Transit software engineered in house and adapted to every operation, from central platforms to embedded devices.
TAP develops the ITS software suite in-house: central platforms for fare collection, scheduling, fleet, passenger information, assets and operations, together with the applications that run on validators, vending machines, driver consoles, point-of-sale terminals and passengers’ phones.
Because we own the code, we adapt it to each authority’s fare policy, network, languages and interfaces. Our engineering follows a secure development lifecycle with version control, automated testing, controlled releases and remote updates to every device in the field.
Customization Levels
Configure First, Extend Second, Build Only Where Needed
TAP meets each authority’s requirements at the lightest level that will do the job, keeping the core platform on a single maintained code base and every deployment upgradeable.
Configuration
Business rules changed through parameters by authorized users, with no software change and no release.
- Fare products and tariffs
- Discounts and concessions
- Network topology and stops
- Messages, languages and branding
Extension
New capability added around the core through interfaces, reports and modules, without altering core logic.
- Integration through APIs
- Custom reports and dashboards
- Additional workflows
- Interfaces to authority systems
Bespoke Development
New functions engineered, tested and released through the full development lifecycle and design review.
- New modules and applications
- Device-specific software
- Algorithms and analytics
- New fare media and channels
Engineering Pipeline
Every Change Built, Tested and Released the Same Way
Code moves through a continuous integration and delivery pipeline with security and quality checks at every stage. Nothing reaches the production system without passing through the test and training environment first.
-
Phase 1
Build
- 01Commit & peer code review
- 02Versioned build artifact
-
Phase 2
Verify
- 03Static analysis (SAST)
- 04Dependency scan (SCA)
- 05Unit & integration tests
- 06Regression suite per device
-
Phase 3
Accept
- 07Test & training environment
- 08User acceptance & authority sign-off
-
Phase 4
Release
- 09Scheduled release to production
What We Build
From Central Platforms to Embedded Devices
TAP’s engineering teams develop across every layer of an ITS deployment, from the data center to the device in a passenger’s hand.
Back-Office Systems
Web-based platforms for fare management and clearing, scheduling, fleet operations, passenger information, assets, faults and complaints, accessed through a standard browser by authorized users.
- Role-based access
- Multilingual interfaces
- Audit trails
- Configurable reports
Device Software
Applications for validators, vending machines and fare gates, with offline operation and secure transaction storage.
View → MobilePassenger Apps
Ticketing, account and journey apps for Android and iOS, with secure communication to the back office.
View → In-VehicleDriver & On-Board Apps
Driver console, location and messaging software built for the moving vehicle.
View → IntegrationAPIs & Data
Open interfaces, data exchange and analytics connecting every subsystem and third party.
View →Versions & Updates
Updating Thousands of Devices
Each part of a transit network brings its own conditions, constraints and standards. TAP plans and delivers installation in all five.
| Equipment | Update channel | Activation |
|---|---|---|
| Station Equipment | Station local area network | Scheduled for non-operating hours |
| On-Board Equipment | Depot Wi-Fi, with 4G/5G for urgent updates | On connection, or at a scheduled date and time |
| Central Systems | Controlled deployment from the test environment | Approved release windows |
Delta Updates
Only changed data is compressed and transferred.
Independent Data Types
Firmware, software and configuration versioned and sent separately.
Dormant Versions
Updates staged on the device in advance of activation.
Scheduled Activation
Applied automatically at a configured date and time.
Update Logs
Every attempt reported with the resulting version of each module.
Security Patching
Third-party components kept current with vendor releases.
Secure Development
Security Engineered Into Every Release
Transit software handles revenue, personal data and payment credentials. TAP applies secure development practice throughout the lifecycle, aligned with OWASP guidance and recognized information security standards.
- SEC-01
Threat Modeling
Risks identified and mitigated at the design stage.
- SEC-02
Static Analysis
Source code scanned for vulnerabilities on every build.
- SEC-03
Composition Analysis
Third-party libraries checked for known vulnerabilities and licenses.
- SEC-04
Penetration Testing
Applications and interfaces tested before major releases.
- SEC-05
Encryption & Keys
Transaction data signed and encrypted, with managed cryptographic keys.
- SEC-06
System Hardening
No unnecessary software, services or user accounts.
- SEC-07
Segregation of Duties
Separate create and release rights for high-impact functions.
- SEC-08
Audit Logging
Sensitive system interactions logged and retained for audit.
Ownership & Continuity
Software Authorities Can Rely On for the Long Term
Source Code Escrow
Source code of custom-built components placed in escrow, protecting the authority's continuity of service.
Clear Licensing
A license agreement defining grant, term, warranty, updates and maintenance in transparent terms.
Third-Party Register
All third-party software listed with version numbers and license information.
Complete Documentation
Software design descriptions, interface specifications and user manuals under version control.
Knowledge Transfer
Training for administrators and technical staff on configuration, reporting and support.
Long-Term Support
Maintenance releases, security patches and enhancements throughout the operating period.
Related
Works Together With
Software
Management
Comments are closed