Software Engineer | Linux & Open Source | Platform Engineering | Application Security
Portfolio | Email | Secure | Madrid, Colombia
I build and harden production software across Linux tooling, Rust security infrastructure, full-stack platforms, cloud delivery, and application security. My work combines upstream open-source contributions, technical ownership of production systems, and disciplined AI-assisted engineering.
I use coding agents as engineering tools, with typed contracts, automated verification, authorization review, and human validation around production changes. The goal is not faster code generation by itself; it is reliable software with evidence behind it.
- Linux desktop reliability, packaging, update workflows, and cross-distribution compatibility.
- Local-first static analysis, reproducible security measurement, and evidence contracts in Rust.
- Security review and hardening for AI-generated and rapidly evolving codebases.
- Platform architecture across authentication, data, media, administration, and cloud delivery.
- Reusable developer tooling with measurable tests and explicit operational boundaries.
| Project | Engineering scope | Evidence |
|---|---|---|
| Codex Desktop Linux | Ongoing upstream collaboration on Linux reliability, Rust updater inputs, per-user browser integration, CI hardening, dependency maintenance, and regression coverage | Merged contributions |
| UseSecure | Rust analyzer and reproducible benchmark infrastructure, paired with an Open Agent Skill for evidence-backed security review and hardening | Engine · Bench · Skill |
| CMS Nova | Reusable headless CMS foundation with typed, schema-driven content, hybrid persistence, template tooling, and role-based administration | cms-nova-template |
| Production platforms | Architecture and delivery across booking, B2B operations, publishing, localization, authentication, PostgreSQL, AWS-backed media, and deployment workflows | Mitiquete · Conociendo Colombia · TripEuropa |
I am an ongoing contributor to codex-desktop-linux, working across Rust, JavaScript, shell tooling, Nix dependencies, and GitHub Actions.
- Repaired updater fallback inputs and per-user browser-integration socket discovery.
- Hardened privileged CI actions and updated vulnerable native-module build dependencies.
- Added regression coverage and validated changes through Rust tests, script tests, and Fedora package rebuilds.
- Documented and drove remediation of 24 high-severity or critical findings across production systems.
- Designed Zero-Trust RBAC controls across Server Actions and REST endpoints.
- Developed a capability- and invariant-centered review method for AI-assisted changes.
- Delivered an invited talk at the Max Planck Institute for Security and Privacy on structural security risks in AI-assisted software systems.
- Review focus includes authentication, authorization dominance, tenant isolation, secrets, storage, webhooks, payments, and fail-open behavior.
- Languages: TypeScript, Rust, JavaScript, Go, Python, C#, SQL, Java, C, C++
- Web and data: Next.js, React, Astro, Node.js, PostgreSQL, Prisma, Tailwind CSS
- Systems and delivery: Linux, Fedora, Docker, Git, pnpm/Turborepo, Vercel, Coolify, Hetzner
- Cloud: AWS S3, SES, VPS operations, media and deployment workflows
- Security: Zero-Trust RBAC, authorization-boundary review, Server Action and API security, secrets, structural audits
- AI engineering: OpenAI Codex/GPT, Claude Code, Gemini, OpenRouter, context construction, task decomposition, failure-mode analysis
A conservative July 2026 audit measures 370k+ unique, non-generated source-code lines across 21 maintained repositories, including 55k+ lines of Rust. This is supporting context, not a productivity score. It excludes dependencies, lockfiles, documentation, generated and minified files, build output, and duplicate files.
Read the measurement methodology, exclusions, and aggregate breakdown.
I lead software architecture and AI-assisted engineering at Mitiquete SAS while contributing to open-source Linux tooling and developing public security-review infrastructure. I am completing a B.Sc. in Software Engineering at Politecnico Grancolombiano (expected 2027, GPA 4.63/5.0).
Spanish is my native language, and I work professionally in English.
- Portfolio: danielcadev.github.io
- Email: daniel.ca.pe207@gmail.com
- GitHub: danielcadev


