Build platforms before they become problems.

An engineering studio for startups whose platforms need to grow up.

MTLabs builds the foundations that let a growing team ship fast without accumulating a decade of technical debt: infrastructure, delivery, security and developer experience.

Studio spec001
Studio
MTLabs
Founder
Marco Tomás
Practice
Platform · AI infra · Cloud
Clients
Startups, seed to Series B
Base
Lisbon · remote-first
Availability
Limited, by enquiry
Marco Tomás · previously at
J.P. MorganVodafoneFarfetchGlobal SharesExpert Thinking
Employment history. Not MTLabs engagements.

Platform problems are cheap to prevent and expensive to fix. The decisions a team makes in its first two years decide how fast it moves in its fifth. MTLabs exists to make those decisions early, and on purpose.

§ 01Studio

Serious platform engineering, at startup scale

MTLabs is the engineering studio of Marco Tomás, Principal Platform Engineer. Fifteen years spent building the platforms that banks, telcos and marketplaces run on: multi-region Kubernetes, zero-trust networks, infrastructure entirely in code.

MTLabs brings that discipline to companies years away from needing a platform team, and who can’t afford to get the foundations wrong in the meantime. Not an agency and not a body shop: one principal engineer, a small number of engagements a year, and the same hands from the architecture diagram to the on-call rotation.

When founders call

01
You’ve just raised a round, and the deploy process lives in one engineer’s head.

It works until that person is on holiday, or leaves. The first thing MTLabs builds is a path anyone on the team can take to production.

02
Headcount is about to double and nothing is paved.

Every new engineer costs a week of someone else’s time. Golden paths turn that into an afternoon.

03
An enterprise customer sent a security questionnaire.

Identity, network boundaries, secrets, audit trails: built in once and answered forever, instead of assembled per deal.

04
The cloud bill is growing faster than revenue.

Usually a design problem, not a discount problem. It gets fixed at the architecture, and then it stays fixed.

How it gets built

Roads

Paved paths, so every engineer ships without waiting on you.

Rails

Safe-by-default guardrails, so the easy way is the right way.

Radar

Observability and AI-assisted ops, so problems surface before customers find them.

What that covers

  • Platform engineering
  • AI infrastructure
  • Cloud architecture
  • Kubernetes
  • Infrastructure as code
  • Security by design
  • CI/CD
  • Observability
  • Developer experience
  • Engineering leadership
  • Technical strategy

Built with

  • Azure
  • AWS
  • GCP
  • Terraform
  • Kubernetes
  • Helm
  • GitHub Actions
  • Datadog
  • Grafana
  • Prometheus
  • Cloudflare
  • Go
  • Python
  • Claude
§ 02Outcomes

What changes

Engineering work is easy to describe and hard to judge. These are the differences a founder should be able to see within a quarter.

Deploys stop being an event.

Any engineer ships to production in their first week, without a senior watching.

Onboarding measured in days.

Environments, access and a working local setup come from a script, not a Notion page.

Security reviews that don’t stall the deal.

Identity-first access, network boundaries and audit trails: the evidence SOC 2 and ISO 27001 questionnaires require, ready before procurement asks.

A cloud bill you can explain.

Costs attributed per environment and per team, designed down instead of discounted.

Fewer 3am incidents.

Observability tuned for signal, with AI-assisted triage. On one multi-region estate, average incident resolution fell from about two hours to about thirty-five minutes.

A platform your next hire can inherit.

Everything in code, documented, and boring enough to hand over.

§ 03Engagements

Three ways to work together

Three fixed shapes, each with explicit scope and a written outcome. Nothing open-ended: the continuing engagement runs in quarters, and every quarter is renewed deliberately or not at all.

Platform Review

1–2 weeks · fixed fee

For

Teams who suspect the foundations won’t survive the next year of growth, and want to know before the next hire.

Includes

  • Infrastructure, delivery, security and cost assessment
  • Architecture review with your engineers
  • Written report with a prioritised plan

You end with

A ranked list of what to fix, in what order, and the cost of leaving each one alone.

Platform Foundation

4–8 weeks · project

For

Post-seed teams putting real customers on the product, still deploying by hand or by hero.

Includes

  • Environments and infrastructure entirely in Terraform
  • CI/CD with safe, repeatable, auditable deploys
  • Kubernetes or serverless baseline, sized honestly
  • Observability, secrets, identity and runbooks

You end with

A paved road your team owns: documented, in your repos, with no dependency on MTLabs.

Embedded Principal

Quarterly · 1–2 days a week

For

Series A/B teams that need principal-level platform judgement before they can justify a full-time principal salary. Scoped one quarter at a time.

Includes

  • Architecture decisions and technical strategy
  • Standards, reviews and on-call design
  • Hiring and mentoring the first platform engineers

You end with

A platform that grows with the team, and engineers ready to run it without the studio.

Every engagement starts the same way: a 15-minute call to establish whether there is a fit. If there is, a longer working session follows, and a written assessment within two business days setting out what MTLabs would tackle first, what it would leave alone, and what the work would cost. If MTLabs isn’t the right partner, you’ll know on the first call, not the third.

§ 04Principles

Engineering principles

Seven positions the studio keeps returning to. Not slogans, but the reason the architecture ends up looking the way it does.

Invisibility

Platforms should disappear.

The best infrastructure is never noticed. Teams ship, all day, without thinking about the road under them.

Complexity

Complexity is a liability.

Every abstraction has a carrying cost, and it’s paid at 3am by someone who didn’t write it.

Right-sizing

Build for next year, not the next decade.

A twelve-person team doesn’t need a bank’s architecture. It needs the handful of practices that prevent the expensive problems.

Trust

Trust is earned through consistency.

One reliable deploy proves nothing. A thousand identical ones become a promise the business can plan around.

Experience

Developer experience is a product.

Your engineers are the users. Adoption, not elegance, is how a platform gets judged.

Ownership

The studio should be replaceable.

Everything in code, in your repos, documented. An engagement that creates dependency has failed.

Cognition

Engineering exists to reduce cognitive load.

Every paved road, guardrail and sane default buys back attention for the product.

§ 05Products

What the studio is building

Two products that started inside client work: Opsyron, for operational correlation, and Opsyron Security, for cloud-security decisions. MTLabs is the studio; Opsyron is the product line.

An MTLabs product · in development

Opsyron Security: reduce risk, not alerts.

Most cloud-security tools surface thousands of findings. Opsyron Security turns them into the short list of actions that remove the most risk, with the evidence, business impact and remediation plan behind each one. Identity-first, across Azure, AWS and GCP.

Prioritises what matters
Thousands of findings become the few decisions that cut the most risk.
Explains every decision
Evidence, business impact and a remediation plan. Machines analyse, humans stay in control.
Identity-first, multi-cloud
Starts with identity governance across Azure, AWS and GCP.
An MTLabs product · in development

Opsyron: explains why, not just what.

An operational platform built in-house. Cloudflare, Azure, AWS, GCP, Datadog, GitHub and Kubernetes are normalised into one event model, then related through a graph of services, environments, deployments and alerts. Cloud resources are discovered rather than declared, so the inventory includes what nobody remembered was running.

One event model
Seven providers, one operational event. Azure and AWS resources discovered automatically today, GCP next.
Correlation you can audit
Causal rules across services, deployments and alerts. Every conclusion can be traced back, not taken on trust.
A risk score that opens
Each service scores 0–100, and the score decomposes into the events and the actions behind it.
§ 06Notes

Engineering essays

Not a blog. Notes are written from the work: arguments worth defending, mistakes worth documenting, positions that changed after contact with production. Five are in draft.

N/01

Build platforms before they become problems

The studio’s thesis, and the arithmetic behind it: what prevention costs against what repair costs.

Strategy · in draft
N/02

What a Series A platform actually needs

The short list, and the longer list of things founders get sold before they need them.

Platform · in draft
N/03

Why internal platforms fail

Adoption is the only score that counts, and most platforms lose it in the first quarter.

Platform · in draft
N/04

Automation isn’t the goal

Removing friction is. The difference decides what you automate first.

Automation · in draft
N/05

The cost of complexity

Every abstraction is a loan. A note on the interest rate.

Architecture · in draft

Follow MTLabs for the first one

§ 07Lab

Research, open source and talks

The Lab is the studio’s non-billable half: where patterns get tested before they reach a client, released when they’re worth releasing, and explained in public.

Research

AI-assisted incident response

On-call triage tooling, developed against real post-mortems and measured on a live estate.

Active
Right-sized Kubernetes

Where k3s beats managed clusters for teams under twenty engineers.

Active
Platform adoption metrics

What to measure when the platform’s users are your own engineers.

Open

Open source

Opsyron Collector

Go DaemonSet that maps live topology across multi-cloud Kubernetes estates.

Preparing release
Landing-zone modules

Reusable multi-region Terraform modules, extracted from production work.

Preparing release
On-call diagnostic skills

AI-assisted triage for Claude Code, built on real post-mortems.

Preparing release

Talks

Build platforms before they become problems

What early infrastructure decisions cost, compounded.

Talk · 45 min
Why internal platforms fail

What adoption actually costs, and who pays it.

Talk · 30 min
Golden paths

Designing a platform your engineers choose to use.

Workshop · half day

Invite MTLabs to speak

§ 08Record

Marco Tomás

Founder of MTLabs. Principal Platform Engineer, fifteen years in. The roles below are employment history: the estates where the patterns MTLabs brings to startups were proven, at a scale where getting them wrong was expensive.

Marco Tomás
Reach IT · Principal Platform Engineer · 8 AKS clusters across 4 regions, ~60 Terraform stacks, zero-trust network, AI-assisted incident response2025–now
Marco Tomás, Unipessoal Lda · Founder · independent platform engineering for enterprise clients2023–now
Expert Thinking · Senior Platform Engineer · Azure landing-zone modules adopted as the standard across all teams2023–2025
Global Shares, a J.P. Morgan company · Senior DevOps · regulated financial-services platform2019–2023
Vodafone · DevOps Platform Manager · network and delivery platforms2018–2019
Farfetch · Infrastructure Engineer · test-automation platform for 400+ engineers, 10,000+ runs a day2016–2018

Education

Instituto Superior Técnico · BSc Computer Science & Engineering2007–2016

Full record on LinkedIn

§ 09Contact

Start with a call.

Fifteen minutes to describe what you have and what keeps breaking. If MTLabs is the right partner, a longer session and a written assessment follow. No deck, no discovery phase, no obligation, and an honest answer about fit.

Based inLisbon · remote-first