Trust & governance
Our clients are publicly funded and accountable — to governors, auditors, regulators and the public. This page exists so that anyone conducting due diligence on us can verify who we are and how we operate, without having to ask. It states only what is true today, and is updated as facts change.
Company identity
- Legal name
- TWOPOINTZERO.IO LTD (trading as TwoPointZero.io)
- Company number
- 13059563 — registered in England & Wales, incorporated 3 December 2020; filings are up to date and can be verified at Companies House
- Registered office
- 24 1 Wesley Avenue, London E16 1SW
- Director
- Wai Hang (Peter) Lau
- VAT
- Not VAT-registered; no VAT is chargeable on our invoices. Should registration become required, quoted prices in an engagement are the total amounts payable unless expressly agreed otherwise.
Data protection
- ICO registration
- Registration as a fee payer with the Information Commissioner's Office is in progress; this page will carry the registration number once issued.
- Role
- When handling client personal data (for example student records), we act as a processor under a written data-sharing or data-processing agreement, with the client as controller. We do not use client personal data for any purpose beyond the engagement.
- Where your data lives
- The systems we build are deployed into the client's own Microsoft Azure tenancy, under the client's policies and identity platform. Client data stays inside the client's environment — it does not leave it, and it is not copied into ours.
- Practices
-
- Data minimisation: we work on the smallest extract that does the job, for the shortest time.
- Client personal data is never committed to code repositories.
- Client personal data never appears in our demonstrations or marketing — demonstration environments use invented data and published datasets only.
- Retention and erasure follow the client's own policies, encoded in the systems we deliver.
- On exit, any client data in our custody is returned or destroyed, with written confirmation.
Security
- Certifications
- None held yet. Cyber Essentials is the first we intend to obtain; this page lists certifications only once they are actually in place.
- Security by architecture
- Security in what we deliver is a product property, not a policy document: role-based access through the client's own identity platform (least privilege by default), maker-checker sign-off so no one approves their own changes, a tamper-evident audit trail of every write, and erasure workflows with cryptographic erasure. All of it is demonstrable, and clients are encouraged to test it.
Continuity — including ours
We advise clients on key-person risk, so we hold ourselves to the same standard. Every engagement includes:
- a perpetual, irrevocable licence to the source code, configuration, data structures and documentation we deliver — vesting as milestones are accepted, surviving the end of any agreement, with no annual fee;
- the exit ramp: every data store exports to plain, documented formats at any time, without our involvement — a standing acceptance criterion, not a promise;
- documentation kept current as we work — much of it generated from the system's own configuration, so it cannot silently drift from behaviour;
- acceptance-tested knowledge transfer: named client staff perform the key operating tasks unaided, and a nominated technical successor can rebuild a working environment from the repository and documentation alone, before the project is called complete;
- repository access from the start of an engagement, with escrow arrangements available if preferred.
The client is never dependent on our continued existence to operate its system. We would rather be retained for usefulness than for lock-in.
Procurement & due diligence
We are happy to complete supplier due-diligence questionnaires, provide references, and enter into data-sharing and data-processing agreements on client or institutional templates. Milestone acceptance criteria are agreed in writing before work starts, and payment falls due on acceptance. Requests to contact.
This page was last reviewed on 30 July 2026. If anything here appears out of date, please tell us.