Dear Readers,
We hope you all are doing well. February at Gurzu was full of exciting events. In this edition, we are excited to share highlights from our recent work and reflections from across the team.
Let’s dive in!
Knowledge Ketchup
For those new to it, Knowledge Ketchup is our flavorful twist on the classic ‘lunch and learn’. Each week, a Gurzu team member takes the stage to share something that they know with the rest of the team.
Here are the sessions we had this month:
February 4: Base64 Encoding & JWT Tokens: Understanding Modern Authentication Technologies
Diken delivered an insightful session on JWTs and Base64, explaining how they enable stateless authentication and secure data transmission. The talk covered practical, real-world use cases along with essential security best practices every developer should understand. Find the slide deck here, or you can listen to the podcast of the session here.

Gurzu Blog
At Gurzu, we’re passionate about exchanging ideas and learning out loud. Our blog explores practical development strategies, lessons from real-world projects, and thoughtful perspectives on emerging technologies. Whether you’re building products, leading teams, or simply curious about tech, you’ll find insights tailored for you. Here are some of the latest topics we’ve explored.
QA Testing a Security & Compliance Platform: How we validate trust from governance to remediation (Part I)
In our latest blog of QA Testing security and compliance, we break down how QA goes beyond UI testing to validate governance workflows, control tracking, evidence management, remediation processes, and reporting accuracy.
If your platform influences audit readiness, risk posture, or compliance decisions, QA isn’t optional, it’s mission-critical. Read Part I here.
QA Testing a Security & Compliance Platform: Trust, Defensibility, and the QA Mindset (Part II)
In Part II of the QA testing security and compliance blog, we explore the mindset shift from traditional QA to security-domain QA, where testing isn’t just about features working, but about outputs being accurate, traceable, and defensible.
We share real examples of how QA validates permissions, evidence lifecycle, dashboard accuracy, and audit readiness in high-stakes platforms.
If your product makes claims about being “verified,” “compliant,” or “audit-ready,” QA must validate more than flows, it must validate trust. Read Part II here.
Events
Ruby on Rails Meetup Kathmandu Meetup
Recently, Gurzu had the pleasure of supporting a local Ruby on Rails Meetup event at Siddartha Cottage, Dhobighat on February 27, 2026 where 3 of the expert Ruby on Rails speakers Santosh Sah, Saugat Khadka, and Madhav Poudel presented their knowledge on the topics Upgrading Ruby the Hard Way: A Legacy App Story, The Emperor has no clothes. A journey into agentic systems within Rails, Understanding the Rails Boot Process respectively.
As a company that actively builds and maintains Rails applications, contributing to the community that powers so many great products is something we truly value.

From connecting with fellow developers to exchanging insights on real-world Rails challenges, the event was a great reminder that strong communities build strong software.
We are proud to support initiatives that encourage learning, collaboration, and innovation, and we look forward to many more opportunities to give back to the tech ecosystem.
You’ve read it all!
Your dedication to reading through means a lot to us. Stay tuned for more stories from our office in the upcoming edition.
Gurzu is a full-cycle software development company. Since 2014, we have helped world-class customers get to their markets quickly with high-quality products built with modern software technologies. Our team of experienced developers, designers, and test automation engineers can help you develop your next product.
Have a tech idea you want to turn into reality? Book a free consulting call. or simply, drop us a message.
Thank you!