 28, 2026 2 min read

Zero Trust in 2026: a practical roadmap for mid-market teams

Zero Trust doesn't have to mean rip-and-replace. Here's how to roll it out in phases that actually stick…

Read article
How to interview software engineers properly

Most advice on how to interview software engineers optimises for the wrong thing: it measures how somebody performs in an interview room rather than how they would do the job. Those correlate less than anyone would like. The gap produces expensive mistakes in both directions - people who interview well and cannot deliver, and people who would have been excellent and never got the chance to show it.

Keep reading
IT Strategy

Apr 27, 2026 2 min read

How to interview software engineers properly

Most loops measure interview performance rather than the work, and the gap is where the expensive mistakes come from…

Read article
Why your CI pipeline is slow, and what to fix

A slow CI pipeline is usually treated as an annoyance to tolerate, and it is better understood as a change to how the team works. When feedback takes long enough that people start something else while waiting, they stop integrating frequently, batch up larger changes, and review with less context. The queue is the visible symptom; the behaviour change is the real cost, and it appears on no dashboard.

Keep reading
IT Strategy

Apr 24, 2026 2 min read

Why your CI pipeline is slow, and what to fix

A slow CI pipeline does not merely waste minutes, it changes how often people are willing to integrate…

Read article
Infrastructure as code without the sprawl

The usual justification for infrastructure as code is automation, and that undersells it. The real value is that the environment you are debugging matches the one you deployed, and that the reason a thing exists is recorded in a file somebody can read. Manual infrastructure fails not because clicking is slow, but because knowledge of what was clicked, and why, leaves with the person who clicked it.

Keep reading
Cloud

Apr 23, 2026 3 min read

Infrastructure as code without the sprawl

The value is not automation, it is that the environment you debug matches the one you deployed…

Read article
Load testing that tells you something useful

Most load testing produces a green result and no information. A script hits a handful of endpoints with a traffic pattern nothing like production, the system survives, and everyone concludes it will scale. When it does not scale, the test is never blamed, because the test passed. Learning how to load test a web application usefully begins with accepting that the answer you want is not pass or fail, it is where the system stops behaving well and why.

Keep reading
Cloud

Apr 21, 2026 2 min read

Load testing that tells you something useful

Most load tests confirm that the system survives a shape of traffic it will never actually see…

Read article
Idempotency keys: making retries safe

Clients retry. Mobile applications on unreliable connections retry, gateways retry, load balancers retry on timeout, and users press the button again when nothing appears to happen. An idempotency key is how an API makes that safe, and designing for it is not optional politeness - the retries arrive whether or not you planned for them, and the second request is the one that charges the card twice.

Keep reading
Cloud

Apr 20, 2026 3 min read

Idempotency keys: making retries safe

The client will retry whether or not you designed for it, and the second request is the one that hurts…

Read article
Webhooks that arrive: delivery and receipt

Webhooks look like the simplest integration available: an event happens, you post it to a URL. Both ends turn out to be harder than that, and the characteristic failure is silence - the sender believes it delivered, the receiver never processed anything, and nobody notices until someone asks why an order never appeared. Building reliable webhooks is mostly a matter of accepting that delivery is uncertain and designing both sides accordingly.

Keep reading
Cloud

Apr 17, 2026 3 min read

Webhooks that arrive: delivery and receipt

Both ends of a webhook are harder than they look, and the characteristic failure is silence…

Read article
REST or GraphQL: choosing for a real team

The choice between REST and GraphQL is usually framed as modern against traditional, which is the least useful way to decide anything. They address different problems. GraphQL exists because some clients need to request varying shapes of data and cannot wait for a backend team to add an endpoint each time. Where that is not your situation, most of what it costs you buys nothing.

Keep reading
IT Strategy

Apr 16, 2026 3 min read

REST or GraphQL: choosing for a real team

The comparison is usually framed as modern against old, which is the least useful way to decide…

Read article
Why your transactional email goes to spam

When transactional email goes to spam, the instinct is to blame the recipient's mail provider, and the cause is almost always configuration on the sending side. Password resets, receipts and verification codes are the messages a product cannot afford to lose, and their deliverability is mostly an identity question: can the receiving system establish that this message genuinely came from you, and that mail from you is normally wanted.

Keep reading
Cloud

Apr 14, 2026 3 min read

Why your transactional email goes to spam

Deliverability is mostly an identity problem, and the fixes are unglamorous configuration…

Read article
Open-source dependencies and the risk you own

Most of the code shipping in a modern application was written by people the team will never meet, arriving through a dependency tree several levels deep. That is a reasonable trade and it is rarely made deliberately. Managing open-source dependency vulnerabilities starts by acknowledging that you own the security and the maintenance of everything you ship, regardless of who wrote it, and that the transitive dependencies nobody chose are the bulk of it.

Keep reading
Security

Apr 13, 2026 3 min read

Open-source dependencies and the risk you own

Most of the code you ship was written by people you will never meet, and that deserves a deliberate decision…

Read article
Designing a CI/CD pipeline people actually trust

A continuous integration pipeline has one job: tell you quickly and reliably whether a change is safe. Most pipelines fail at one of those two words. They are slow, so people batch changes and stop waiting for results, or they are flaky, so red builds get re-run rather than investigated. Either failure converts the pipeline from a safety net into a tax.

Keep reading
Cloud

Apr 10, 2026 2 min read

Designing a CI/CD pipeline people actually trust

A pipeline that takes forty minutes and fails randomly gets bypassed, and then it protects nothing…

Read article
How we cut a client's data pipeline costs by 62% with AI

A retail client was spending a small fortune reprocessing the same data every night. The pipeline worked - it was just brute-force expensive.

Keep reading
Data & AI

Apr 09, 2026 1 min read

How we cut a client's data pipeline costs by 62% with AI

A behind-the-scenes look at the architecture and modeling choices that made a dramatic difference…

Read article
Blue-green or canary: choosing a deployment strategy

Once deployments stop involving downtime, two strategies dominate. Blue-green runs two complete environments and switches traffic from one to the other in a single move. Canary sends a small share of traffic to the new version, watches, and increases gradually. They sound like variations on a theme and behave quite differently under failure.

Keep reading
Cloud

Apr 07, 2026 2 min read

Blue-green or canary: choosing a deployment strategy

Both let you ship without downtime. They fail differently, and the database usually decides which you can use…

Read article
Container images: the supply chain nobody audits

A container image built from a standard base contains an operating system, a language runtime, and every transitive dependency your package manager resolved. Your own code is a rounding error in that total. Everything else arrived on trust, and most teams have never looked at what is in there or where it came from.

Keep reading
Security

Apr 06, 2026 2 min read

Container images: the supply chain nobody audits

Your application is a few thousand lines. The image you ship contains a few hundred thousand you never read…

Read article
Load testing that tells you something useful

Most load testing produces a number nobody acts on. A tool is pointed at the busiest endpoint, concurrency is increased until something breaks, and a figure is recorded. The figure is real and almost useless, because it measures a scenario no user will ever create and ignores everything about how the system actually behaves under real traffic.

Keep reading
Cloud

Apr 03, 2026 2 min read

Load testing that tells you something useful

Hitting one endpoint with a thousand threads proves your load generator works. It proves little else…

Read article
Connection pooling: the limit you hit before CPU

A common scaling story: traffic grows, response times worsen, more application instances are added, and the database gets slower rather than faster. The instinct is that the database needs a bigger machine. Often it needs fewer connections, and understanding why is one of the higher-leverage pieces of knowledge in operating a database.

Keep reading
Cloud

Apr 02, 2026 2 min read

Connection pooling: the limit you hit before CPU

Adding application servers made it slower. That is usually connections, and the fix is counterintuitive…

Read article
Logging: what to record and what never to record

Logging goes wrong in two directions at once. Too little, and an incident becomes guesswork. Too much, and the bill grows, the signal drowns, and - the part that gets least attention - personal data ends up in a system with far weaker access controls than the database it came from. Both failures are common in the same codebase.

Keep reading
Security

Mar 31, 2026 2 min read

Logging: what to record and what never to record

The bill is one problem. The password sitting in plain text in your log aggregator is the other…

Read article
Serverless or containers: what actually decides it

The serverless argument is usually framed as cost, and cost is the least stable part of it. Functions bill per invocation and per gigabyte-second of execution, so at low or spiky volume they are extremely cheap and at sustained high volume they become expensive relative to a container running continuously. The crossover exists, it is calculable from your own numbers, and almost nobody calculates it before choosing.

Keep reading
Cloud

Mar 30, 2026 2 min read

Serverless or containers: what actually decides it

Serverless is cheaper until it is dramatically not, and the crossover point is a property of your traffic…

Read article
Data modelling: normalise first, denormalise deliberately

Normalisation has an unfashionable reputation, usually justified by performance. The argument is that joins are expensive and duplicating data avoids them. It is true in specific circumstances and false as a general rule, and adopting it early costs far more than the joins ever would - because every duplicate is a place where the truth can diverge.

Keep reading
Data & AI

Mar 27, 2026 2 min read

Data modelling: normalise first, denormalise deliberately

Duplicated data is a correctness decision disguised as a performance one…

Read article
Refactoring code that has no tests

The advice to write tests before refactoring is correct and, on the codebases where it is most needed, circular. The code is untestable precisely because of the things you want to change - a single enormous function, dependencies constructed inline, database access woven through business logic. You cannot get it under test without changing it, and you cannot change it safely without tests.

Keep reading
IT Strategy

Mar 26, 2026 2 min read

Refactoring code that has no tests

You need tests to refactor safely and you need to refactor to make it testable. There is a way through…

Read article
Getting a new engineer productive in a week

Onboarding is usually designed as a tour: architecture diagrams, an overview of the domain, a walkthrough of the systems. It feels thorough and it is largely wasted, because none of it attaches to anything the person has done yet. What produces a productive engineer quickly is the opposite - a small, real change shipped early, and the context arriving as it becomes needed.

Keep reading
IT Strategy

Mar 24, 2026 2 min read

Getting a new engineer productive in a week

Most onboarding optimises for orientation. What actually helps is shipping something small on day two…

Read article
API errors: what to return when something goes wrong

Error responses are the part of an API that gets designed last and used most during integration. A developer wiring up your API spends their first week almost entirely in the failure paths, and what you return determines whether they fix their own mistakes or open a support ticket for each one. It is worth as much design attention as the success case.

Keep reading
Cloud

Mar 23, 2026 2 min read

API errors: what to return when something goes wrong

Returning 500 with a stack trace tells an attacker more than it tells your integration partner…

Read article
Moving data between systems without losing any

One-off data migrations - out of a legacy system, into a new platform, between two products after an acquisition - are treated as a scripting exercise and are really a verification exercise. Writing the transformation is straightforward. Being able to demonstrate, to a finance director who will not sign off otherwise, that every record arrived and arrived correctly, is where the time goes.

Keep reading
Data & AI

Mar 20, 2026 2 min read

Moving data between systems without losing any

The migration script is the easy part. Proving afterwards that everything arrived is the work…

Read article
Why it works in staging and breaks in production

Every team has had the experience: tested thoroughly in staging, shipped, broke immediately. The instinct is to blame testing discipline. The cause is almost always that staging differs from production in a way nobody had written down - different data volume, different configuration, different versions, a service stubbed out, a feature flag in a different state.

Keep reading
Cloud

Mar 19, 2026 2 min read

Why it works in staging and breaks in production

Staging with two hundred rows and no traffic is not a rehearsal for anything…

Read article
REST, GraphQL or gRPC: choosing an API style

These three get compared as though one must be best, and they are better understood as answers to different questions about who consumes the API and how much control you have over them. Choosing by technical merit alone is how teams end up with a GraphQL endpoint serving one internal client, or gRPC on a public API nobody can call from a browser.

Keep reading
IT Strategy

Mar 17, 2026 2 min read

REST, GraphQL or gRPC: choosing an API style

The right answer usually depends on who is calling you, not on which is technically superior…

Read article
Why your product emails end up in spam

Transactional email - password resets, verification links, receipts, notifications - is treated as solved because sending is easy. Arriving is the hard part, and the failure is invisible from your side: your logs say sent, the provider says delivered, and the user says they never got it. By the time it is understood as a systemic problem rather than isolated complaints, a meaningful share of signups have already been lost.

Keep reading
Cloud

Mar 16, 2026 2 min read

Why your product emails end up in spam

Password resets that never arrive are a support problem, a churn problem and an authentication problem…

Read article
Generating PDFs and reports without taking the site down

Document generation looks like a small feature and behaves like an infrastructure problem. Invoices, statements, contracts, exports - each one is fine in isolation, and the load arrives in a spike because everyone runs their month-end on the same two days. A design that renders synchronously in the request handles the demo and falls over exactly when the business needs it most.

Keep reading
Cloud

Mar 13, 2026 2 min read

Generating PDFs and reports without taking the site down

Rendering a document in the request thread works until month-end, when everyone does it at once…

Read article
Internationalisation is not translation

Internationalisation is usually scoped as a translation project: extract the strings, send them out, put them back. That part is the most visible and the least likely to cause defects. The failures come from assumptions baked into the data model and the interface - about what a name looks like, how an address is structured, how numbers are written, and how plurals work.

Keep reading
IT Strategy

Mar 12, 2026 2 min read

Internationalisation is not translation

Names, addresses, numbers and plurals break long before the words do…

Read article
Frontend state: most of it is not yours to manage

The standard progression in a frontend codebase is that state gets passed through a few layers, becomes awkward, and someone introduces a global state library. It usually helps for a while and then the store becomes an enormous object holding everything the application has ever fetched, with no clear ownership and no idea when anything is stale. The mistake was earlier: treating all state as one kind of thing.

Keep reading
IT Strategy

Mar 10, 2026 2 min read

Frontend state: most of it is not yours to manage

Teams reach for a state library to solve a problem that is really about caching server data…

Read article
Monorepo or many repositories

The repository layout question gets argued as a matter of taste and is really a trade between two costs. A single repository makes it easy to share code and change several services together, and hard to keep them independent. Many repositories make independence the default, and coordination expensive. Whichever you choose, you pay one of those bills.

Keep reading
IT Strategy

Mar 09, 2026 2 min read

Monorepo or many repositories

One repository makes sharing easy and isolation hard. Many repositories do the reverse. Neither is free…

Read article
Handling money in software without losing paise

Money is the area where a small representational mistake becomes an accounting problem, and the mistake is usually made in the first hour of the project. Floating-point numbers cannot represent most decimal fractions exactly - 0.1 plus 0.2 is famously not 0.3 - and once amounts are stored that way, the error compounds through every calculation until a total is off by a paisa and a finance team cannot reconcile it.

Keep reading
IT Strategy

Mar 06, 2026 2 min read

Handling money in software without losing paise

Storing an amount as a floating-point number is the bug that produces an invoice off by one paisa, then a reconciliation nobody can close…

Read article
The N+1 query and other ways an ORM surprises you

The N+1 query is the most common performance bug in applications built on an object-relational mapper, and it is invisible in the source. You fetch a list of orders, loop over them, and read each order's customer. The code reads as one operation. The database sees one query for the orders and then one more per order - four hundred round trips for a page that should have taken two.

Keep reading
Cloud

Mar 05, 2026 2 min read

The N+1 query and other ways an ORM surprises you

One line of readable code becomes four hundred database round trips, and nothing in the code says so…

Read article
Sending webhooks your customers can rely on

Offering webhooks looks like the simplest integration feature there is: when something happens, POST to a URL the customer gave you. The complexity is entirely in what happens when that POST does not succeed, and since the receiving endpoints are built by other people and hosted somewhere you cannot see, it will not succeed a meaningful share of the time.

Keep reading
Cloud

Mar 03, 2026 2 min read

Sending webhooks your customers can rely on

Your customer's endpoint will be down, slow and wrong at various times. That is your delivery problem, not theirs…

Read article
Audit trails: recording who did what

Sooner or later someone asks who changed this record, and when, and what it said before. If the answer has to be reconstructed from application logs, it usually cannot be - logs have rotated, were never structured for the question, and record what the code did rather than what a person decided. An audit trail is a different artefact with different requirements, and it needs to be designed rather than inferred.

Keep reading
Security

Mar 02, 2026 2 min read

Audit trails: recording who did what

Application logs are not an audit trail, and the difference becomes apparent at exactly the wrong moment…

Read article
Permissions: why roles stop being enough

Most products start with a role column - admin, manager, user - and a scattering of checks against it. It works for a year. Then a customer wants someone who can approve expenses but not view salaries, and someone else who can manage one region but not another, and the role list starts growing towards the number of customers you have. That growth is the signal that roles alone have run out.

Keep reading
Security

Feb 27, 2026 2 min read

Permissions: why roles stop being enough

Admin, manager and user works until the first customer asks for something that fits none of them…

Read article
Dependency upgrades: small and often, or not at all

Dependency upgrades are the maintenance work most easily deferred, because nothing breaks when you skip them. The cost accrues invisibly and then arrives all at once, usually as a critical vulnerability in a library you cannot upgrade because it requires a framework version that requires a runtime version that breaks four other things. The urgent fix becomes a three-week project at the worst possible time.

Keep reading
Security

Feb 26, 2026 2 min read

Dependency upgrades: small and often, or not at all

A codebase two years behind cannot patch a vulnerability quickly, because every upgrade path is blocked by another…

Read article
Bot traffic: what to block and what to leave alone

A significant share of traffic to any public site is automated, and the instinct on discovering that is to block it. The instinct needs tempering: some of that traffic is Googlebot, without which you do not appear in search results, and some is monitoring, link previews and legitimate partner integrations. The task is discrimination rather than exclusion.

Keep reading
Security

Feb 24, 2026 2 min read

Bot traffic: what to block and what to leave alone

Blocking all automated traffic removes your search rankings along with the scrapers…

Read article
Testing data the way you test code

Data pipelines have a failure mode software does not: succeeding while being wrong. The job runs, the rows load, the dashboard refreshes, and the numbers are incorrect because an upstream system changed a field or a join silently duplicated rows. Nothing errors. The discovery happens days later, in a meeting, when someone notices a figure that cannot be right.

Keep reading
Data & AI

Feb 23, 2026 2 min read

Testing data the way you test code

A pipeline that runs successfully and loads wrong numbers reports itself as green…

Read article
Streaming or batch: how fresh does the data need to be?

Ask a business stakeholder whether they need real-time data and the answer is always yes, because nobody prefers stale information. The useful question is different: what decision does this data drive, and how quickly must it be made? A dashboard reviewed each morning does not need sub-second freshness. A fraud check during a payment does. Most requirements sit closer to the first than the second, and building for the second unnecessarily is expensive in ways that keep costing.

Keep reading
Data & AI

Feb 20, 2026 2 min read

Streaming or batch: how fresh does the data need to be?

Real-time is a requirement people state and rarely need. The honest question is what decision the data changes…

Read article
Machine learning models degrade quietly

Software either works or throws an error. A machine learning model does neither - it keeps returning confident predictions that are gradually less correct, because the world it was trained on has moved. Fraud patterns change, customer behaviour shifts, a product line is discontinued, a supplier changes their document format. Nothing errors. Accuracy declines and the system reports itself as healthy.

Keep reading
Data & AI

Feb 19, 2026 2 min read

Machine learning models degrade quietly

A model that was accurate at launch is not accurate two years later, and nothing in your monitoring will say so…

Read article
Prompt injection: the vulnerability with no patch

Any system where a language model reads untrusted content and can also take actions has a security problem that does not have a clean fix. The model receives your instructions and the content in the same channel, and it cannot reliably tell which is which. Text hidden in a document, a support email, a web page or a code comment can instruct the model, and the model may follow it.

Keep reading
Data & AI

Feb 17, 2026 2 min read

Prompt injection: the vulnerability with no patch

The model cannot reliably distinguish your instructions from instructions hidden in the data it reads…

Read article
SQL injection: still the one that gets people

SQL injection has been well understood for twenty-five years and remains among the most damaging vulnerabilities found in production systems. Not because the fix is hard - it is one line - but because modern frameworks prevent it so thoroughly by default that when someone does write raw SQL, they are usually doing so in unusual circumstances, without the habits that would protect them, and in a part of the codebase nobody reviews closely.

Keep reading
Security

Feb 16, 2026 2 min read

SQL injection: still the one that gets people

Every framework prevents it by default, which is exactly why the remaining cases are the dangerous ones…

Read article
Cross-site scripting and the header that limits it

Cross-site scripting is the vulnerability where an attacker gets their JavaScript running in another user's browser, on your domain, with all the access that implies - session cookies unless they are protected, anything the user can see, anything the user can do. Modern frameworks escape output by default and have made the common cases rare. The remaining ones cluster in specific, recognisable places.

Keep reading
Security

Feb 13, 2026 2 min read

Cross-site scripting and the header that limits it

Modern frameworks escape output by default. The vulnerabilities are in the places you told them not to…

Read article
Storing passwords: what the algorithm choice buys you

Password storage is a solved problem with a small number of correct answers, and getting it wrong is the difference between a database breach that is embarrassing and one that hands over every user's credentials - including the ones they reused on their bank. The decision is worth ten minutes even though almost every framework makes it for you.

Keep reading
Security

Feb 12, 2026 2 min read

Storing passwords: what the algorithm choice buys you

The difference between a fast hash and a slow one is the difference between a breach and a catastrophe…

Read article
Multi-factor authentication people will actually use

Multi-factor authentication is the single highest-return security control for most applications, because the overwhelming majority of account compromises begin with a valid password used by the wrong person. The design question is not whether to have it but which factors to offer, and that is a genuine trade between security and the proportion of users who will complete setup.

Keep reading
Security

Feb 10, 2026 2 min read

Multi-factor authentication people will actually use

SMS codes are the weakest option and the one most users can manage. Both facts are true at once…

Read article
Choosing a message broker: queue or log

The comparison usually presented as Kafka versus RabbitMQ is really a comparison between two data structures. A traditional broker is a queue: messages are delivered to a consumer and then removed. Kafka is a log: messages are appended, retained for a configured period, and each consumer tracks its own position independently. Almost every practical difference between them follows from that one distinction.

Keep reading
Cloud

Feb 09, 2026 2 min read

Choosing a message broker: queue or log

Kafka and RabbitMQ are not competitors so much as different data structures with different jobs…

Read article
Importing large files without breaking anything

Bulk import is a feature customers ask for early and one that fails in more ways than almost anything else, because you are accepting a file produced by someone else's process, with someone else's idea of correctness, and attempting to turn it into valid rows in your database. Every assumption you make about that file will eventually be violated.

Keep reading
Cloud

Feb 06, 2026 2 min read

Importing large files without breaking anything

Customers will upload a two-hundred-megabyte spreadsheet with a row that has one extra comma in it…

Read article
Choosing a frontend framework in 2026

Framework choice generates strong opinions and, for most business applications, has less effect on the outcome than almost any other early decision. React, Vue, Angular and Svelte are all capable of building the same product to the same quality. The considerations that actually differ are practical and unglamorous: who will maintain this, what does the ecosystem provide, and what does the product actually need to be.

Keep reading
IT Strategy

Feb 05, 2026 2 min read

Choosing a frontend framework in 2026

The technical differences are smaller than the ecosystem and hiring differences, and both outlast the project…

Read article
Read replicas: buying capacity, paying in staleness

Read replicas are the standard first answer to a database that cannot keep up: add copies, send reads to them, keep writes on the primary. It genuinely works for read-heavy workloads and it introduces one specific problem that has to be designed around rather than discovered - replication lag, and the class of bugs that follows from it.

Keep reading
Cloud

Feb 03, 2026 2 min read

Read replicas: buying capacity, paying in staleness

The user saves a change, the page reloads from a replica, and their change is gone. That bug is the whole topic…

Read article
Removing a feature without breaking trust

Software products accumulate. Features get added, a few users adopt each one, and nothing is ever removed because removing things upsets people. The result is a product that is harder to learn, harder to test, harder to change, and slower to develop in - where every new idea must be reconciled with eleven old ones. Deliberate removal is ordinary maintenance, and treating it as an admission of failure is why most products never do it.

Keep reading
IT Strategy

Feb 02, 2026 2 min read

Removing a feature without breaking trust

Every feature you keep costs testing, support and design constraint forever. Removal is maintenance, not failure…

Read article
Concurrency: the bug that only happens in production

Race conditions are the defects that pass every test and appear in production, because tests run one operation at a time and production does not. Two users edit the same record and one change silently disappears. Two requests both check that stock is available and both proceed. A button clicked twice creates two orders. All of these are correct-looking code, and all of them are wrong the moment two things happen at once.

Keep reading
Cloud

Jan 30, 2026 2 min read

Concurrency: the bug that only happens in production

Two people clicked at the same time and one of their changes vanished. It is reproducible, just not by one person…

Read article
Password reset: the endpoint attackers actually target

Password reset is authentication's back door. Teams put effort into login - rate limiting, multi-factor, strong hashing - and then implement reset as a convenience feature, which is precisely why attackers look there. Every control on the login path is irrelevant if the reset flow will issue a working credential to someone who is not the account holder.

Keep reading
Security

Jan 29, 2026 2 min read

Password reset: the endpoint attackers actually target

You can harden login perfectly and still hand out accounts through the reset flow…

Read article
SSO: the feature enterprise deals stall on

Single sign-on is the feature that appears in the security questionnaire of your first serious enterprise deal, framed as a requirement rather than a preference. The buyer's reasoning is sound - they want employees provisioned and deprovisioned centrally, and an account they cannot revoke when someone leaves is an audit finding. Understanding what they actually need saves a great deal of guesswork.

Keep reading
Security

Jan 27, 2026 2 min read

SSO: the feature enterprise deals stall on

SAML looks like a fortnight of work and behaves like a quarter, mostly because of what surrounds it…

Read article
Practising failure before production does it for you

Resilience is usually asserted rather than demonstrated. The architecture diagram shows redundancy, the runbook describes failover, the backup job reports success - and none of that is evidence, because the paths have never been exercised. The purpose of deliberately breaking things is to convert assumptions into knowledge at a moment of your choosing.

Keep reading
Cloud

Jan 26, 2026 2 min read

Practising failure before production does it for you

Every system has failure modes nobody has seen. You can meet them at a planned time or at three in the morning…

Read article
Analytics: instrument deliberately or measure nothing

Product analytics decays in a predictable way. A tool is installed, events are added as features ship, and eighteen months later there are hundreds of event types with inconsistent names, overlapping meanings and unknown reliability. When someone finally asks a straightforward question - what share of signups complete onboarding - the honest answer is that the data cannot support it.

Keep reading
Data & AI

Jan 23, 2026 2 min read

Analytics: instrument deliberately or measure nothing

Six hundred event types, no naming convention, and nobody can answer how many people finished signing up…

Read article
Mobile releases: you cannot roll back an app

Mobile release management is a different discipline from web deployment, and teams that treat it as the same thing learn why during their first serious bug. You cannot roll back: the version on someone's phone stays there until they update, and a meaningful share of users will not update for weeks. Whatever you ship, you live with.

Keep reading
IT Strategy

Jan 22, 2026 2 min read

Mobile releases: you cannot roll back an app

Web deploys are reversible in minutes. A bad app build lives on devices until users choose to update…

Read article
Offline-first: syncing is the whole problem

Applications used by people who move - field engineers, delivery staff, sales teams, anyone in a warehouse or a basement - meet connectivity that is intermittent rather than absent. Handling that well is the difference between software people rely on and software they work around with paper. It is also considerably harder than it appears, and the difficulty is entirely in writes.

Keep reading
IT Strategy

Jan 20, 2026 2 min read

Offline-first: syncing is the whole problem

Caching data for reading is easy. Accepting edits while disconnected is where the design work is…

Read article
API documentation developers can actually use

Most API documentation is a generated list of endpoints with parameter tables. It is necessary and it is not sufficient, because it answers what each endpoint accepts and never answers the questions an integrating developer actually has: how do I authenticate, what is the sequence for the thing I am trying to do, and what happens when it goes wrong. The gap between reference and documentation is measured in support tickets.

Keep reading
IT Strategy

Jan 19, 2026 2 min read

API documentation developers can actually use

A generated endpoint list is a reference, not documentation. The gap between them is your integration time…

Read article
Internal platforms: paving the path rather than policing it

Past a certain size, every team ends up solving the same problems independently: how to deploy, where secrets live, how to get a database, what monitoring looks like, how to run something on a schedule. Each team's answer is reasonable and they are all different, so nothing transfers, incident response requires knowing which team built what, and the same work has been done five times.

Keep reading
IT Strategy

Jan 16, 2026 2 min read

Internal platforms: paving the path rather than policing it

Every team solving deployment, secrets and monitoring separately is the same work done five times, differently…

Read article