Metaluxo
ABOUT

Often the only dedicated security person in the room

Roberto Arias brings nearly 20 years in IT, 14 of them in information security and five as a fractional CISO. He holds a Master's degree in Information Security and a Postgraduate Certificate in Policing, Intelligence and Counter-Terrorism, both from Macquarie University, Australia.

He has spent most of his career as the only dedicated security person in the business — the position most Metaluxo clients are in. It is why the work starts with decisions rather than frameworks, and why engagements are scoped honestly enough to include telling you that you need someone else.

Metaluxo works remotely with clients across the EU and beyond, from Poland, in English and Spanish. Sector focus is healthtech and medtech, fintech, B2B SaaS selling into regulated buyers, and regulated crypto businesses. We do not work with large enterprises.

Book a free 30-minute consultation →
Roberto Arias, founder of Metaluxo
Roberto Arias Founder · Virtual CISO and GRC consultant
TRUST & ASSURANCE

We hold ourselves to what we ask of clients

A security consultancy that cannot evidence its own posture is asking you to take it on faith. These are independent, externally scored, and current.

SecurityScorecard
Continuous external rating of our own attack surface. Live embed to be added.
ImmuniWeb
Independent web and application security assessment. Badge embed to be added.
GDPR compliant
We meet our obligations as controller and processor. GDPR certification does not exist — treat any such claim with caution.
UK Cyber Essentials
In progress. Reserved, and left empty until the certificate is actually awarded.
We publish only what an independent party has verified. Where something is in progress we say so rather than implying it is done.
01 Who is accountable ONE NAMED PERSON
Roberto Arias, founder of Metaluxo
Roberto Arias Founder · Virtual CISO and GRC consultant

You are hiring a person, not a platform

Metaluxo is led by Roberto Arias, who brings nearly 20 years in IT, 14 of them in information security and five as a fractional CISO. He holds a Master's degree in Information Security and a Postgraduate Certificate in Policing, Intelligence and Counter-Terrorism, both from Macquarie University, Australia.

The person who scopes your engagement is the person who reads your architecture, reviews your cloud configuration and talks to your engineers directly. Nothing is passed to a delivery team you have never met. We work remotely across the EU from Poland, travelling when being in the room matters, in English and Spanish.

20 YEARS IN IT
14 IN INFORMATION SECURITY
5 AS A FRACTIONAL CISO
More about Roberto →
02 What we are not SAID ON THE FIRST CALL
Half of the value is being told, in the first call, that you need someone else
Not a testing firm We do not run penetration tests. We define what needs testing, help you select and brief a qualified provider, and make sure remediation actually happens.
Not a forensics firm We do not image drives or reverse engineer malware. We direct the teams who do, and we do not negotiate with attackers.
Not a certification body No consultant can guarantee a certificate, and only a licensed CPA firm issues a SOC 2 report. We make sure nothing reaches Stage 2 untested.
We also do not work with large enterprises, and we do not work on US-specific regimes such as HIPAA, HITRUST or FedRAMP. If that is what your buyer requires, we will say so early.
EVIDENCE

What the work looks like when it is finished

Client names stay confidential unless a client asks otherwise. What we can show is the shape of an engagement: what triggered it, what changed, and what the company was left holding.

01 How an engagement gets written up FOUR-PART
02 What we can show today
CASE STUDY 01
Engagement write-up in preparation The first published engagement is being written up with the client's agreement. It will follow the four-part structure below, so a prospective client can compare their own situation against it directly.
01THE TRIGGER The deal, questionnaire, audit date or regulator letter that started it.
02THE STARTING POSITION Team size, stack, what existed on paper and what existed in practice.
03WHAT WE DID Decisions taken, in sequence, with the ones we advised against.
04WHERE IT LANDED The outcome, the timeline it actually took, and what remained open.
IN CLIENTS' WORDS No testimonials are published yet We would rather run an empty section than a manufactured one. Client quotes go here once they are given and cleared.
OUR OWN CERTIFICATION Cyber Essentials, in progress
TERMS YOU CAN HOLD US TO

Published before you ask for them

A young practice cannot borrow trust from a wall of logos. It can put its terms in public and be judged on whether it keeps them.

01 How we engage SIX COMMITMENTS
SCOPE Fixed scope, priced before we start The gap assessment is a fixed scope of work at a fixed price, agreed in writing before any work begins. Around four weeks, with a defined output.
COMMITMENT A retainer you can size Ongoing work runs at 30–40 hours a month, or as a fixed-scope project. No minimum term dressed up as a partnership.
OWNERSHIP You keep everything produced Policies, risk register, roadmap and evidence are yours, in editable form, whether or not the engagement continues.
CONFIDENTIALITY Under NDA, by default We sign your NDA before the first technical conversation. Client names are never published without written permission, which is why none appear here.
CONTINUITY The person you meet is the person who works Nothing is handed to a delivery team you have not met. If the work needs a specialist we do not employ, we say so and help you brief them.
RESPONSE Twelve hours, in an emergency Emergency contact is answered within 12 hours, and often faster inside CET business hours. That is the commitment, not a marketing number.
02 What stands in for testimonials UNTIL CLIENTS ARE NAMED
Client references are available on request, given directly to you by the client rather than written for a website. The first published engagement write-up is in preparation. Ask for a reference →
Send us a message
Message us Book now