Developer docs · security & lifecycle

Trust is a system property—and a vehicle-lifetime commitment.

Design identity, privacy, cybersecurity, quality, safety allocation, updates, observability and support alongside the feature. Exact certifications and responsibilities are program-scoped.

Six control domains for a connected automotive program.

The strongest control is a clear boundary: who owns the identity, key, command, data, update, incident and evidence.

01

Identity & entitlement

Separate user, vehicle, device, application, tenant and service identities; authorize by purpose, environment, region and module.

02

Secrets & keys

Keep server secrets off clients; use least privilege, managed rotation, short-lived tokens where supported and customer-controlled trust where contracted.

03

Vehicle commands

Require strong authentication, authorization, vehicle-state rules, idempotency, replay resistance, timeout and complete audit.

04

Data governance

Minimize signals, capture lawful purpose and consent, separate owner and driver, define retention, deletion, export and derivatives.

05

Software & content updates

Declare manifest, compatibility, integrity, staging, retry, activation, rollback, campaign monitoring and incident pause.

06

Tenant & deployment

Define isolation, residency, encryption, network controls, backup, DR, administrative access, exit and evidence ownership.

Use precise scope. Avoid blanket badges.

Standards and regulation apply differently to map data, cloud services, embedded software, electronics and complete vehicle functions.

Automotive SPICE

Development process and evidence expected by many OEM programs; declare organizational and project capability scope.

ISO 26262

Functional-safety allocation depends on the item and use; map or cloud can be QM or safety-related.

ISO 21448 / SOTIF

Relevant to performance limitations, ODD and foreseeable misuse of intended ADAS or AI functions.

ISO/SAE 21434

Cybersecurity engineering across concept, development, production, operations and decommissioning.

UNECE R155 / R156

Support the OEM CSMS and SUMS evidence for applicable vehicle markets and software-update scope.

NDS / ADASIS

Validate the exact release and profile used for map storage, delivery or electronic horizon.

Test the road, network, vehicle and lifecycle—not only the UI.

A representative program builds reusable India and vehicle-specific conformance cases.

Search

Misspellings, phonetics, local language, house and entrance, landmarks, ambiguous names and moving-vehicle constraints.

Routing

Flyover and underpass, service lanes, divided roads, U-turns, tolls, closures, private and vehicle-profile constraints.

Positioning

Urban canyon, tunnel, overlaps, weak or lost GNSS, dead reckoning, cold start and map-match recovery.

Traffic & ETA

Peak, incidents, stale or missing feed, reroute and actual-versus-predicted analysis.

EV

Invalid signals, climate and elevation, charger mismatch, skipped stop, deviation, arrival SoC and reserve.

Connected

Provisioning, transfer, geofence, buffer, duplicates, command replay, timeout, notification and consent revocation.

ADAS / HD

ODD, coverage, freshness, localization or horizon error, missing attributes, rollback and safe degradation.

Performance

Startup, route time, FPS, memory, storage, power, thermal, service SLO and long-duration soak.

Security and quality evidence at every exit.

The lifecycle aligns product maturity, environment, validation and operations before SOP.

01

Qualify

Align vehicle, territory, proof route, outcomes and architecture; identify what is standard, configured or partner-dependent.

02

Define

Allocate features, interfaces, data coverage, deployment, HMI, compliance and commercial assumptions.

03

Integrate

Establish environments, maps, credentials, SDK or app baseline, vehicle signals, identity and telemetry.

04

Validate

Test function, performance, HMI, weak GNSS, network loss, route, EV, connected, security and vehicle behavior.

05

Launch

Provision production services, content and devices; approve monitoring, rollback, support and incident playbooks.

06

Evolve

Manage maps, applications, devices, model-year branches, field quality, security and end-of-life.

SLOs that tell the OEM what users feel.

Targets are illustrative categories; actual thresholds are defined in the program.

Cloud / APIAvailability, p50/p95/p99 latency, errors, throttles, failover and restore.
NavigationSearch success, route time, ETA error, off-route recovery, crash-free use and update adoption.
ContentCoverage, freshness, correction lead time, topology and attribute defects, delivery and rollback.
ConnectedProvisioning, telemetry completeness and latency, twin freshness, notification and command success.
EVRange and arrival-SoC error, charge-plan success, route energy and unplanned charging.
DeviceConnectivity, field failure, OTA, storage, thermal, power, warranty and service turnaround.
OEM program workshop

Bring us the vehicle. Leave with the program shape.

Choose the surfaces, modules, deployment and lifecycle that fit your next RFQ. We will turn it into a focused discovery brief.