Bullet Solutions

Trust & security

Security you can verify

Universities entrust us with timetabling data that touches staff, students and estates. This page sets out our information security certification, how to verify it independently, and what documentation we can share with your procurement and data protection teams.

Last reviewed: August 6, 2026

Certification

ISO/IEC 27001:2022

Our Porto operations are covered by ISO/IEC 27001:2022 certification for information security management, independently assessed by a UKAS-accredited certification body.

Certified scope

The development, sales and support of software solutions encompassing timetabling software for universities, colleges, and private providers world-wide.

Quoted verbatim from the certificate. Certification applies to this scope only.

Certificate details

Certificate number
272145
Certification body
British Assessment Bureau Limited, trading as Amtivo
Accreditation
UKAS-accredited to ISO/IEC 17021-1:2015
Initial certification
June 11, 2026
Latest issue
June 11, 2026
Expiry date
June 10, 2029

Subject to annual surveillance assessments

Statement of Applicability
v4.0, dated April 11, 2026

Locations covered

  • Suite 6, The Gardens, Coleshill Manor Office Campus, South Drive, Coleshill, B46 1DL, United Kingdom

  • Rua Júlio Dinis 728, Sala 911, 4050-012 Porto, Portugal

Who holds the certificate

The certificate is held by Corbett Engineering Limited, trading as Celcat, incorporating Bullet Solutions. The Bullet Solutions office in Porto, Portugal is named on the certificate as a covered location. Bullet Solutions and Celcat are part of the same group, both Volaris companies within Constellation Software Inc.

You can verify this certificate independently through the UKAS certificate check service. Search using certificate number 272145 or the certificate holder name, Corbett Engineering Limited.

What the certification means

ISO/IEC 27001 is the international standard for information security management. Certification is not a self-declaration: it is awarded after an independent audit and has to be re-earned every year.

  • An audited management system

    We operate a documented information security management system covering risk assessment, security controls, and the policies that govern how information is handled. Its design and operation were examined by an external auditor before certification was granted.

  • UKAS-accredited assessment

    Our certification body is accredited by the United Kingdom Accreditation Service, the sole national accreditation body appointed by the UK government. Many tender processes require UKAS-accredited certification specifically, rather than certification from an unaccredited body.

  • Reassessed every year

    The certificate runs to June 2029 but is conditional on annual surveillance assessments. Certification can be suspended or withdrawn if the required standards are not maintained.

  • Built to improve

    The standard requires ongoing risk review, incident handling, supplier oversight, and corrective action rather than a fixed checklist. Our security posture is expected to change as threats do.

Data protection and GDPR

Bullet Solutions – Information Systems, S.A. is established in Porto, Portugal and processes personal data in accordance with the General Data Protection Regulation. Our privacy policy sets out what we collect, the legal grounds for processing, retention periods, international transfers, and how to exercise your rights. We have an appointed Data Protection Officer, whose contact details are published in that policy.

Documentation for procurement teams

The certificate above is public. The material behind it is not, because publishing it would itself be a security risk. We share the following with institutions evaluating us, normally under a mutual non-disclosure agreement.

  • Statement of Applicability summary and control coverage

  • Information security policy overview

  • Completed vendor security questionnaires and assessment forms

  • Data processing agreement and records of processing

  • Hosting, data residency and sub-processor information

  • Incident response and business continuity overview

Availability of specific documents depends on the nature of the engagement and the scope of your assessment.

Questions from your security team?

We are used to working through institutional security reviews, DPIAs and tender questionnaires. Tell us what you need and we will route it to the right people.