MEET US

Meet Pilotfish at Persontrafik 2026

No matter what you run onboard, it needs a future-proof architecture. We focus on building that — scalable, secure, and open for your Public Transport operations to be able to evolve. Meet us at our stand C03:48 at Persontrafik and discuss the future of your onboard architecture. See you at Stockholmsmässan.

Persontrafik is where the Nordic public transport sector meets, and this year the conversation is about doing more with less: bringing down cost per kilometre, meeting new security requirements, and procuring in a way that keeps your options open. Those are the questions we work with every day, together with authorities and operators across Europe. Come and talk to us about yours.

Open, scalable & secure – no matter what you run onboard

Whether your onboard systems are new or a decade old, from one supplier or six, ITxPT-compliant or not, they all need the same thing underneath.

 

A shared network, one controlled route to the back office, and one source of vehicle data. That architecture layer decides whether a fleet can scale, change supplier and be secured at all.

 

Book a meeting with us during Persontrafik 2026 in order to discuss this further.

Putting something new on a vehicle usually means its own box, its own connection and its own integration. Do that five times and the fifth one costs more than the first, because it has to coexist with four things that were never designed to coexist with anything.

With a shared onboard network and one managed route to the back office, adding a system becomes a connection rather than a project. The same holds when you go from a pilot on three vehicles to a full fleet: the work is rollout, not redesign. It is a good thing to talk through against a real fleet, so come and find us at the stand.

Onboard IT specified in a tender this year will still be in the vehicle a decade from now. If the systems depend on each other, changing one of them means renegotiating all of them, and the supplier knows it.

An open architecture separates the functions from the foundation. Ticketing can be replaced without touching passenger counting. A camera supplier can be changed without a new gateway. That is what turns vendor independence from a line in the requirements into something you can actually exercise.

It is built on ITxPT, which exists precisely so this works across suppliers rather than only within one.

Fleets are rarely uniform any more. Diesel beside electric, buses beside trams, several vehicle generations in service at once, and sometimes more than one operator under the same authority.

When every vehicle type sits on the same architecture, they can be run and monitored as one operation instead of three parallel ones with three sets of tools and three people who each know how one of them works.

Position, CAN and FMS data, system status: it already exists in every vehicle. It is usually locked inside whichever system happened to collect it, in whatever format that supplier chose.

Collected once at the architecture level and shared in a standard format, the same data serves operations, maintenance and reporting at the same time. And it keeps working when the fleet changes, because the format does not depend on who won the last procurement.

Onboard networks usually carry ticketing, CCTV, passenger information and payment devices from several vendors on one flat network. Everything can reach everything, so a single compromised unit puts the whole vehicle at risk.

The answer is not to lock things down until nothing works. It is to separate the network into zones and permit only the traffic that has a reason to cross between them, so a compromised device reaches nothing else. Handled at the architecture level, it works without replacing the onboard hardware you already run.

It is also what produces the evidence: an inventory of what is connected, an audit trail, and a documented way of handling vulnerabilities when they turn up. Which is, in the end, what obligations under the Cyber Resilience Act and NIS2 come down to.

A scalable, secure architecture for onboard systems and vehicle data is what makes a fleet future-proof: no vendor lock-in, multimodal from the start, and open to whatever you already run, ITxPT or not. That architecture is what Pilotfish builds.

Why this comes up more than it used to

On most vehicles the onboard network is flat. Ticketing, CCTV, passenger information and payment devices share it, and everything can reach everything else. One compromised unit is enough to put the whole vehicle at risk.

A year ago this was mostly an engineering conversation. It is now a legal one as well. Reporting obligations under the EU Cyber Resilience Act started on 11 September, the full requirements apply from December 2027, and Sweden’s cybersecurity act has applied to operators and authorities since 15 January. The first reaches your suppliers, the second reaches you, and both arrive in the same place: the vehicle.

Our position is that the risk should be contained rather than the functionality: separate zones on the onboard network, with only the traffic that has a reason to cross between them. It is done at the architecture level and without replacing the equipment already in the vehicles.

What the architecture actually is

The Pilotfish® Vehicle Communication Platform and the gateway that runs it sit underneath everything else on the vehicle. Every onboard system connects to the onboard IP network and reaches the back office through one managed connection instead of its own.

ITxPT services come as standard: module inventory, time, GNSS position, FMS to IP. A compliant system works out of the box. Systems that predate the standard, or ignore it, connect anyway. That is the point: the architecture doesn’t ask you to replace what you have in order to start.

From there, adding a system is a connection rather than a project, swapping one does not disturb the others, and there is finally a single place where access, updates and monitoring are handled for the whole vehicle.

That is what open, scalable and secure means in practice. Not three qualities bolted on afterwards, but three consequences of putting the vehicle together properly in the first place.

Meet us in stand C03:48 or at the open stage

We are at stand C03:48 for all three days. Come and talk about what sits underneath the onboard systems on your vehicles, whether that is the network, the route out to the back office, or the vehicle data you already produce and cannot reach.

On Wednesday 21 October at 12:50 we are on the open stage for twenty minutes on cyber security in public transport: where a flat onboard network leaves you exposed, what changed when the Cyber Resilience Act and Sweden’s cybersecurity act started to apply, and what can be done about it without replacing the equipment already in the vehicles.

Want more than a passing hello? Leave your details in the forms and we will come back with a time that suits you.

Book a meeting at Persontrafik 2026

Leave your details and we will get back to you to book a meeting during Persontrafik 2026.

We use the details you provide to answer your enquiry and to follow up on our business relationship. Please do not include sensitive personal data in your message. Read more in our privacy policy.

What we do


We provide hardware, software and services built around our Vehicle Communication Platform and Vehicle Gateway, connecting vehicles, onboard systems and vehicle data into one unified ecosystem. Our solutions enable interoperable, secure and scalable Public Transport operations that are built to evolve.

Explore what we do
Orange icon of a puzzle

Decoupled architecture

We believe systems should be free to evolve. Change one system, and the rest carry on untouched.

Orange icon of a globe

Standardised communication

We believe standards should open doors, not close them. We build on ITxPT, and connect systems that predate it or ignore it entirely.

Orange icon of a router

Real-time data flows

We believe data should move without friction. When it does, you see the fleet as it is, not as it was this morning.

Pilotfish is certified in accordance with ISO 9001 for quality management Pilotfish is certified in accordance with ISO 14001 for environmental management Pilotfish is certified in accordance with ISO 27001 for information security management
The bridge between Hisingen and Gothenburg in Gothenburg.

Certifications & compliance


We operate according to internationally recognised standards for information security, quality and environmental management. These certifications ensure that everything we design, build and operate meets high requirements for reliability, compliance and long-term performance.

Learn more

Latest news from us

Learn more about what's going on at Pilotfish in our latest news.

Close up of the VG212 - Vehicle Gateway for Public Transport Fleets

Explore products

Discover our hardware, software and platform solutions designed for connected Public Transport.

Go to offering
Two electric Västtrafik buses charging at a bus station in Heden, Gothenburg.

Explore success stories

See how our solutions are deployed in real-world Public Transport systems across multiple regions and fleets.

View cases

Want to get in touch?

Get in touch to discuss your system, challenges or upcoming projects.