The standard
Eight commitments, each with evidence you can audit
Speed claims are easy. We publish what every release must meet, and hand you the proof. The standard is HubSpire’s own, built on the rules and specifications transit already works to.
The problem
Why transit software has been slow
Traditional Agile paced itself around expensive handoffs between roles. The real cost was feedback delay: a wrong requirement surfaced only at the end of a two-week sprint.
-
Stakeholder time is scarce
Operations and IT leaders might give an hour a day. Every meeting has to count.
-
System access takes days
Provisioning accounts and environments often takes two to three days.
-
Integrations are complex
CAD/AVL, GTFS and GTFS-rt, fare, and APC systems all have to keep working.
The evidence
Why transit projects slip, and what the standard does about it
Each commitment answers a problem that independent research has measured. Here is the problem, the cause, and the control we put in its place.
| What the research shows | Why it happens | What the standard does | Proof you get |
|---|---|---|---|
| 45% Large IT projects run 45% over budget and deliver 56% less value than planned. Every extra year adds about 15% to cost overruns. McKinsey & Oxford, 5,400+ IT projects. | Long delivery cycles, weak stage gates, and stakeholders brought in late. McKinsey ties about half of overruns to misaligned strategy and stakeholders. | One-week sprints keep batches small. Seven gates on every change. The agency approves the spec before anything is built. | Weekly demo and gate records |
| 7.2% Each 25% increase in AI adoption was associated with an estimated 7.2% drop in delivery stability. DORA State of DevOps 2024. | AI speeds up writing code but not checking it. DORA’s conclusion: small batch sizes and robust testing remain crucial. | AI works inside small weekly batches, against tests written from approved requirements, with automated gates and a human sign-off. | Traceability and test results |
| 95.9% of the top one million home pages have detectable WCAG failures, averaging 56 errors per page. WebAIM Million 2026. | Accessibility is audited at the end, when fixes are expensive. It is also a legal deadline: WCAG 2.1 AA under ADA Title II by April 26, 2027 for large public entities. | WCAG 2.1 AA checks run in every sprint, automated plus manual keyboard and screen-reader testing. | Accessibility report |
| 900 office computers were encrypted in the 2016 SFMTA ransomware attack; station faregates and ticket machines were shut down for a weekend as a precaution. SFMTA; Mineta Transportation Institute, 78 agencies. | Transit is a target, and Mineta’s 2025 research found many agencies still lack documented cybersecurity policies and procedures. | Every change is scanned before merge; zero known critical vulnerabilities at release; rescans as new issues are published. | Scan report per release |
| 5% or 1,000 people: the FTA Title VI safe-harbor threshold at which vital documents must be translated for a language group. FTA Title VI guidance. | Multilingual support is often added after launch, forcing rework of content and templates. | Multilingual-ready content structure from day one, so translations slot in without rebuilding pages. | Translation workflow |
Effectiveness so far
What HubSpire has measured on its own delivery. We’ll track the same numbers on your pilot, so you can judge for yourself.
- 2 mo Case study. From handover to launch on a program 12+ months in, at one of the largest global transit agencies.
- 40–60% Company-reported. Faster project delivery across AI-assisted engagements.
- 85%+ Company-reported. Automated test coverage.
- 90%+ Company-reported. Of issues caught by automated checks before human review.
The pipeline
Seven gated stages from ticket to release
AI agents draft the spec, plan, code, and tests. People approve the spec before anything is built, every stage has a gate, and nothing ships until a named engineer signs off.
- Requirement. A short ticket becomes functional, non-functional, and test requirements, using project knowledge we load in.
- Planning. Which modules change, front end vs back end, data, and test scenarios. Your product owner approves the spec and plan before build.
- Implementation. HubAI generates readable code from strict templates: React UI, GraphQL APIs, auth, Docker, Cypress tests.
- Testing. The agent runs the app against the approved tests, including accessibility, and fixes the code. It can’t change the tests without human approval.
- Code review. Automated review against our coding and architecture standards.
- Security gate. Static analysis, dependency, and dynamic scans. Any finding goes back for a fix.
- Human sign-off. An engineer checks the work and the evidence pack against a written checklist, adds documentation, and merges.
What HubAI adds
HubAI is HubSpire’s own code-generation platform. It builds predictable project structures, CRUD APIs, secure authentication layers, and schema-connected React forms. It is published under the MIT license, and its output is standard, editable code, so there is no black box and no lock-in. HubSpire reports 4–5x faster MVP cycles with it (our own measurement). Read more about HubAI.
Sprints, reshaped
One week when requirements are ready. Two when they’re not.
We keep Agile’s strengths: a backlog, teamwork, and regular feedback. The track depends on one question.
Our security promise
0 known critical vulnerabilities at release.
That is the honest promise. No vendor can guarantee zero unknown vulnerabilities, because new ones are published against existing software every month. So we scan every change, and rescan after release.
- Scan every change. Long-established, industry-standard tools check the code and its dependencies after code review.
- Fix before merge. Any finding sends the code back to implementation, and the fix is scanned again.
- A person confirms. An engineer reads the scan report and confirms zero critical findings before merging. High-severity findings are triaged with fix timelines agreed in your contract.
- Rescan after release. When new vulnerabilities are published, rescans catch them and they go into the backlog.
“Critical” follows the CVSS scale (9.0–10.0). Evidence for security teams: a scan report per release, shareable under your audit process.
What changes for you
Fewer handoffs, more verification
AI lets one skilled HubSpire engineer cover work that used to pass through many hands. Our people shift from producing work to checking it.
| You are | What changes | What you get |
|---|---|---|
| CEO or owner | Budget goes to outcomes, not headcount per role | Weekly visible progress and less schedule risk |
| Project or product owner | Review working software every week, not every two | Wrong turns caught in hours |
| Solution architect | HubAI enforces agreed patterns: monorepo, microservices, federated GraphQL, Docker | Consistent code you can extend or hand over |
| QA lead | Test cases come from requirements and run automatically | QA time goes to edge cases, not repetitive scripts |
| ADA or civil rights lead | Accessibility and language access are tested every sprint, not audited at the end | Evidence for your ADA and Title VI records |
| Security team | Every change passes scanners before a person reviews it | A report per release and a named sign-off |
Where people still lead
The slowest part is now the conversation, not the code
-
Before meetings
AI helps our analysts prepare expert-level questions, so your one hour a day goes further.
-
After meetings
AI reviews transcripts for missed requirements and edge cases. Nothing said gets lost.
-
Access on day one
We request system access at kickoff, so provisioning never holds up the first sprint.
What stays human: understanding your riders and operations, final judgment on requirements, and sign-off on every release.
Questions leaders ask us
Speed only matters if it’s safe
What agency executives, architects, security and ADA teams, and primes ask most, answered plainly.
-
Is this an official industry standard?
It’s HubSpire’s own published standard, built on established ones: WCAG 2.1 AA, CVSS, and GTFS. What makes it a standard is that every commitment comes with evidence you can audit.
-
Do AI agents touch our systems or rider data?
No. Agents work in isolated development environments, without access to production systems or live rider data.
-
Is our information sent to public AI?
We use approved enterprise AI tools. Your documents and code are not used to train models and stay under your confidentiality terms.
-
Who is accountable when AI writes the code?
A named engineer signs off every release. AI never merges code on its own.
-
Doesn’t fast review mean rubber-stamping?
Sign-off follows a written checklist and the evidence pack. A release can’t merge until every gate is green.
-
Can the AI change tests just to make them pass?
No. Acceptance tests come from approved requirements, and changing them needs human approval.
-
Can you really promise zero vulnerabilities?
No one honestly can. We promise zero known critical vulnerabilities at release, prove it with a scan report, and rescan as new issues are published.
-
Aren’t daily drops risky?
Drops go to a review environment so you can steer early. Only work that passed every gate reaches production.
-
Are we locked into HubAI?
No. HubAI is MIT-licensed and produces standard React, GraphQL, and Docker code in your repository. Any capable team can maintain it.
-
Does weekly delivery fit our procurement?
Yes. Weekly cycles roll up into your contract milestones and acceptance process. You simply see progress sooner.
- Transit clients include MTA New York City Transit, SEPTA and MARTA
- Delivering since 2015 · 275+ projects
- Certified SBE · MBE · DBE
Hold us to the standard. Start with one week.
A 60-minute discovery session to pick your track, list access needs, and agree what you’ll see working at the end of week one.