Available for new engagements from November 2026

Analytics and AI on data that can’t be shared.

Consulting in privacy-preserving machine learning, secure multiparty computation (MPC), homomorphic encryption (FHE) and high-performance compilers: protocol design, production systems, and the performance engineering that makes them viable.

Free intro call · NDA on request · Reply within 2 business days

How secure multiparty computation works A hospital, a biobank and a research lab each keep their own data. They exchange only meaningless fragments and jointly compute a result, which is the only thing revealed. Joint result Hospital patient records Biobank genotypes Research lab cohort data
Each party sends out only meaningless fragments of its data. Together they compute the answer. Raw data never leaves its owner.

Published at IEEE S&P · USENIX Security · npj Digital Medicine · Genome Biology · ACM Compiler Construction · CGO

Institutions and teams worked with

  • Yale University
  • Stanford University
  • MIT
  • Broad Institute
  • National Institutes of Health
  • U.S. Department of Veterans Affairs
  • UTHealth Houston
  • University of Pennsylvania
  • University of Victoria
  • University of Sarajevo
  • Exaloop
  • Algemetric
  • EagleView
  • Fathom Health
  • Symphony.is
01

Ways to work together

Every engagement is scoped to a clear deliverable. The usual starting point is a feasibility study:
identifying what is possible to run and at what cost, before committing engineering budget.

Typically 4–12 weeks

Prototype & implementation

Turns an analysis that today needs all the data in one place into software that runs across the data holders’ own systems, so the raw data never moves. For example, a joint statistical study across hospitals that cannot exchange patient records. The work starts as a prototype on test data and ends as a system running in each participant’s environment.

Deliverables
  • A working secure version of the workflow
  • A check that its results match the original analysis
  • Runtime and cost measurements on realistic data
  • Source code, deployment instructions and documentation
  • Walkthroughs and training for the team taking it over
Best for
Teams with a defined workflow and data that cannot be pooled.
From $30,000 Discuss a build
Scoped per project

Performance engineering

Makes computation that works, but too slowly, fast enough to use. That covers secure computation that takes hours where minutes are needed, and general data pipelines that have outgrown their hardware. Optimization reaches from the protocol down to the compiler: LLVM passes, vectorization and SIMD, CUDA.

Deliverables
  • A profiling report showing where the time goes
  • An optimized implementation
  • Before-and-after benchmarks
Best for
Tech startups and research teams hitting a performance wall.
From $15,000 Discuss performance
Monthly retainer or ad hoc

Advisory, due diligence & training

Independent expert judgement without a full project: a second opinion on a protocol, an architecture or a roadmap, an assessment of a technology or a vendor’s claims, or training for a team entering the field.

Deliverables
  • Protocol and architecture reviews, with written findings
  • Technical due diligence for investors
  • Help hiring for cryptography roles
  • Workshops for teams new to the field
Best for
Founders, CTOs and investors in privacy-enhancing technology.
From $3,500 per month Discuss advisory
Domains

Deepest experience in biomedical informatics. The same techniques apply to finance, advertising and private AI inference.

02

Selected work

Research deployments, open-source frameworks and industry systems, all built to run on real data.

Open-source frameworks · MPC & HE

Sequre & Shechi: secure computation that’s practical to write and fast to run

ContextSecure computation frameworks were too slow, and too hard to program, for real biomedical workloads.

ContributionDesigned and built two Pythonic frameworks with their own compilers: Sequre for secure multiparty computation and Shechi for multiparty homomorphic encryption. Both optimize secure programs automatically.

OutcomeMade large-scale secure genome-wide association studies, drug–target interaction inference, metagenomic binning and kinship estimation feasible for the first time. Sequre runs up to 3–4 times faster than existing pipelines with 7-fold smaller codebases; Shechi runs up to 15 times faster than the prior state of the art.

Genome Biology 2023 (Featured Article) · USENIX Security 2025

Protocol research · MPC

Decor: accurate nonlinear functions inside MPC

ContextTrigonometric, exponential and sigmoid functions are everywhere in machine learning and statistics, but MPC protocols evaluate them through polynomial approximations that are costly and imprecise.

ContributionDesigned a framework that generalizes Beaver multiplication triples, a cornerstone of MPC, to a broad class of nonlinear functions: the costly operations are delegated to an offline phase that computes only on random values.

OutcomeOrders-of-magnitude better accuracy at comparable or faster runtimes than existing approaches, shown on image representation and on logistic models for genome-wide association studies.

IEEE Symposium on Security and Privacy 2026

Clinical data · EHR

Secure MICE: hospitals filling gaps in health records together

ContextElectronic health records are full of gaps. The standard fix, multiple imputation (MICE), normally needs all the data in one place.

ContributionBuilt a secure, distributed multiple imputation algorithm on Sequre.

OutcomeHospitals can impute and analyze incomplete records jointly without sharing them.

npj Digital Medicine (Nature Portfolio)

Compilers · LLVM

Codon: a high-performance Python compiler

ContextPython is productive but slow. Codon compiles it to native code through LLVM.

ContributionCo-authored the paper and contributed to core pieces: the SIMD module, a security module, and optimization passes for a high-performance NumPy-style ndarray.

OutcomeAn open-source compiler with 16k+ GitHub stars.

ACM Compiler Construction 2023

More work
  • Secure pharmacogene genotyping In progress

    Genotyping pharmacogenes from private genomic sequences in outsourced, untrusted cloud environments.

  • Vectron: auto-vectorization for dynamic programming

    A compiler framework that automatically vectorizes dynamic-programming algorithms. CGO 2025 paper.

Before research: five years in industry

Lead software, algorithm and ML engineer at Symphony.is in Sarajevo, delivering remotely for U.S. clients.

  1. 2019–2020

    EagleView

    Led a team of eight building algorithms that extract roof outlines and reconstruct 3D roof models from LiDAR point clouds of entire towns.

    C++ · Point Cloud Library · CGAL · Python · AWS

  2. 2017–2019

    A global chemical company U.S. & Australia · name under NDA

    As lead algorithm engineer, remodeled bottlenecks in engineering pipelines using convex optimization and computational geometry, and set the direction for the company’s data-science work.

    Python · NumPy · SciPy · Keras

  3. 2016–2017

    Fathom Health

    Data engineering for deep-learning medical coding: a named-entity gazetteer built on medical n-grams, negation and context detection, and a grammar that generates realistic synthetic medical records for training.

    Python · TensorFlow · Airflow · Docker

03

Choosing the right technique

Several technologies let organizations compute on data they can’t share. They make different trade-offs, and most real systems combine more than one.

Privacy-enhancing techniques compared
Technique What it does Good for Main trade-off
Secure multiparty computation MPC Several parties compute a joint result; nobody sees anyone else’s inputs. Cross-institution statistics, joint model training. Communication-heavy; parties stay online during the computation.
Homomorphic encryption FHE Computes directly on encrypted data. Outsourcing to an untrusted server, private inference. Compute-heavy; works best when the computation is kept shallow.
Multiparty homomorphic encryption MHE Combines the two: shared keys, encrypted computation across parties. Many-party studies at scale; the basis of Shechi. More complex to engineer well.
Trusted execution environments Secure hardware Runs code inside hardware-isolated enclaves. Speed, and running arbitrary existing code. Requires trusting the hardware vendor; side-channel risk.
Federated learning The model travels; the data stays put. Large-scale training across sites. Model updates can leak information unless combined with the techniques above.
Differential privacy Adds calibrated noise to released results. Publishing statistics about individuals safely. Trades accuracy for privacy; complements the others.

Where the right choice is unclear, a feasibility study settles it.

Discuss a use case
04

How an engagement works

  1. 01

    Intro call

    Thirty minutes, free of charge: the data, the parties and the goal, followed by a frank assessment of feasibility.

  2. 02

    Proposal

    Within 5 business days: a written scope with deliverables, timeline and, where possible, a fixed price.

  3. 03

    Delivery

    Weekly written updates and calls in the client’s time zone.

  4. 04

    Handoff

    Code, documentation and a walkthrough with the client’s team, so the system can be run and extended in-house.

Confidential by default

NDAs welcome. Client work and client names are never disclosed without permission.

Clear ownership

Client owns the deliverables. Pre-existing tools and open-source components keep their existing licenses.

Remote-first, across time zones

Based in New Haven (ET). Full overlap with U.S. working hours and European afternoons. Available for short-term co-location.

05

About

Haris Smajlović is a cryptography and compilers expert based in New Haven. After five years as a lead software and ML engineer delivering for U.S. companies, Haris completed a Ph.D. at the University of Victoria on secure computational genomics and is now a postdoctoral associate at Yale.

Haris is the author of the Sequre and Shechi frameworks and a contributor to the Codon compiler, with publications at IEEE S&P, USENIX Security, Genome Biology and npj Digital Medicine. The common thread is turning protocols that work on paper into systems that hospitals, biobanks and companies can run.

NowPostdoctoral Associate at Yale, with Hyunghoon Cho · Technical Advisor at Algemetric

  1. 2026–Technical Advisor Algemetric
  2. 2025–Postdoctoral Associate Yale University
  3. 2020–2024Ph.D., Computer Science University of Victoria
  4. 2017–2020Lecturer, Computational Geometry University of Sarajevo
  5. 2015–2020Lead software & ML engineer Symphony.is
  6. 2012–2017M.Sc. & B.Sc., Theoretical Computer Science University of Sarajevo
Honours
Golden Badge of the University of Sarajevo · Genome Biology Featured Article · UVic Graduate Award, 2020–2024 · UVic Ph.D. Fellowship
Tools
Python · C/C++ · LLVM · CUDA · Go
06

Research & talks

Selected papers

  1. IEEE S&P 2026 Decor: Delegated Computation on Randomness for Secure Evaluation of Nonlinear Functions Smajlović, Sheng, Antonopoulos, Piskac, Cho
  2. npj Digital Medicine 2026 Secure distributed multiple imputation enables missing data inference for private data proprietors Smajlović, Lian, Long, Numanagić, Jiang
  3. USENIX Security 2025 Shechi: A Secure Distributed Computation Compiler Based on Multiparty Homomorphic Encryption Smajlović, Froelicher, Shajii, Berger, Cho, Numanagić
  4. CGO 2025 Vectron: A Dynamic Programming Auto-vectorization Framework Naser Moghaddasi, Smajlović, Shajii, Numanagić
  5. Genome Biology 2023 · Featured Sequre: A high-performance framework for secure multiparty computation enables biomedical data sharing Smajlović, Shajii, Berger, Cho, Numanagić
  6. ACM CC 2023 Codon: A Compiler for High-Performance Pythonic Applications and DSLs Shajii, Ramirez, Smajlović, Ray, Berger, Amarasinghe, Numanagić

Talks

  • 2026IEEE S&P, San Francisco · Decor
  • 2025USENIX Security, Seattle · Shechi
  • 2025CEGS Annual Meeting, Pittsburgh · Secure federated association studies and risk modeling
  • 2025AMLD, Lausanne · Invited: Enabling accessible and secure federated AI by design
  • 2025RECOMB, Seoul · A compiler for secure computing, and secure distributed MICE for EHRs
  • 2023RECOMB, Istanbul · Sequre
  • 2022HiCOMB, Lyon (remote) · Sequre

Service

Program committee, RECOMB-Arch. Reviewer for ACM CC, ISMB, RECOMB, Genome Biology and the Journal of Biomedical Informatics.

07

Common questions

Is the work limited to healthcare and genomics?

No. Genomic and clinical data are where the experience runs deepest, but the same techniques apply wherever organizations need to compute on data they cannot share: finance, advertising, private AI inference and the public sector.

MPC, FHE, secure hardware or federated learning: which one fits?

It depends on who holds the data, which parties are trusted, and the performance budget. The comparison above is a starting point; a feasibility study gives a definite answer for a specific case.

Can the work proceed under an NDA and our security requirements?

Yes. Client work is confidential by default, and engagements can operate within institutional data-governance rules.

How does remote collaboration work in practice?

The practice is based in New Haven (ET), with full overlap with U.S. working hours and with European afternoons. Engagements run on weekly written updates and calls in the client’s time zone. Short-term co-location is available.

How is pricing structured?

Feasibility studies are a fixed fee from $8,000, depending on the number of parties and the complexity of the computation. Implementation and performance projects are quoted at a fixed price after scoping, typically between $15,000 and $120,000. Advisory retainers start at $3,500 per month for roughly two days of time; one-off technical due diligence starts at $5,000. All prices are in U.S. dollars.

Can the work be done alongside our engineers?

Yes. Most engagements end with a handoff (documentation, code walkthroughs and training) so the client’s team owns the system.

Are academic groups and grant teams a fit?

Yes, as a collaborator or subcontractor on projects that involve secure data sharing. Experience includes work as named personnel on NIH- and NSF-funded projects.

08 Contact

Data that can’t be shared can still be put to work.

A free 30-minute call is the usual first step. Written inquiries are equally welcome; the most useful ones cover:

  • The organization
  • What data is involved, and who holds it
  • What needs to be computed
  • The timeline
Reply time
Within 2 business days
Local time
in New Haven
Availability
New engagements from November 2026