Dan Shearer, head and shoulders

I live in Edinburgh, Scotland and work worldwide. If you have a hard or interesting problem let’s talk! You can email dan@shearer.org ↗ as usual or verify and email me securely.

What I work on

I work best in teams, using policy and governance on one side and the technical details of computing and medical/engineering science on the other. Data sovereignty can be protected by elements including open source, encryption, enforcement of laws and mandatory public scrutiny.

Much of my career has involved modifying structures to change where power lies:

  • The world’s most-used software (SQLite) does not offer users privacy on their own devices, so I founded the LumoSQL team, secured 3 years of funding and launched working code in 2026
  • Microsoft locked up files and network servers in proprietary formats, so I co-founded the Samba team as a technical alternative and which helped establish a legal right to interoperability. Samba became a billion-user success, and also showed the limits of this approach
  • EU privacy and AI laws implement human rights to give citizens control over their electronic environment, also impacting giant organisations and states. Clauses in the GDPR, the AI Act, NIS2 and the CRA are structures that can be used, and I work with UK organisations to protect their vital post-Brexit interests in these matters. Conversely, ISO27005 is basically a how-to whose structure fails to improve security.
  • Scottish law guarantees rights regarding the air we breathe in our homes, but there is no easy way to exercise these rights. I co-founded the Active Heat Exchanger project in response, with prototypes demonstrating cheap and effective control even retrofitted to old housing stock.
  • In my most recent university job, my epidemiology research found the One Health global approach to be an extraordinarily ambitious reboot of healthcare. Treating animal and ecological health on a par with human health is a reversal of two hundred years of Anglo-Western ignorance.
  • In my Not Before Time research I propose public infrastructure offering timed-release encryption for journalism, sealed bids, legal instruments and AI content provenance. This kind of control contrasts with always-on, stressful and poorly attested internet norms.
  • My medical observation systems research explores how removing normal control over data also removes errors and distortions. I have analysed all the major observer-only health systems to challenge my own design.

Publications and research writing

  • Shearer, D. (2026). Lumions ↗. Lumions are a novel concept, combining well-understood post-quantum encryption to provide role-based access control (RBAC) with each line of a text file or database row. I defined the Lumion object and byte encoding in two complete draft RFCs, with a working Python demonstration as the basis for row-level encryption in LumoSQL.
  • Shearer, D. (2026). Not Before Time, a proposal for public time-locked encryption infrastructure.
  • Shearer, D. (2026). Active Heat Exchanger, engineering and health research into retrofit ventilation and longitudinal indoor air quality data.
  • Shearer, D. (2026, in preparation). Hidden reservoirs: how host genetic heterogeneity defeats symptom-driven malaria surveillance. eprints.soton.ac.uk/509880 ↗
  • Shearer, D. (2026, in preparation). Discovering Epidemiology and One Health: For Scientists Joining the New Health Collaboration. codeberg.org/rbem/discovering-epidemiology ↗
  • Shearer, D. (2026, in preparation). Lossy by Design, on deliberate information loss in bibliographic systems. codeberg.org/danshearer/lossy-design ↗

Other open source projects

Not-forking (2021 onwards). A prerequisite for LumoSQL and a source code integration tool for non-diffable codebases, able to merge multiple upstreams with a target despite the codebases diverging within defined tolerances over time.

Fossil (2010 to 2023). Hundreds of forum posts and many code commits to the core repository. Also contributed to packaging on Debian, the BSDs and others to ensure packaging was sustainable into the future.

SQLite (2020 onwards). Much interaction with the team and some code commits and bug fixes.

Technical range

Languages. Python, C (applications and systems), Perl, Ruby, R, and assorted scripting languages. Previous work also includes Rust, Java and Lua.

AI and ML. PyTorch, fast.ai, feature engineering, LLM APIs including Anthropic, OpenAI and OpenRouter, multi-agent orchestration, structured output and agentic system design. This also involves data pipeline design from ingestion to trained models, DVC, dbt, Parquet, graph-based reasoning, SQLite internals, MySQL and PostgreSQL.

Reproducibility. DVC, the reproducible-builds tradition, the Turing Way community. The FAIR ↗ framework is talked about a lot, but in practice it is a basic minimum and CARE ↗ (people and ethics) and TRUST ↗ (longevity and institutions) are more relevant to strategy.

Infrastructure. Linux and Unix, HPC (Iridis, Slurm, job arrays), virtualisation including Xen, Incus, IBM zSeries and User Mode Linux, cloud platforms, TCP/IP and many higher-level network protocols, and NVIDIA A100/H100 GPU computing.

Engineering. Git, Fossil, Codeberg and GitHub workflows, CI/CD, tests, documentation and code review.

Open Source. Analysing the strategic and legal implications of open source stacks, including showing how modifying technical internals can alter strategy: network filesystems, SQLite and Postgres internals, local filesystems, user interface models and more.


Where I have worked

Role ended Continues to present
Founder and lead developer, LumoSQL December 2019 – Present
Founded and lead LumoSQL, a modification of SQLite that gives applications encryption, page checksums and incremental backup without changing them. Initially funded by NLnet, in cooperation with the SQLite project and with Vrije Universiteit Brussel’s attribute-based encryption group, across codebases in C, Tcl, JavaScript and Perl. Wrote the Lumion Internet RFC ↗. I was sole budget holder and payment authority, responsible for the safety, scheduling and management of five of the team of seven. LumoSQL ships open-source at-rest encryption for existing SQLite applications without application changes, providing page checksums and incremental backup via LMDB v1.0. The project went quiet in 2023 following COVID-19 injuries and restarted in 2026.
Research Data Scientist, University of Southampton November 2025 – July 2026
Rule Based Epidemic Modelling (RBEM ↗) group, IT Innovation Centre. Worked with the PI on modelling for sub-Saharan malaria and investigated One Health, funded by the MRC Better Methods, Better Research grant programme. Built computable tools for non-epidemiologists to contribute to epidemiological models. Ran simulations on the Iridis HPC facility with Slurm array jobs for large approximate Bayesian computation and parameter fitting. Built AI pipelines to investigate intermediate results.
Perseverance Composition Engine, Leith Document Company December 2025 – April 2026
Developed and dogfooded the Perseverance Composition Engine ↗: an open source multi-agent AI system for document composition and curation. Python, agentic AI, and a LaTeX MCP server that makes it easy to do things rarely done by Western computing people. A structural approach to AI safety using information partition architectures. We also built knowledge bases around complex UK university requirements, including REF 2029.
Research Software Engineer, University of Southampton May 2023 – October 2025
Open source cybersecurity risk assessment, IT Innovation Centre. Spyderisk automated risk assessment of cyber-physical systems: making it open source, and work on risk theory as expressed in software. Ontology-based threat modelling, meaning graph-based reasoning over large structured datasets. Delivered internal training on software engineering practices and open source pipelines.
Technology Review Lead, Open Ocean Capital March 2013 – February 2019
Helsinki and Edinburgh. Technology assessment and product strategy for a Nordic venture capital fund. Investigated and assessed B2B software companies across Europe: codebases, technology stacks, market positioning, product viability. 250 cases to first stage, 20 to second stage, 5 or more to investment committee. Portfolio involvement including board-level review and strategy changes. Embedded in four machine learning startups, optimising data pipelines and aligning the degree of reproducibility with the cost per experiment and the commercial value of particular reproducibility dimensions.
VP Special Projects, Zentyal S.L. February 2013 – November 2015
Zaragoza, Spain. Board member representing investor Open Ocean Oy’s interests. Strategy development with board. Assisted CTO with code integration and workflow across internal teams and between commercial customers and open codebases. Market positioning in multiple dissimilar markets. Working with the external open source teams on Linux, Samba and especially OpenChange.
Cybersecurity and computer science consultant, self-employed January 2013 – April 2023
Scotland. Privacy and security specialist implementing compliance frameworks and resolving complex technology problems, with some law-adjacent work. ISO 27001 implementation for cloud computing, earth sciences and logistics companies. Expert witness in electronic microfabrication before the Court of Session (Ultratech Inc v Stepper Technology Ltd). Radiopharmacology software architecture. Manufacturing fault and fake detection. Software architecture consultancy across diverse domains, each requiring rapid assessment of unfamiliar systems and datasets, and often the initial implementation too.
Senior architect and technical lead, major UK retailer January 2007 – December 2012
Worked as the senior architect and technical lead for a major UK retailer on IT infrastructure from hardware to middleware, introducing virtualised on-premises servers with distributed data solutions. The delivery team had nine people; line management sat elsewhere.
Open Source Lead and Education, Virtutech January 2004 – December 2005
San Francisco and Stockholm. Open source lead for Simics reversible computers ↗. I am still tracking reversibility twenty years later and watching where it lands in AI.
Inetd/Internode January 2002 – December 2003
Worked for Inetd on its Daemon Internet product line, in both Inetd’s and Internode’s data centres. Worked on large-scale email, high-performance shared filesystems and network interoperability.
Senior Enterprise Lead, LinuxCare January 1999 – December 2001
San Francisco. Senior Enterprise Lead at a major Linux support company, including the early migration toolkit and the first Windows replacement paper. From 1998 to 2008 I gave talks around the world representing Samba on how to use Linux to replace Windows NT.
IT Unit, University of South Australia and predecessor institution January 1990 – December 1997
Systems administrator supporting six campuses, beginning at a predecessor institution before the University of South Australia was formed. Microsoft, IBM, VMS, Unix and Linux infrastructure, networking and security operations in a multi-stakeholder university environment. Secondments for software development projects in the Schools of Architecture, Physiotherapy and Mechanical Engineering. This is where Samba started.
Co-founder, Samba Project January 1993 – December 2015
Co-founded Samba, providing file and print services to SMB/CIFS clients. C porting, infrastructure implementation and protocol analysis over two decades. The hardest parts were navigating giant companies objecting to openness and the legal realities that came with it.

Talks

Education and teaching

  • BSc Computer Science, University of South Australia, 1997, taken concurrently with the UniSA IT Unit role above, after ten years of prior industry experience.
  • Part-time security lecturer, South Australian College of Further Education, 1997 to 1999, concurrently with the IIT Training work below.
  • Part-time curriculum and training development, IIT Training Sydney: developed a five-day Linux course for telcos and military, 1997 to 1999.
  • Guest lectures at regional colleges in France on data-centric thinking and pipelining techniques (Pas tout nouveau).
  • Ongoing training delivery in software engineering practice, cybersecurity and open source contribution workflows, and teaching exercises I have either created or been subjected to.