About the company
Five months old, and unwilling to pretend otherwise.
THE TWENTY FINTECH LTD was incorporated in England and Wales on 1 March 2026 under company number 17061506. That sentence contains every verifiable milestone the company has. This page explains what it is set up to do, how it intends to behave, and which of the usual reassurances it is not in a position to offer.
There is no founding story on this page. A founding story written five months after incorporation is a marketing exercise, and this portfolio has decided that a young company is better served by accurate scope than by an origin myth.
How to read this page
On names
No individual is named anywhere on this site. Directors, persons with significant control and secretaries are recorded on the public Companies House register for company number 17061506, which is the authoritative and statutorily maintained source. Reproducing a name here would add nothing and could go wrong in a way that matters to a real person.
On numbers
There are no counts on this site. No customers, no transactions processed, no revenue, no headcount, no uptime figure. Not because they are confidential, but because the company has not earned any of them yet and an unearned number is the fastest way to make everything else on a page unreliable.
On tense
Where this site describes a process it uses the conditional: how an engagement would run, what a handover would contain. That is deliberate. Present tense would imply a routine that has been performed, and none has.
The cheapest thing a new supplier can offer is an accurate account of its own limits.
Why this page is shaped the way it is
The thesis
Why a company aimed at this layer
Financial technology infrastructure is the sector direction the company was registered for, and it is reflected in the SIC codes on the register: 62012, 63110, 64999 and 66190.
The interesting problems moved down the stack
A great deal of attention in financial technology sits on the surface: the interface, the onboarding funnel, the pricing model. Underneath it, an unreasonable number of firms are still running a ledger that cannot reproduce a historic balance, a reconciliation that lives in a spreadsheet somebody maintains by hand, and a payment integration that assumed messages arrive once, in order, and exactly as documented.
The failure mode is silence
A broken interface is noticed immediately. A ledger that quietly permits an unbalanced state is noticed at year end, or by an auditor, or by a customer who has been overcharged for eight months. The cost of a defect in this layer is proportional to how long it stays invisible, which is why the design goal is not elegance but detectability.
It is work that suits a small operation
A reconciliation review or a ledger design critique is bounded, deliverable as a document, and judgeable on its own merits by a competent reader. That is the honest shape of the work a company at this stage can credibly take on, and it is a better use of a client's money than being sold a platform.
The register decides what is claimed
The four SIC codes on the Companies House record are the boundary of what this site describes. Where a possible line of work sits outside them, it is not described here as though it were already in scope.
Dated record
Everything that has actually happened
Three entries. When there is a fourth it will be added here with its date, and the entry above it will not be quietly reworded.
-
01
1 March 2026: incorporation
THE TWENTY FINTECH LTD was incorporated as a private limited company in England and Wales, company number 17061506, with its registered office at 66 Paul Street, London, England, EC2A 4NA. The four SIC codes recorded against it set the intended activity: software development, data processing and hosting, financial intermediation not elsewhere classified, and activities auxiliary to financial intermediation.
Verifiable at Companies House
-
02
2026: D-U-N-S registration
The company holds Dun and Bradstreet D-U-N-S number 234619137. A D-U-N-S number is an identifier used in supplier onboarding and application store enrolment. It is not an accreditation, a rating or an endorsement of any kind, and it is listed here only because counterparties frequently ask for it.
Identifier, not accreditation
-
03
7 August 2026: this site published
A static site published from Cloudflare Pages, stating scope, method, declared limits and the statutory disclosures required of a UK limited company. The legal documents on it take effect from this date. It sets no cookies of its own, which is explained in the cookie notice rather than asserted in a banner.
Today's entry
Not on this list
First engagement, first release, first hire, first accounts filed. None of these has happened. The first statutory accounts and confirmation statement will be due in the ordinary course and will appear on the Companies House record when filed.
Security posture
What is in place, and what is not
Buyers in financial services ask this early, and the wrong answer is a vague paragraph about taking security seriously. The table states the position for each control, including where the answer is no.
| Control | Position | Detail |
|---|---|---|
| ISO 27001 | Not held | The company is not certified to ISO 27001 and does not claim to be. No certification body has assessed it. |
| SOC 2 | Not held | No SOC 2 Type I or Type II report exists for this company. None has been commissioned. |
| Cyber Essentials | Not held | The company is not Cyber Essentials or Cyber Essentials Plus certified. Where a client requires it, it would have to be obtained first and the timing agreed in writing. |
| ICO registration | Position stated | [TO CONFIRM: whether the company is required to pay the ICO data protection fee and, if so, the registration reference] Registration status does not change the company's obligations under the UK GDPR, which apply regardless. |
| Written DPA | Available | Any engagement involving personal data would be governed by a written agreement meeting Article 28 of the UK GDPR, signed before access is granted. |
| Client production access | Avoided by default | The working preference is reduced, pseudonymised or synthetic data. Where production access is unavoidable it would be time bound, named, logged and revoked at the end of the task. |
| Transport security | In place | This site is served over HTTPS only, with HTTP Strict Transport Security and a restrictive Content Security Policy set at the edge. |
| Penetration test | Not applicable yet | There is no product or client facing system to test. When one exists, the testing position will be published here with a date. |
| Cyber insurance | Unstated | [TO CONFIRM: whether professional indemnity and cyber liability cover are in place, the insurer and the limit of indemnity] |
A "not held" row is not an admission of weakness. It is the only defensible answer for a company that has not been assessed, and it is the answer a procurement team can actually work with.
Governance
How the company is administered
Officer and person with significant control details are recorded on the public Companies House register for company number 17061506 and are maintained there by statute. This site does not reproduce them. Anyone conducting due diligence should use the register rather than a supplier's own website, because the register is the version that is legally required to be current.
The registered office is 66 Paul Street, London, England, EC2A 4NA. That is the address for service of legal documents on the company. This site does not describe it as an office you can visit, because that would be a claim about the arrangement rather than a fact from the register.
Any subcontractor used on an engagement touching client data would be named to the client in advance, bound by a written agreement passing down the same obligations, and listed as a sub-processor in the privacy notice. There is no arrangement under which work would be passed on silently.
This is a legitimate question to ask a company incorporated this year, and the answer should be contractual rather than reassuring. An engagement contract would provide for source code and documentation to be delivered to the client on an ongoing basis rather than at the end, so that a client is never holding a partly built system they cannot read. Escrow arrangements can be agreed where a client requires them.
Hand written static HTML and CSS with one small script, served from Cloudflare Pages. No analytics product, no tag manager, no advertising pixel, no chat widget, no embedded video. Web fonts are requested from Google Fonts, which means Google receives the request and the IP address that made it; that is disclosed in the cookie notice because it is the only third party the page touches.
Next step
If the limits above are workable, write
The company would rather be told early that its stage is a problem than discover it in the third meeting. An enquiry that starts with a constraint is more useful than one that starts with a compliment.