Skip to content
Excavated foundations on the Byrsa hill at Carthage, the citadel of the ancient city, under a clear Mediterranean sky.

About

Trust is a structure. Someone has to build it.

Arx Fidei takes its name from the Latin for the citadel of trust. The name is not decoration: it describes what we are asked to do.

The story

01

The citadel

In Rome, the arx was the fortified summit of the Capitoline hill. It held the treasury, the auguries and the last line of defence. When the lower city was taken, the arx was what remained — and as long as it stood, the city had not fallen.

Trust in a company works the same way. It is not a statement on a website or a certificate in a frame. It is a structure: decisions recorded, controls that function, evidence you can produce on demand, and people who know what to do at three in the morning. It is built slowly, and it is defended continuously.

02

The pressure

In 2026 the pressure arrives from four directions at once. NIS2 has pulled thousands of mid-size companies into scope and made their directors personally accountable. DORA asks financial entities and their ICT providers to evidence resilience contract by contract. The Cyber Resilience Act turns security into a condition of market access for anything with digital elements. The AI Act sets obligations for organisations that merely use an AI system, not only those that build one.

At the same time, the attack surface has moved. Cloud adoption put critical systems outside the perimeter. Generative AI put company data into tools nobody approved. Supply chains turned every supplier into a possible entry point.

The companies caught in the middle — fifty to two thousand people — rarely have a compliance team. They have an IT manager with a full plate, a CFO watching the budget, and a board that has just discovered it is accountable. The large consulting firms will quote them a programme they cannot afford, staffed by consultants who learned the framework last quarter.

03

The method

We built Arx Fidei for exactly that gap. One senior partner who stays on the engagement from first call to final readout. Four practices — cybersecurity, compliance, cloud and DevSecOps, AI — held by the same people, because the gaps between practices are where findings and incidents live.

Underneath, a unified control framework. NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act ask overlapping questions in different words. We map them once, so a control is implemented once, evidenced once, and reused in every audit that asks for it.

And security built into the delivery pipeline rather than reported on top of it. A finding in a pull request costs an hour. The same finding in an audit report costs a quarter.

04

The proof

Eighty per cent of our catalogue is sold at a fixed price, with the deliverables written down before you commit. Our packs carry names, timelines and price bands, published on this site rather than revealed after a discovery phase.

Our engagement model has six steps and a weekly thirty-minute checkpoint. You always know what has been done, what is next, and whether we are on schedule.

05

The relationship

Compliance is not a project that ends. A certificate has to be maintained, a register kept current, an AI system re-reviewed when it changes. So we are built around recurring services — vCISO, Compliance-as-a-Service, Managed DevSecOps — rather than around one-off missions that leave a report behind and nobody to maintain it.

A pack is usually the way in. What follows is a relationship.

The founder

Founder nameFounder and principal consultant

Arx Fidei was founded by a cybersecurity and compliance specialist with senior experience across regulatory compliance, data security, artificial intelligence, software platforms and cloud infrastructure. Based in France, working across Europe, French-speaking Africa and South America.

The choice to stay small is deliberate. It means the person who scopes your engagement is the person who delivers it, and the person who presents it to your board. It also means we say no to work we cannot do well, and bring in a partner when a mission needs a qualification or a jurisdiction we do not hold ourselves.

Photograph to be supplied before launch.

The partner network

Multi-jurisdiction coverage through partners who practise locally and are vetted before they touch an engagement. We remain your single point of contact and stay accountable for the result.

The walls of the Kasbah of the Udayas in Rabat rising above the river mouth, with the city beyond.
Europe
France, Belgium, Luxembourg, Switzerland, Spain, Germany, Portugal, Italy
Qualified testing and incident response teams, certification bodies, and counsel for national transpositions of NIS2.
French-speaking Africa
Tunisia, Morocco, Senegal, Ivory Coast, Cameroon
Local data protection law, national cybersecurity agencies, and support for subsidiaries of European groups.
South America
Brazil, Argentina, Colombia, Chile
LGPD and national privacy regimes, local hosting requirements, and audit support in Spanish and Portuguese.

Our commitments

Five things we put in the contract, not on a slide.

  1. Confidentiality

    A mutual non-disclosure agreement is signed before any technical detail is exchanged, and it survives the end of the engagement. Findings are never reused as case studies without written permission.

  2. Professional liability insurance

    We carry professional indemnity cover that explicitly includes cyber liability. Certificates are provided with the framework contract.

  3. Vendor independence

    We take no commission, rebate or referral fee from any vendor or partner. When we recommend a tool, it is because it fits your case. Our partner arrangements are disclosed in writing.

  4. Mission data hosted in the EU

    Documents, evidence and findings related to your engagement are stored on infrastructure located in the European Union, under our control, and returned or destroyed at the end of the engagement on your instruction.

  5. Retest included

    Every technical audit includes a retest after remediation, at no additional cost. A finding you have fixed should be closed with evidence, not left open until the next budget cycle.

Start with a conversation

Forty-five minutes, free, and specific to your situation.