A new standard for delivering transit software

Transportation

A new standard for delivering transit software

October 01, 2026

A new standard for delivering transit software

The standard

Eight commitments, each with evidence you can audit

Speed claims are easy. We publish what every release must meet, and hand you the proof. The standard is HubSpire’s own, built on the rules and specifications transit already works to.

  • Working software every week

    One-week sprints when requirements are ready, with drops to review in between.

    Evidence: weekly demo in a review environment
  • Every requirement traced to a test

    Acceptance tests are written from approved requirements before any code exists.

    Evidence: traceability report
  • Accessible by design

    Built and tested to WCAG 2.1 AA, the level the DOJ’s ADA Title II rule sets for public entities. Large entities must comply by April 26, 2027.

    Evidence: accessibility report, automated and manual
  • Ready for language access

    Multilingual-ready content from day one, supporting the language assistance plans FTA Title VI asks of grant recipients.

    Evidence: translation workflow in the CMS
  • Zero known critical vulnerabilities at release

    “Critical” means the top severity rating (CVSS 9.0+) that our scanners report at release time.

    Evidence: scan report per release
  • Transit data and integrations tested

    GTFS and GTFS-rt feeds validated; CAD/AVL, fare, and APC connections tested through agreed APIs.

    Evidence: integration test results
  • A named person signs every release

    An engineer approves each release against a written checklist and the evidence pack.

    Evidence: signed release record
  • Code the agency owns

    Standard React, GraphQL, and Docker code in your repository, documented for handover. No lock-in.

    Evidence: your repository and handover docs
  • Built on
  • WCAG 2.1 AA
  • ADA Title II
  • FTA Title VI
  • CVSS severity ratings
  • GTFS / GTFS-rt

The problem

Why transit software has been slow

Traditional Agile paced itself around expensive handoffs between roles. The real cost was feedback delay: a wrong requirement surfaced only at the end of a two-week sprint.

Illustrative comparison for one small task, a login page. Traditional delivery takes 5 to 6 hours across an estimate meeting, build, QA, and code review with 3 or more people. HubSpire takes 1 to 2 hours: built, tested, and scanned by AI, then verified by 1 engineer. Actual time varies by task. Fewer handoffs are what make one-week cycles affordable.
  • Stakeholder time is scarce

    Operations and IT leaders might give an hour a day. Every meeting has to count.

  • System access takes days

    Provisioning accounts and environments often takes two to three days.

  • Integrations are complex

    CAD/AVL, GTFS and GTFS-rt, fare, and APC systems all have to keep working.

The evidence

Why transit projects slip, and what the standard does about it

Each commitment answers a problem that independent research has measured. Here is the problem, the cause, and the control we put in its place.

Research findings, why they happen, what the standard does, and the proof you get.
What the research shows Why it happens What the standard does Proof you get
45% Large IT projects run 45% over budget and deliver 56% less value than planned. Every extra year adds about 15% to cost overruns. McKinsey & Oxford, 5,400+ IT projects. Long delivery cycles, weak stage gates, and stakeholders brought in late. McKinsey ties about half of overruns to misaligned strategy and stakeholders. One-week sprints keep batches small. Seven gates on every change. The agency approves the spec before anything is built. Weekly demo and gate records
7.2% Each 25% increase in AI adoption was associated with an estimated 7.2% drop in delivery stability. DORA State of DevOps 2024. AI speeds up writing code but not checking it. DORA’s conclusion: small batch sizes and robust testing remain crucial. AI works inside small weekly batches, against tests written from approved requirements, with automated gates and a human sign-off. Traceability and test results
95.9% of the top one million home pages have detectable WCAG failures, averaging 56 errors per page. WebAIM Million 2026. Accessibility is audited at the end, when fixes are expensive. It is also a legal deadline: WCAG 2.1 AA under ADA Title II by April 26, 2027 for large public entities. WCAG 2.1 AA checks run in every sprint, automated plus manual keyboard and screen-reader testing. Accessibility report
900 office computers were encrypted in the 2016 SFMTA ransomware attack; station faregates and ticket machines were shut down for a weekend as a precaution. SFMTA; Mineta Transportation Institute, 78 agencies. Transit is a target, and Mineta’s 2025 research found many agencies still lack documented cybersecurity policies and procedures. Every change is scanned before merge; zero known critical vulnerabilities at release; rescans as new issues are published. Scan report per release
5% or 1,000 people: the FTA Title VI safe-harbor threshold at which vital documents must be translated for a language group. FTA Title VI guidance. Multilingual support is often added after launch, forcing rework of content and templates. Multilingual-ready content structure from day one, so translations slot in without rebuilding pages. Translation workflow
Bar chart of the six accessibility failures behind 96 percent of detected errors, WebAIM Million 2026. Low-contrast text 83.9 percent. Missing image alt text 53.1 percent. Unlabeled form inputs 51.0 percent. Empty links 46.3 percent. Empty buttons 30.6 percent. Missing page language 13.5 percent.
Share of the top one million home pages with each failure, 2026. Our automated checks target all six on every build. Source: WebAIM Million 2026.

Effectiveness so far

What HubSpire has measured on its own delivery. We’ll track the same numbers on your pilot, so you can judge for yourself.

  • 2 mo Case study. From handover to launch on a program 12+ months in, at one of the largest global transit agencies.
  • 40–60% Company-reported. Faster project delivery across AI-assisted engagements.
  • 85%+ Company-reported. Automated test coverage.
  • 90%+ Company-reported. Of issues caught by automated checks before human review.

The pipeline

Seven gated stages from ticket to release

AI agents draft the spec, plan, code, and tests. People approve the spec before anything is built, every stage has a gate, and nothing ships until a named engineer signs off.

Seven stages from ticket to release: 1 Requirement, 2 Planning, 3 Implementation, 4 Testing, 5 Code review, 6 Security gate, 7 Sign-off. People approve the spec at stage 2 and sign off the release at stage 7. Failed tests loop back for an automatic fix. Security findings loop back for a fix and rescan.
The two loops are where defects and vulnerabilities get fixed automatically. People check every stage and hold the two decisions that matter most: what gets built, and what gets released.
  1. Requirement. A short ticket becomes functional, non-functional, and test requirements, using project knowledge we load in.
  2. Planning. Which modules change, front end vs back end, data, and test scenarios. Your product owner approves the spec and plan before build.
  3. Implementation. HubAI generates readable code from strict templates: React UI, GraphQL APIs, auth, Docker, Cypress tests.
  4. Testing. The agent runs the app against the approved tests, including accessibility, and fixes the code. It can’t change the tests without human approval.
  5. Code review. Automated review against our coding and architecture standards.
  6. Security gate. Static analysis, dependency, and dynamic scans. Any finding goes back for a fix.
  7. Human sign-off. An engineer checks the work and the evidence pack against a written checklist, adds documentation, and merges.

What HubAI adds

HubAI is HubSpire’s own code-generation platform. It builds predictable project structures, CRUD APIs, secure authentication layers, and schema-connected React forms. It is published under the MIT license, and its output is standard, editable code, so there is no black box and no lock-in. HubSpire reports 4–5x faster MVP cycles with it (our own measurement). Read more about HubAI.

Sprints, reshaped

One week when requirements are ready. Two when they’re not.

We keep Agile’s strengths: a backlog, teamwork, and regular feedback. The track depends on one question.

Flowchart. If requirements are ready, Track A is a one-week sprint: build, test, secure, and ship a feature from ticket to release. If not, Track B week 1 covers workshops, access, and an AI gap check, then Track B week 2 builds, tests, secures, and ships. Both tracks return feedback in days before the next sprint.
Between sprints we share daily or weekly drops in a review environment, so you can steer early. Only fully gated work reaches production.

Our security promise

0 known critical vulnerabilities at release.

That is the honest promise. No vendor can guarantee zero unknown vulnerabilities, because new ones are published against existing software every month. So we scan every change, and rescan after release.

  1. Scan every change. Long-established, industry-standard tools check the code and its dependencies after code review.
  2. Fix before merge. Any finding sends the code back to implementation, and the fix is scanned again.
  3. A person confirms. An engineer reads the scan report and confirms zero critical findings before merging. High-severity findings are triaged with fix timelines agreed in your contract.
  4. Rescan after release. When new vulnerabilities are published, rescans catch them and they go into the backlog.

“Critical” follows the CVSS scale (9.0–10.0). Evidence for security teams: a scan report per release, shareable under your audit process.

What changes for you

Fewer handoffs, more verification

AI lets one skilled HubSpire engineer cover work that used to pass through many hands. Our people shift from producing work to checking it.

What changes for each role, and what you get.
You are What changes What you get
CEO or owner Budget goes to outcomes, not headcount per role Weekly visible progress and less schedule risk
Project or product owner Review working software every week, not every two Wrong turns caught in hours
Solution architect HubAI enforces agreed patterns: monorepo, microservices, federated GraphQL, Docker Consistent code you can extend or hand over
QA lead Test cases come from requirements and run automatically QA time goes to edge cases, not repetitive scripts
ADA or civil rights lead Accessibility and language access are tested every sprint, not audited at the end Evidence for your ADA and Title VI records
Security team Every change passes scanners before a person reviews it A report per release and a named sign-off

Where people still lead

The slowest part is now the conversation, not the code

  • Before meetings

    AI helps our analysts prepare expert-level questions, so your one hour a day goes further.

  • After meetings

    AI reviews transcripts for missed requirements and edge cases. Nothing said gets lost.

  • Access on day one

    We request system access at kickoff, so provisioning never holds up the first sprint.

What stays human: understanding your riders and operations, final judgment on requirements, and sign-off on every release.

Questions leaders ask us

Speed only matters if it’s safe

What agency executives, architects, security and ADA teams, and primes ask most, answered plainly.

  • Is this an official industry standard?

    It’s HubSpire’s own published standard, built on established ones: WCAG 2.1 AA, CVSS, and GTFS. What makes it a standard is that every commitment comes with evidence you can audit.

  • Do AI agents touch our systems or rider data?

    No. Agents work in isolated development environments, without access to production systems or live rider data.

  • Is our information sent to public AI?

    We use approved enterprise AI tools. Your documents and code are not used to train models and stay under your confidentiality terms.

  • Who is accountable when AI writes the code?

    A named engineer signs off every release. AI never merges code on its own.

  • Doesn’t fast review mean rubber-stamping?

    Sign-off follows a written checklist and the evidence pack. A release can’t merge until every gate is green.

  • Can the AI change tests just to make them pass?

    No. Acceptance tests come from approved requirements, and changing them needs human approval.

  • Can you really promise zero vulnerabilities?

    No one honestly can. We promise zero known critical vulnerabilities at release, prove it with a scan report, and rescan as new issues are published.

  • Aren’t daily drops risky?

    Drops go to a review environment so you can steer early. Only work that passed every gate reaches production.

  • Are we locked into HubAI?

    No. HubAI is MIT-licensed and produces standard React, GraphQL, and Docker code in your repository. Any capable team can maintain it.

  • Does weekly delivery fit our procurement?

    Yes. Weekly cycles roll up into your contract milestones and acceptance process. You simply see progress sooner.

  • Transit clients include MTA New York City Transit, SEPTA and MARTA
  • Delivering since 2015 · 275+ projects
  • Certified SBE · MBE · DBE

Hold us to the standard. Start with one week.

A 60-minute discovery session to pick your track, list access needs, and agree what you’ll see working at the end of week one.

thomas@hubspire.com · Schedule a conversation

Have a new project you’d like help with?

Let’s get started