Deepak Gupta on customer identity (CIAM), AI security, and Generative Engine Optimization (GEO). Long-form essays plus curated portals across guptadeepak.com.
India turns 79 today. Before any accelerator or investor, India installed the operating system I still build on: resourcefulness, jugaad, and the refusal to accept that something cannot be done. A reflection on going from back office to reference implementation.
Google's official 2026 guidance says optimizing for AI search is still just SEO. Meanwhile Semrush's own data shows under 50% domain overlap between AI Mode and organic results.
Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.
The Anthropic Startup Program's three credit tiers explained: $5,000 direct, $25,000 with a VC referral, up to $100,000 at Anthropic's discretion, plus eligibility, rate limits, and how it differs from Claude via AWS Bedrock.
Adobe does not make impulsive acquisitions, yet it put a ten-figure price on a discipline critics were still calling fake. Acquisition prices are the most honest signal in tech.
Prompt engineering is overrated. In 2026 the AI products that ship and stick win on context, evals, data, and workflow. Here is the stack that actually matters.
Most founders build outbound infrastructure on top of a contact list that is already 25 to 30 percent stale. Discovery, verification, and enrichment are three different problems, and skipping verification is what wrecks deliverability.
A leaked static key is a disaster; a five-minute token is mostly a shrug. Here is the credential lifecycle that gets AI agents from 24-hour tokens to ephemeral ones.
Your data isn't ready for AI, and that's good news. It means you found the problem before you built on it. What LoginRadius, GrackerAI, and LogicBalls taught me about the gap between organized data and AI-ready data, plus the 2025 numbers on why it sinks most projects.
I built in India and sold into the US the hard way. Here is the blueprint I would hand my younger self: get the entity right, earn SOC 2 trust early, price in dollars, and put your best people in front of US buyers.
Over 90 days I tracked how six AI search engines cite sources across 50,000+ B2B software responses. The data broke several assumptions the GEO industry treats as settled, starting with the idea that AI visibility is one thing you can optimize for.
An enterprise prospect just asked for your SOC 2. Here is what the report really is, Type I vs Type II, the ten policies auditors expect, and how Vanta and Drata changed the work.
Black Hat and DEF CON pull millions in marketing spend to Las Vegas this week. AI engines that buyers ask afterward do not weigh booth size. They weigh whether your research is structured, specific, and citable.
Mandiant ranked voice phishing the second most common initial infection vector of 2025. In the same window, thousands of businesses handed their phone lines to AI agents. Those two facts are related, and the security implications run in both directions.
In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.
MCP is Anthropic’s open standard for connecting AI agents to your tools and data. Here is what it actually is, how it differs from a REST API, and a clear rule for when to use each in 2026.
IAM decides who gets in the door. PAM controls the keys that can rewire the building. Here is the real difference, where they converge in 2026, and why your AI agents need both.
AI made it cheap to fake a face, a voice, and a video. Here is my working map of the three problems authentication now has to solve, and the tools that actually hold up in 2026: verifying people, verifying agents, and verifying content.
Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.
Your AI security review passed and still missed the real attack surface. EchoLeak, over-permissioned agents, shadow AI: the AI-specific vectors most CISOs never test for, and the five moves that close them.
The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days.
On System Administrator Appreciation Day, appreciation for the people who hold the literal keys to the organization, and why identity work matters more, not less, in the AI era.
Agents can already prove who they are. What no standard has cleanly solved is passing scoped authority down a multi-hop chain across organizations. Here is the real state of agent identity in 2026, minus the blockchain hype.
Machine identities now outnumber humans by 45 to 1 or more, and every AI agent widens the gap. Here is what an identity orchestration layer is, in plain terms, and how to build one that governs humans, workloads, and agents from a single control plane.
Four serious CNAPP platforms, four different philosophies: agentless graphs, runtime detection, container lifecycle, and all-in-one breadth. Here is how to choose.
Passkeys, post-quantum crypto, silent network authentication, AI behavioral biometrics, and decentralized identity are fusing into one login stack. Here is what it looks like by 2030, and the two moves in 2026 that decide whether you are ready.
Reddit, USA Today and Reuters are weighing whether to cut Google off. Most of the numbers from that story were corrected a day later. What the breaking crawl bargain means for B2B SaaS, and why blocking is a negotiating position rather than a plan.
One phished BPO agent extracted 13M Adobe customer records and unpublished vulnerability reports from HackerOne. Third-party access is the breach pattern of 2026.
Iranian hackers wiped tens of thousands of Stryker devices in one attack. No data stolen. Just destruction. A new phase in state-sponsored cyber warfare.
LinkedIn says GEO is a grift. Corporate job boards say it is a salary band up to $171K at Stripe, SailPoint, AWS, and Citizens Bank. I break down what these companies actually hire for, and why this looks exactly like the cloud and email revolutions did fifteen years ago.
Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.
On Space Exploration Day, the moon landing is a founder's lesson in sequencing: commit to the outcome before you have proof it is reachable, and build the proof on the way.