Dan Shearer, head and shoulders

I live in Edinburgh, Scotland and work worldwide. If you have a hard or interesting problem, let’s talk. You can email dan@shearer.org ↗ as usual or verify and email me securely.

What I work on

I work best in teams, using policy and governance on one side and the technical details of computing and medical/engineering science on the other. Data sovereignty can be protected by elements including open source, encryption, enforcement of laws and mandatory public scrutiny.

Much of my career has involved modifying structures to change where power lies:

  • AI alignment efforts are often disappointing, so I worked on an information partitioning and structural solution that enforces better behaviour.
  • SQLite does not encrypt databases by default, so I founded the LumoSQL team, secured three years of funding and launched working code in 2026. This later developed into a different area of cybersecurity, seeking to invert the usual privacy power structure for users.
  • Microsoft locked files and network servers in proprietary formats, so I co-founded the Samba team to provide a technical alternative. Samba also helped establish a legal right to interoperability and became critical infrastructure for a large user base, while showing the limits of this approach.
  • The GDPR ↗ regulates personal-data processing and protects individuals’ data-protection rights. The AI Act ↗ regulates AI systems by risk, NIS2 ↗ sets cybersecurity duties for essential and important entities, and the Cyber Resilience Act ↗ sets cybersecurity requirements for products with digital elements. I work with UK organisations to protect their vital post-Brexit interests in these matters.
  • From 6 October 2026, Scottish regulations ↗ require rented homes to be substantially free from damp and mould, and require landlords who know of either problem to investigate and begin necessary repairs within specified periods. I co-founded the Active Heat Exchanger project to develop controllable retrofit ventilation for old housing stock.
  • In my most recent university job, my epidemiology research examined One Health, which treats human, animal and ecosystem health as an interconnected system and brings many scientific and practical disciplines into a shared framework.
  • In my Not Before Time research I propose public infrastructure offering timed-release encryption for journalism, sealed bids, legal instruments and AI content provenance. This kind of control contrasts with always-on, stressful and poorly attested internet norms.
  • My medical observation systems research tests whether separating observation from clinical care reduces observer effects and reporting biases caused when diagnosis or treatment changes a participant’s disease trajectory. I compared my design with 25 systems used during the past 90 years.

Research writings

  • Shearer, D. et al. (2024). […] How Causal Models Highlight Stakeholder Data-Protection Tussles, DOI 10.1007/978-3-031-76821-7_22 ↗
  • Shearer, D. et al. (2026, PLOS-One, in review). Hidden reservoirs: how host genetic heterogeneity defeats symptom-driven malaria surveillance. eprints.soton.ac.uk/509880 ↗
  • Shearer, D. and Waites, W. (2026, in preparation). Discovering Epidemiology and One Health: For Scientists Joining the New Health Collaboration. discovering-epidemiology.pdf ↗
  • Shearer, D. (2026, in preparation). Lossy by Design, on deliberate information loss in bibliographic systems due to cultural & linguistic bias.
  • Shearer, D. (2026). Active Heat Exchanger, engineering and health research into retrofit ventilation and longitudinal indoor air quality data.
  • Shearer, D. (2026). Lumions prototype Internet-draft RFC ↗. Self-contained data objects defined by rules which provide role-based access control for lines in a text file or database row. Comes with a working Python demonstration.
  • Shearer, D. (2026). Not Before Time, a proposal for public time-locked encryption infrastructure.

Larger open source projects

Not-forking (2021 onwards). Software reproducibility tool able to do source code integration tool for non-diffable codebases. Able to merge multiple upstreams with a target despite the codebases diverging within defined tolerances over time. This has lead to further research in the topic of developer intent.

Fossil (2010 onwards). Code commits and community contributions to the core repository. Engage with packaging teams on multiple Linux and BSD operating systems to ensure Fossil gets distributed.

SQLite (2020 onwards). Much interaction with the team and some code commits and bug fixes.

Technical range

Languages. Python, C (applications and systems), Perl, Ruby, R, and assorted scripting languages. Previous work also includes Rust, Java and Lua.

AI and ML. PyTorch, fast.ai, feature engineering, LLM APIs including Anthropic, OpenAI and OpenRouter, multi-agent orchestration, structured output and agentic system design. This also involves data pipeline design from ingestion to trained models, DVC, dbt, Parquet, graph-based reasoning, SQLite internals, MySQL and PostgreSQL.

Reproducibility. DVC, the reproducible-builds tradition and the Turing Way community. For my strategy work, FAIR ↗ is a baseline, while CARE ↗ and TRUST ↗ contribute more to ethical governance and institutional longevity.

Infrastructure. Linux and Unix, HPC (Iridis, Slurm, job arrays), virtualisation including Xen, Incus, IBM zSeries and User Mode Linux, cloud platforms, TCP/IP and many higher-level network protocols, and NVIDIA A100/H100 GPU computing.

Engineering. Git, Fossil, Codeberg and GitHub workflows, CI/CD, tests, documentation and code review.

Open Source. Analysing the strategic and legal implications of open source stacks, including showing how modifying technical internals can alter strategy: network filesystems, SQLite and Postgres internals, local filesystems, user interface models and more.


Where I have worked

Role ended Continues to present
Founder and lead developer, LumoSQL December 2019 – Present
Founded and lead LumoSQL, a modification of SQLite. Initially funded by NLnet, in cooperation with the SQLite project and with Vrije Universiteit Brussel’s attribute-based encryption group, across codebases in C, Tcl, JavaScript and Perl. Wrote the Lumion Internet RFC ↗. I was sole budget holder and payment authority, responsible for the safety, scheduling and management of five of the team of seven. LumoSQL ships open-source at-rest encryption for existing SQLite applications without application changes, providing page checksums and incremental backup via LMDB v1.0. The project went quiet in 2023 following COVID-19 injuries and restarted in 2026.
Research Data Scientist, University of Southampton November 2025 – July 2026
Rule Based Epidemic Modelling (RBEM ↗) group, IT Innovation Centre. Worked with the PI on modelling for sub-Saharan malaria and investigated One Health, funded by the MRC Better Methods, Better Research grant programme. Built computable tools for non-epidemiologists to contribute to epidemiological models. Ran simulations on the Iridis HPC facility with Slurm array jobs for large approximate Bayesian computation and parameter fitting. Built AI pipelines to investigate intermediate results.
Perseverance Composition Engine, Leith Document Company December 2025 – April 2026
Developed the Perseverance Composition Engine ↗, an open source multi-agent Python system, and used it internally to compose and curate documents. Its LaTeX MCP server supports bibliographies spanning multiple scripts, languages and historical eras. The engine takes a structural approach to AI safety using information-partition architectures. We also built knowledge bases around complex UK university requirements, including REF 2029.
Research Software Engineer, University of Southampton May 2023 – October 2025
Open source cybersecurity risk assessment, IT Innovation Centre. Spyderisk automated risk assessment for cyber-physical systems. I helped make it open source and worked on its software representation of risk theory. Ontology-based threat modelling, meaning graph-based reasoning over large structured datasets. Delivered internal training on software engineering practices and open source pipelines.
Technology Review Lead, Open Ocean Capital March 2013 – February 2019
Helsinki and Edinburgh. Technology assessment and product strategy for a Nordic venture capital fund. Investigated and assessed B2B software companies across Europe: codebases, technology stacks, market positioning, product viability. Portfolio involvement including board-level review and strategy changes.
VP Special Projects, Zentyal S.L. February 2013 – November 2015
Zaragoza, Spain. Board member representing investor Open Ocean Oy’s interests. Strategy development with board. Assisted CTO with code integration and workflow across internal teams and between commercial customers and open codebases. Market positioning in multiple dissimilar markets. Working with the external open source teams on Linux, Samba and especially OpenChange.
Cybersecurity and computer science consultant, self-employed January 2013 – April 2023
Scotland. Privacy and security specialist implementing compliance frameworks and resolving complex technology problems, with some law-adjacent work. ISO 27001 implementation for cloud computing, earth sciences and logistics companies. Expert witness in electronic microfabrication before the Court of Session (Ultratech Inc v Stepper Technology Ltd). Radiopharmacology software architecture. Manufacturing fault and fake detection. Software architecture consultancy across diverse domains, each requiring rapid assessment of unfamiliar systems and datasets, and often the initial implementation too.
Senior architect and technical lead, major UK retailer January 2007 – December 2012
Worked as the senior architect and technical lead for a major UK retailer on IT infrastructure from hardware to middleware, introducing virtualised on-premises servers with distributed data solutions. The delivery team had nine people; line management sat elsewhere.
Open Source Lead and Education, Virtutech January 2004 – December 2005
San Francisco and Stockholm. Open source lead for Simics reversible computers ↗. I am still tracking reversibility twenty years later and watching where it lands in AI.
Inetd/Internode January 2002 – December 2003
Worked for Inetd on its Daemon Internet product line, in both Inetd’s and Internode’s data centres. Worked on large-scale email, high-performance shared filesystems and network interoperability. Co-sponsored the Shearer.org/Inetd experimental conference CD.
Senior Enterprise Lead, LinuxCare January 1999 – December 2001
San Francisco. Senior Enterprise Lead at a major Linux support company, including an early migration toolkit and Windows NT replacement paper. From 1998 to 2008 I gave talks around the world representing Samba on how to use Linux to replace Windows NT.
IT Unit, University of South Australia and predecessor institution January 1990 – December 1997
Systems administrator supporting six campuses, beginning at a predecessor institution before the University of South Australia was formed. Microsoft, IBM, VMS, Unix and Linux infrastructure, networking and security operations in a multi-stakeholder university environment. Secondments for software development projects in the Schools of Architecture, Physiotherapy and Mechanical Engineering. This is where Samba started.
Co-founder, Samba Project January 1993 – December 2015
Co-founded Samba, providing file and print services to SMB/CIFS clients. C porting, infrastructure implementation and protocol analysis over two decades. The hardest parts were navigating giant companies objecting to openness and the legal realities that came with it.

Talks

Education and teaching

  • BSc Computer Science, University of South Australia, 1997, taken concurrently with the UniSA IT Unit role above, after ten years of prior industry experience.
  • Part-time security lecturer, South Australian College of Further Education, 1997 to 1999, concurrently with the IIT Training work below.
  • Part-time curriculum and training development, IIT Training Sydney: developed a five-day Linux course for telcos and military, 1997 to 1999.
  • Guest lectures at regional colleges in France on data-centric thinking and pipelining techniques (Pas tout nouveau).
  • Ongoing training delivery in software engineering practice, cybersecurity and open source contribution workflows, and teaching exercises I have either created or been subjected to.