RSSAmplifier

Blog

Deepak Gupta's notebook

Deepak Gupta on customer identity (CIAM), AI security, and Generative Engine Optimization (GEO). Long-form essays plus curated portals across guptadeepak.com.

guptadeepak.comRSS feed ↗50 posts

Latest posts

August 15: The Country That Taught Me to Build Before I Had Permission

India turns 79 today. Before any accelerator or investor, India installed the operating system I still build on: resourcefulness, jugaad, and the refusal to accept that something cannot be done. A reflection on going from back office to reference implementation.

Google Says GEO Is Just SEO. Its Own Data Says Otherwise.

Google's official 2026 guidance says optimizing for AI search is still just SEO. Meanwhile Semrush's own data shows under 50% domain overlap between AI Mode and organic results.

The State of AI Search in 2026: 42 Statistics, Every One Sourced

Most AI search statistics have no traceable source. These 42 name the producing organisation, the period, and the method.

The CISO's Guide to Hiring Cybersecurity Consultants

Three RFPs out, three decks back, cheapest bid wins, and six months later you are over budget. The problem is the selection process, not the firms.

The Identity Tax: What Auth Actually Costs Per Closed Deal

Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.

Anthropic Claude for Startups: The Complete Guide to Credits, Tiers, and Eligibility (2026)

The Anthropic Startup Program's three credit tiers explained: $5,000 direct, $25,000 with a VC referral, up to $100,000 at Anthropic's discretion, plus eligibility, rate limits, and how it differs from Claude via AWS Bedrock.

Adobe Paid $1.9 Billion for Something Skeptics Still Call a Buzzword

Adobe does not make impulsive acquisitions, yet it put a ten-figure price on a discipline critics were still calling fake. Acquisition prices are the most honest signal in tech.

Stop Obsessing Over Prompts: What Actually Matters for AI Success

Prompt engineering is overrated. In 2026 the AI products that ship and stick win on context, evals, data, and workflow. Here is the stack that actually matters.

How ChatGPT, Claude, Perplexity, and AI Overviews Retrieve and Cite: The Engine Mechanics Reference

ChatGPT layers citations onto an answer. Perplexity builds the answer from citations. The four engines are not one surface.

What a B2B Contact Database Actually Requires (Most Founders Get This Wrong)

Most founders build outbound infrastructure on top of a contact list that is already 25 to 30 percent stale. Discovery, verification, and enrichment are three different problems, and skipping verification is what wrecks deliverability.

Credential Lifecycle for AI Agents: From 24-Hour to Ephemeral Tokens

A leaked static key is a disaster; a five-minute token is mostly a shrug. Here is the credential lifecycle that gets AI agents from 24-hour tokens to ephemeral ones.

Your Data Isn't Ready for AI (And Why That's Actually Good News)

Your data isn't ready for AI, and that's good news. It means you found the problem before you built on it. What LoginRadius, GrackerAI, and LogicBalls taught me about the gap between organized data and AI-ready data, plus the 2025 numbers on why it sinks most projects.

The Indian B2B SaaS Founder's Blueprint for Winning US Customers

I built in India and sold into the US the hard way. Here is the blueprint I would hand my younger self: get the entity right, earn SOC 2 trust early, price in dollars, and put your best people in front of US buyers.

10 Lessons From Tracking 50,000 AI Citations Across 6 Engines

Over 90 days I tracked how six AI search engines cite sources across 50,000+ B2B software responses. The data broke several assumptions the GEO industry treats as settled, starting with the idea that AI visibility is one thing you can optimize for.

The Shadow Agent Crisis: Your AI Agents Are Now Insider Threats

Shadow AI is an employee pasting into ChatGPT. A shadow agent holds real credentials and acts on its own. That is a different, and bigger, problem.

GEO vs SEO: What Actually Changes in the Workflow (And What Does Not)

The crawl and authority layer is unchanged. Retrieval moves from page to passage, and the outcome moves from click to citation.

SOC 2 Policies: What Founders Actually Need to Write

An enterprise prospect just asked for your SOC 2. Here is what the report really is, Type I vs Type II, the ten policies auditors expect, and how Vanta and Drata changed the work.

What Black Hat Week Reveals About Security Marketing

Black Hat and DEF CON pull millions in marketing spend to Las Vegas this week. AI engines that buyers ask afterward do not weigh booth size. They weigh whether your research is structured, specific, and citable.

Your Phone Line Became the Front Door. Then Everyone Automated It.

Mandiant ranked voice phishing the second most common initial infection vector of 2025. In the same window, thousands of businesses handed their phone lines to AI agents. Those two facts are related, and the security implications run in both directions.

Authentication and Authorization in Microservices: What Works

In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.

Model Context Protocol vs. API: How to Connect AI to Your Tools

MCP is Anthropic’s open standard for connecting AI agents to your tools and data. Here is what it actually is, how it differs from a REST API, and a clear rule for when to use each in 2026.

How to Structure Content So AI Actually Extracts It: 11 Patterns With Before and After Rewrites

AI does not read your page. It retrieves a fragment and decides whether that fragment answers the question on its own.

IAM vs PAM: Key Differences and Best Practices for Access Management

IAM decides who gets in the door. PAM controls the keys that can rewire the building. Here is the real difference, where they converge in 2026, and why your AI agents need both.

Passkeys Have a 93% Login Success Rate. Only 36% of Accounts Enroll.

Passkeys demo better than any login method ever shipped. Most deployments still cannot get anyone to turn them on. Both numbers are true.

AI Authentication: Verifying People, Agents, and Content

AI made it cheap to fake a face, a voice, and a video. Here is my working map of the three problems authentication now has to solve, and the tools that actually hold up in 2026: verifying people, verifying agents, and verifying content.

AI Agents Don't Have Passwords. Your Auth Stack Assumes Everyone Does.

Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.

The Massive AI Security Hole Your CISO Doesn't Know About

Your AI security review passed and still missed the real attack surface. EchoLeak, over-permissioned agents, shadow AI: the AI-specific vectors most CISOs never test for, and the five moves that close them.

Why a Payments Company Wants an AI Model Router: Tokens Are Acting Like Currency

OpenRouter was worth .3 billion in May. Stripe is reportedly discussing billion in July. The routing layer turned out to be the valuable part.

When AI Hackers Meet Machine Identity: The Ignored Attack Surface

The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days.

Nvidia Rallied the Industry Behind Open Weights. Then OpenAI Joined Anyway.

Huang published the letter with 25 signatures. A day later there were 50, including OpenAI and Google. That reversal says more than the document does.

llms.txt, Explained: The Spec, What Actually Reads It, and a Working File for a Security Vendor

llms.txt is a proposal, not a standard. No major AI company parses it, and 97 percent of the files get zero requests.

SysAdmin Appreciation Day: For the People Who Hold the Keys

On System Administrator Appreciation Day, appreciation for the people who hold the literal keys to the organization, and why identity work matters more, not less, in the AI era.

Anthropic Finally Answered the Open Weights Letter. A Chinese Lab Answered It Louder.

Amodei says Anthropic never wanted a ban. His real objection is irreversibility. Days earlier, a Chinese lab shipped 2.8 trillion open parameters.

An OpenAI Agent Escaped Its Sandbox and Hacked Hugging Face to Cheat on Its Own Benchmark

Hugging Face detected the intrusion on July 16. OpenAI worked out five days later that the attacker was its own model, cheating on its own benchmark.

The Identity Mesh: Federated Trust for Multi-Agent AI

Agents can already prove who they are. What no standard has cleanly solved is passing scoped authority down a multi-hop chain across organizations. Here is the real state of agent identity in 2026, minus the blockchain hype.

The Identity Orchestration Layer for Hybrid AI

Machine identities now outnumber humans by 45 to 1 or more, and every AI agent widens the gap. Here is what an identity orchestration layer is, in plain terms, and how to build one that governs humans, workloads, and agents from a single control plane.

Every AI Crawler in 2026: The Reference Table (And Which Ones Your WAF Is Silently Blocking)

About two dozen AI crawlers matter in 2026. They split into three classes, and your security team has blocked several without telling marketing.

Your Cold Email Inbox Is the Cheapest Positioning Audit You Will Ever Run

Eight out of ten cold emails now describe my company correctly. Eighteen months ago it was three. Nobody ran a rebrand.

Prisma Cloud vs Aqua vs Wiz vs Sysdig: CNAPP Compared

Four serious CNAPP platforms, four different philosophies: agentless graphs, runtime detection, container lifecycle, and all-in-one breadth. Here is how to choose.

Infisical vs Doppler: Which Secrets Manager Is Right for Your Team?

Both centralize secrets and kill the .env-file-in-Slack habit. The real fork is open-source and self-hosted versus a managed SaaS you never operate.

Quad9 vs Cloudflare: Which DNS Resolver Is More Secure and Private?

Both are free, fast, and encrypted. The real differences are what they block, what they log, and whose laws govern the servers.

The Future of Authentication 2026-2030: How Five Converging Technologies Are Rebuilding Identity from the Ground Up

Passkeys, post-quantum crypto, silent network authentication, AI behavioral biometrics, and decentralized identity are fusing into one login stack. Here is what it looks like by 2030, and the two moves in 2026 that decide whether you are ready.

Publishers Are Ready to Block Google. Blocking Is Not a Strategy.

Reddit, USA Today and Reuters are weighing whether to cut Google off. Most of the numbers from that story were corrected a day later. What the breaking crawl bargain means for B2B SaaS, and why blocking is a negotiating position rather than a plan.

Kodak Breached by ShinyHunters: The Extortion Group That Won't Stop Until Every Enterprise Platform Is Hit

ShinyHunters claimed 2.2M Kodak records with a June 18 leak deadline. The group has breached Snowflake, Salesforce, Canvas, PeopleSoft, and now Kodak.

Adobe's BPO Breach: One Phished Support Agent Extracted 13 Million Records and Unpublished Vulnerability Reports

One phished BPO agent extracted 13M Adobe customer records and unpublished vulnerability reports from HackerOne. Third-party access is the breach pattern of 2026.

Stryker's Tens of Thousands of Wiped Devices: Iran Shifts From Espionage to Destruction

Iranian hackers wiped tens of thousands of Stryker devices in one attack. No data stolen. Just destruction. A new phase in state-sponsored cyber warfare.

GEO Is Fake, Says Everyone. So Why Are So Many Companies Hiring GEO Managers?

LinkedIn says GEO is a grift. Corporate job boards say it is a salary band up to $171K at Stripe, SailPoint, AWS, and Citizens Bank. I break down what these companies actually hire for, and why this looks exactly like the cloud and email revolutions did fifteen years ago.

Build vs Buy Auth Is the Wrong Question. Here's the Right One.

Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.

Novo Nordisk Breached: When the World's Most Valuable Pharma Company Becomes a Target

Novo Nordisk confirmed a June 2026 data breach. The pharmaceutical giant behind Ozempic becomes the latest healthcare target in an accelerating trend.

Space Exploration Day: Everything Starts as an Impossible Idea

On Space Exploration Day, the moon landing is a founder's lesson in sequencing: commit to the outcome before you have proof it is reachable, and build the proof on the way.