The actionable layer of guptadeepak.com
Guides that teach you to do the thing.
After the research explains the landscape and before you pick a vendor, you have to actually build, migrate, raise, get cited, or evaluate. Guides is that middle layer. Pick a topic below and you get everything on that subject in one place, in reading order: start here, then explainers, how-tos, playbooks, migrations, and teardowns. Human-authored, honest about tradeoffs, no gate.
Browse by topic
AI Search & GEO
10 guides · 19 termsHow AI answer engines pick and cite sources, and what to change on your own site so they pick yours.
Identity & Access
12 guides · 23 termsCustomer and workforce identity: the protocols, the buying decision, the implementation, and the migrations off a platform you regret.
Security Engineering
14 guides · 50 termsSecuring what you ship and what you send: AI agents and MCP servers, application and supply chain security, and sender authentication.
Fundraising
9 guidesPre-seed through Series A from the founder's side: the deck, the objections, the terms, the trip, and the update nobody teaches you to write.
Founder Brand
5 guidesMedia placement as citation acquisition: what earns coverage, which outlets AI engines actually cite, and how founder brand shows up in the product.
Startup Security Program
5 guidesBuilding the security function from zero: what to run yourself, what to buy, and when to bring in outside help.
Browse by format
The same guides sliced the other way, if you know the shape of what you want rather than the subject.
Every guide
Add SSO to Your B2B SaaS (and Escape the SSO Tax)
IAM · practitioner · 9 minEnterprise deals stall without SSO. Here is how to add SAML and OIDC single sign-on the right way, model it multi-tenant, and price it without the SSO tax.
Implement Passkeys / WebAuthn (with code)
Identity · practitioner · 8 minA working guide to passkeys and WebAuthn: the ceremony, real server and browser code, synced vs device-bound tradeoffs, and the recovery design that makes or breaks it.
What Is CIAM (and How It Differs from IAM)
CIAM · intro · 7 minCIAM is customer identity: registration, consent, and login built for the people who buy from you, not the people who work for you. Here is how it differs from workforce IAM and when you need it.
OAuth 2.0 vs OIDC vs SAML
Identity · intro · 8 minOAuth 2.0 is authorization, OIDC adds authentication, and SAML is enterprise federation. Here is what each actually does, the token types, and a decision table for when to use which.
Migrate Off Akamai Identity Cloud Before the Deadline
CIAM · practitioner · 8 minA runbook for moving off Akamai Identity Cloud (formerly Janrain) before end-of-life: inventory, bulk export, just-in-time password migration, a staged cutover with rollback, and the user-comms plan.
Set Up SCIM Provisioning for Enterprise Customers
IAM · practitioner · 8 minHow to implement SCIM 2.0: the User and Group schema, the endpoints you must build, deactivate-not-delete flows, group-to-role mapping, and testing against Okta and Entra.
Secure an MCP Server
AI Security · advanced · 8 minAn MCP server hands a model the power to act. Here is how to secure it: authN/authZ per invocation, least-privilege tools, untrusted-output handling, brokered secrets, and audit logs.
Red-Team an LLM: A Practical First Pass
AI Security · advanced · 8 minA first pass at LLM red-teaming: the four failure classes, a starter probe set, direct vs indirect injection, scoring, guardrail limits, and turning it into a CI regression suite.
Pass SOC 2 as a Seed-Stage Startup
Startup · intro · 8 minThe honest seed-stage SOC 2 playbook: Type II scoped to Security, realistic cost and timeline, the three controls that matter, whether Vanta/Drata are worth it, and how to avoid theater.
RBAC vs ABAC vs ReBAC vs PBAC
IAM · practitioner · 9 minThe four authorization models compared: RBAC (role), ABAC (attributes), ReBAC (relationship), PBAC (policy). What each is, where each breaks, and a decision table for choosing.
What Is GEO (and How It Differs from SEO/AEO)
GEO/AEO · intro · 7 minGEO is optimizing to be the source AI answers cite, not to rank in a list of links. Here is how it differs from SEO and AEO, why citation share is the metric, and what a GEO program involves.
Migrate Off Auth0 Without Downtime
Identity · practitioner · 8 minA zero-downtime runbook for leaving Auth0: what is portable, trickle vs bulk migration, bcrypt hash export, Rules/Actions remapping, coexistence cutover, and rollback.
The Solo Founder's Identity & Security Stack
Startup · intro · 7 minThe minimum viable identity and security stack for a 1 to 5 person B2B SaaS, in priority order, with an honest do-now-vs-defer table and what to deliberately skip.
Best Cybersecurity Consulting Firms in the US (2026)
Security Services · intro · 12 minA tiered directory of the specialised US cybersecurity consultancies worth a CISO's shortlist, from Optiv and Coalfire down to the boutiques, plus five questions that predict engagement quality.
How to Choose a Cybersecurity Compliance Consulting Firm
Security Services · practitioner · 11 minA decision framework rather than another listicle: four compliance problem types, industry matching, five predictive evaluation criteria, and 2026 pricing benchmarks.
The Investor Objection Playbook
Fundraising · practitioner · 10 minEvery investor objection is a proxy. Here is how to hear the real question, concede what is true, and answer with evidence instead of conviction.
The Seed Deck and Narrative Playbook
Fundraising · intro · 8 minWrite the argument as four paragraphs before you make a slide. Why now is the seed-stage crux, and a deck that needs you present will be read without you.
The Investor Update Playbook
Fundraising · intro · 8 minThe monthly update is a fundraising instrument. It converts a pass into a yes over six to twelve months by showing, in writing, that you do what you said.
The Bay Area Fundraising Trip Playbook
Fundraising · practitioner · 11 minWarm intros close seed rounds. Confirm 8 meetings before you fly, host one dinner, and put everyone who passed on a monthly update.
How to Run a Seed Round
Fundraising · practitioner · 8 minA seed round is a six-week campaign, not a lifestyle. Open with 12 to 18 months of runway, a list, and a milestone. Close when you have a lead and a date.
Raise Your First Pre-Seed Checks
Fundraising · intro · 8 minPre-seed is not a smaller seed. It buys 12 to 18 months to find a reason to raise one: who writes first checks, what you need, and a clean rolling SAFE.
SAFE vs Priced Round
Fundraising · intro · 8 minA post-money SAFE is the default at pre-seed and most seeds. Price the round when a lead wants a board seat and a price. Dilution math and the traps.
Series A Readiness
Fundraising · practitioner · 8 minSeries A buys a machine that turns capital into predictable growth, not a louder seed story. What A funds underwrite, and how to know you are early.
Term Sheet Red Flags
Fundraising · practitioner · 9 minValuation is the headline. Control is the operating system. Here is what is normal on a seed or A term sheet, what to fight, and what to ignore.
Earned vs Contributed vs Paid Media
Founder Brand · practitioner · 12 minChatGPT and Perplexity agree on only 11% of cited domains. Here is the three-tier media model that builds authority instead of a logo wall.
Founder Pitch Templates Editors Answer
Founder Brand · intro · 10 minEditors spend about four seconds on a cold pitch. Six templates for source requests, trades, follow-ups, and the diagnostic for why a pitch died.
Which Outlets AI Engines Actually Cite
Founder Brand · practitioner · 8 minPick outlets by whether the engine retrieves them for your buyer's questions. Prestige logos are not a citation strategy.
How Founder Brand Helps the Product
Founder Brand · intro · 8 minIn B2B and AI search the company often gets retrieved through the person first. Here is how to point founder brand at the product.
Turn Press Coverage into AI Citations
Founder Brand · practitioner · 7 minA clipping is not a citation. Same-day absorption, an owned page for the claim, and a prompt set to see whether the idea became retrievable.
Why Passwords Fail (and What to Ship Instead)
Identity · intro · 8 minA shared secret you can type is a secret an attacker can replay. What actually breaks, what does not fix it, and the order to replace passwords.
SMS MFA Is Not MFA
Identity · intro · 7 minNIST restricted SMS as an authenticator in 2017. SIM swaps and real-time phishing are why. What to rip out, and what to put in.
Replace Static API Keys
AI Security · practitioner · 8 minA long-lived key in a repo or an agent env is a master key you cannot inventory. Workload identity, short-lived tokens, and brokered secrets are the replacement.
GEO for B2B SaaS
GEO/AEO · practitioner · 8 minGEO for a software company is owning the five questions a buyer asks an engine. The stack, the page types, and a 90-day program a small team can run.
How to Choose a CIAM Platform
CIAM · practitioner · 9 minDo not pick CIAM from a logo grid. Decide whether you need it, score five questions that discriminate, bake off four flows, and know when to stay.
Identity for AI Agents
AI Security · advanced · 8 minAn agent is a new principal. Do not give it the user's cookie or the server's root key. Per-action auth, brokered secrets, and an audit id.
The Seed-Stage Identity and Security Stack
Startup · intro · 8 minAfter the solo-founder floor: workforce identity, machine credentials, customer RBAC, exportable audit, and SOC 2 on a trigger. What to add, and what to still defer.
How AI Search Actually Works (and Why Ranking #1 No Longer Matters)
GEO/AEO · intro · 8 minAI engines assemble answers from three layers, not one ranking. Here is the parametric memory, retrieval index, live fetch model, an engine-by-engine comparison, and why blocking the wrong crawler token costs you a whole surface.
What Is Query Fan-Out (and Why AI Cites Pages That Do Not Rank)
GEO/AEO · intro · 6 minQuery fan-out is how AI engines rewrite one prompt into several hidden sub-queries and retrieve each separately. Here is how it works, how to reconstruct your own fan-out footprint, and why Ahrefs found over a third of AI Overview citations skip the top 100 organic results entirely.
How to Audit What ChatGPT, Perplexity, and Google Say About Your Brand
GEO/AEO · practitioner · 11 minThe full protocol for auditing AI search visibility: build a 60 to 150 prompt universe, test search on and off across engines, read the diagnosis matrix, and build a source ledger that becomes your roadmap.
robots.txt for AI Crawlers: The Full Bot-by-Bot Setup
GEO/AEO · practitioner · 8 minEvery AI lab ships a training bot, a search-indexing bot, and a live-fetch bot, each needing its own robots.txt directive. Here is the full configuration, the llms.txt verdict backed by four independent studies, and what to check beyond the file itself.
How to Write Content AI Engines Will Actually Cite
GEO/AEO · intro · 7 minAI engines retrieve passages, not documents. Here are the sentence-, section-, and page-level rules that measurably move citation rate, backed by a 150,000-citation sentence-length study.
How to Choose a Reverse Proxy: nginx, HAProxy, Envoy, Caddy, or Traefik
AppSec · practitioner · 9 minAll five mainstream reverse proxies will work. Choose on operating model, meaning where configuration comes from, not on benchmark numbers you will never hit.
TLS Inspection with a Forward Proxy: What It Sees, What It Breaks
AppSec · advanced · 10 minDeploy TLS inspection only with managed devices, a written bypass list, and a defensible retention policy. Here is what it sees, what it breaks, and where it stops working.
Egress Control for AI Agents: Stop Your Agent Reaching What It Should Not
AI Security · practitioner · 10 minDefault-deny egress at a proxy the agent cannot route around is the highest-leverage single control for agent security. An allowlist alone will not stop exfiltration.
LLM Ads Explained: How AI Advertising Works in 2026
GEO/AEO · intro · 9 minChatGPT launched ads in February 2026, Google and Microsoft serve them from campaigns you already run, and Perplexity walked away entirely. Here is how the surface works, how it differs from search, and the tier constraint that decides whether it fits B2B.
The ChatGPT Ads Setup Guide: Launching Your First Campaign
GEO/AEO · practitioner · 11 minCampaign structure, objectives, budget, context hints, creative limits, and the measurement stack to configure before launch, plus the five failure patterns that account for most wasted first-campaign budget.
How to Write Context Hints for ChatGPT Ads
GEO/AEO · practitioner · 10 minContext hints replaced keywords as the targeting control in ChatGPT Ads. Here is the four-part structure that matches well, worked examples at three intent stages, the six mistakes that waste budget, and how to source hints from real buyer language.
Gmail Blue Checkmark: What BIMI Actually Costs in 2026
Email Security · practitioner · 10 minGmail's blue checkmark requires BIMI, DMARC at enforcement, a registered trademark, and a VMC costing $750 to $1,400 a year. Full requirements, steps, costs, and when to skip it.
Roll Out DMARC to p=reject Without Breaking Mail
Email Security · practitioner · 9 minReaching p=reject takes six to eight weeks and one hard prerequisite: naming every system that sends as your domain. The staged rollout, the alignment rule people miss, and what breaks.
The Email Authentication Stack: SPF to BIMI, and How Each Layer Fails
Email Security · intro · 9 minSPF, DKIM, DMARC, ARC, MTA-STS, TLS-RPT, and BIMI in one page: what each layer proves, where the boundaries sit, and why every one of them degrades silently.
Verify an AI Agent: Web Bot Auth and Signed Agent Traffic
AI Security · practitioner · 8 minWeb Bot Auth signs agent requests with a verifiable key, turning "this claims to be ChatGPT" into proof. The drafts, the CDN path, origin verification, and the policy that has to come first.
Verified Builds: SLSA Provenance and Sigstore Signing
AppSec · advanced · 9 minSigstore proves who built it, SLSA provenance proves how. Generation is nearly free on hosted CI; verification with a real policy is the project. Levels, steps, and the silent failures.
Implement Content Credentials (C2PA) Without Breaking Your Pipeline
AI Security · practitioner · 9 minSigning what you produce, verifying what you ingest, and deciding what absence means. The pipeline audit that decides whether any of it survives to the browser.
Deepfake Executive Fraud: The Controls That Actually Work
Identity · intro · 9 minAssume the voice, face, and story are perfect. The controls that still hold are process controls: out-of-band callback, dual authorization, a slow vendor-detail workflow, and a blameless stop.
Blue Checks Are Not Security: What Each Badge Actually Proves
Email Security · intro · 7 minGmail's checkmark proves a trademark. X's proves a payment cleared. LinkedIn's proves an ID matched a face. What each badge checks, what it costs to counterfeit, and why none of them make a message safe.
Glossary
All 73 terms →Short, citable definitions of the identity and security vocabulary, each cross-linked to the guide that explains it in depth.
- SAML
- OIDC
- OAuth 2.0
- SCIM
- JWT
- MFA
- FIDO2
- WebAuthn
- Passkey
- RBAC
- ABAC
- ReBAC
- PBAC
- MCP
- Prompt injection
- Jailbreak (LLM)
- Agentic AI
- Tool use (function calling)
- Guardrails (LLM)
- MLSecOps
- RAG
- Embeddings
- Vector database
- Fine-tuning
- Context window
- Inference
- Quantization
- SIEM
- SOAR
- EDR
- XDR
- Zero trust
- ZTNA
- SAST
- DAST
- JIT Provisioning
- IGA
- PAM
- CIEM
- ITDR
- Session Management
- Refresh Token
- Token Binding
- Magic Link
- SASE
- SSE
- CNAPP
- CSPM
- DSPM
- ASPM
- IAST
- SCA
- Forward Proxy
- Reverse Proxy
- SOCKS5
- TLS Inspection
- BIMI
- VMC
- DMARC
- SPF
- DKIM
- ARC
- MTA-STS
- Web Bot Auth
- C2PA
- SLSA
- Sigstore
- SBOM
- SPIFFE
- mTLS
- llms.txt
- AI Overviews
- Citation Share