Transparency

Implementation status

What runs today, what uses simulated data, and what waits on partners or regulators.

Authentication, roles & tenant isolation

Row-level security per tenant; demo users receive demo-tenant roles only.

Operational

Operator & vehicle onboarding with approvals

Self-entered data is labelled self-reported, never government verified.

Operational

Fleet assignment to routes

Only approved vehicles may be assigned; every change is audited.

Operational

Idempotent fare ingestion & exception queue

Engine is live; incoming events come from a simulated provider.

Operational

Double-entry subledger & daily close

Journals must balance; ledger rows are immutable.

Operational

Settlement instructions & four-eyes approval

Approved batches wait for a payout provider — no money moves.

Operational

GPS tracking

Positions generated by a labelled simulator until a tracker provider is authorised.

Simulated data

PayFine compliance view

Mock adapter. Real citations require PayFine API access and legal authority.

Simulated data

VECTRA Intelligence assistant

Answers from demo-tenant data only; never takes binding actions.

Operational

Passenger route browsing

Demonstration routes; arrival estimates only shown when data exists.

Operational

Fare provider (TransPay / O-CITY)

No agreement or API access.

Blocked by third party

Payment gateways (BlueGate, PowerTranz, BiMPay partners)

Requires merchant/partner agreements and credentials.

Blocked by third party

Electronic Vehicle Registration lookups

Requires government authorisation.

Needs regulatory approval

Legally authorised fine deductions

Not built to execute. Requires legal authority, consent and human approval.

Needs regulatory approval

Partner portals, government exports, commercial billing

Next build phase.

Planned

Integration readiness checklist

Every provider must clear each step before moving from NOT CONNECTED.

  1. 1Signed data-sharing or service agreement with the provider
  2. 2Sandbox credentials stored as server-side secrets
  3. 3Scopes reviewed against least-privilege and legal basis
  4. 4Field mappings and webhook signatures verified
  5. 5Reconciliation test against provider settlement reports
  6. 6Security review and audit-log sign-off
  7. 7Production credentials and go-live approval