Home / Platform / ShieldSync
On-board cybersecurity

The OBU is an endpoint on a public network. ShieldSync treats it like one.

Malware and intrusion detection, integrity monitoring and port control running inside the on-board unit — monitored from a cloud console, and still protecting the vehicle when it drops off the network.

Feasibility

Where it can run.

Where it can run. ShieldSync runs on the device, so it needs one of two things: the RouteSync OBU software stack, or an OBU vendor who permits a third-party agent and grants the device access it requires. Many imported OBUs are closed platforms and will not. We confirm feasibility against the specific make and model before offering it, and where it cannot run on the device the vehicle is covered by the platform-side controls on the Security page instead. It applies to vehicles already in service and not only to new production, which is the point — most fleets that need this are already running. Stating all of that here is cheaper than discovering it after purchase.
Why it exists

Every module in the vehicle layer depends on the connection. The connection is also the exposure.

A connected OBU runs a Linux or Android operating system, holds video and passenger data, accepts over-the-air updates, exposes USB and diagnostic ports in an unattended vehicle, and on electric vehicles sits alongside the CAN bus. That is the description of an endpoint, and endpoints are managed.

It is a general-purpose computer

An operating system, a filesystem, a network stack and an update mechanism — the same components that are protected everywhere else they appear, sitting in a bus at a depot overnight.

It holds data worth reaching

Video, passenger counts, ticketing events and position history. Some of it is evidence, and evidence is only useful if it can be shown not to have been altered.

It is physically accessible

USB and diagnostic ports in an unattended vehicle are the shortest path in, and they do not require a network at all.

The consequence, stated plainly. A fleet of unprotected OBUs is a fleet of unmonitored endpoints. One compromised unit can reach the operator's network, corrupt evidence video before it is needed, or interfere with on-vehicle systems. None of that requires an unusual attacker; it requires an unmanaged device.
Capability

What runs on the unit, and what you see of it.

On-device protection

Malware and intrusion detection, application whitelisting, and quarantine of unauthorised processes — running locally inside the OBU rather than inferred from traffic elsewhere.

Integrity monitoring

Continuous verification of firmware, binaries and configuration against signed baselines. An unauthorised change raises an alert instead of persisting quietly.

Port and interface control

USB, debug and diagnostic port policy enforcement — the most common physical attack path on an unattended vehicle.

Network anomaly detection

Unexpected outbound connections, command-and-control traffic patterns, and anomalous data volumes.

Offline operation

Full protection without connectivity. Events are buffered on the device and synchronised on reconnection, so a vehicle out of coverage is not a vehicle out of cover.

Cloud console

Fleet-wide threat dashboard, per-vehicle security posture, alerting and escalation, and an audit-ready incident history.

Compliance value

The evidence an IT review asks for.

IT security reviews

A named control on the vehicle endpoint, with a console that can show its state, rather than an assurance that the device is behind a firewall somewhere.

MeitY-aligned control expectations

Endpoint protection, integrity verification and logged incident history map onto the control families a public-sector security review works through.

Operator and city-authority audits

An incident history that can be produced on request, per vehicle and per fleet, with the dates and the disposition attached.

Tell us the make and model.

Feasibility is a per-device question and we would rather answer it before you buy than after. Send the device list and we will come back with which units can host it.

Thanks — we'll be in touch shortly.