IR FleetIR Fleet
Engineering

Built to scale to a major-company-sized portfolio

This technology runs the real scoring engine described below end-to-end against a synthetic fleet. The architecture is the same one that scales from a 100-vehicle pilot to a multi-million-policy portfolio — only the data sources at the edges change.

System architecture

Four layers, each independently scalable and independently testable.

Ingestion
Telematics/OBD connectors
GPS & mobile SDK stream
Claims/core-system sync
Weather & external feeds
Streaming & Storage
Event bus (Kafka/Kinesis)
Time-series store (signals)
Feature store (online + offline)
Data lake (raw + curated)
Intelligence
SafeGuard risk models
RapidRate pricing engine
ClaimSense fraud/NLP
PredictEdge portfolio model
Serving
Risk & pricing API
Insurer/broker dashboards
Fleet owner app
Webhooks & core-system push

Design principles

Event-driven ingestion

Every telemetry source (OBD/CAN, GPS, driver app, claims, weather) lands on an append-only event bus (Kafka/Kinesis-class). Producers and consumers scale independently, so onboarding a new OEM/telematics vendor or a new insurer's claims feed never touches the scoring path.

Stateless scoring services

SafeGuard, RapidRate, ClaimSense and PredictEdge (lib/engine in this technology) are pure functions over a feature vector. In production they run as horizontally-scaled stateless services behind an API gateway — scale is linear with fleet size, not with model complexity.

Feature store, not point calculations

Raw signals are aggregated once into a shared online/offline feature store. The dashboard, the pricing engine and the claims-fraud model all read the same driver/vehicle/route features, so scores stay consistent across every surface.

Multi-tenant by design

Every record carries a tenant (insurer/broker/fleet) and policy-scope key from ingestion through to the API. Row-level isolation plus per-tenant encryption keys let IR Fleet serve a major company's captive, a broker panel and a direct fleet client from one platform without data crossing boundaries.

Explainable by construction

Every score already carries its contributing factors (see the behavioural breakdown in the live dashboard). That is not a UI add-on — it's how the engine is written: weighted, named sub-scores, never an opaque black-box output. This is what actuarial and compliance sign-off requires.

Human-in-the-loop actions

The engine recommends (coach driver, adjust premium, trigger maintenance, investigate fraud); it does not auto-execute against policy or bank systems. Every action routes through the insurer's existing underwriting/claims workflow and audit trail.

Evidence at the point of handover

Odometer reading and condition photos are captured before a vehicle goes to a driver, timestamped and stored against that vehicle's record. This is the same evidentiary logic as the ClaimSense liability-dispute reduction — an objective initial-state record beats a disputed memory when a damage claim is filed.

Predict, then prevent

Each vehicle's forward claim rate becomes claim probabilities over 30, 90 and 365 days, a per-category loss forecast and wear-driven deadlines for brakes and battery. Every recommended action is valued by re-running the same risk model with that action applied — the drop in expected loss is its benefit — so a fleet manager sees which vehicles to act on first and what each action is worth. Category mix, severities and action costs are documented assumptions that the pilot calibrates against the insurer's own loss data.

Owned engines, plugged in once

ClaimSense and RapidRate connect through a single operator-only console with an API URL and key — encrypted at rest, never shown to customers. Responses are validated against a published contract; if an engine is slow, down or returns something unexpected, the built-in model answers for that vehicle so the platform keeps working and the failure is visible only to the operator.

Pluggable ingestion, not just one-by-one

A fleet manager can upload their whole fleet as CSV, Excel or JSON instead of adding vehicles individually — column or key names are matched to our fields by word-overlap similarity, not exact string matching, with a manual review step before import since every provider's export looks different. For continuous updates, the same field-matcher runs unattended behind a plain JSON endpoint (POST /api/admin/units/ingest) that any polling script or telematics relay can push to; records are upserted by plate, so a vehicle reported every few minutes updates in place instead of piling up duplicates. Either path runs the identical validation and scoring as a one-by-one entry.

Compliance & risk posture

Data residency
EU-region data storage and processing; per-tenant residency pinning for regulated entities.
GDPR
Purpose-limited processing, driver consent flows for behavioural/app data, right-to-erasure pipelines down to the feature store.
Actuarial governance
Score components and weights are versioned and auditable — required for Solvency II model-risk sign-off and regulator review.
Security
Encryption in transit and at rest, per-tenant key isolation, RBAC down to the driver-record level, full access audit log.
Model risk management
Shadow-mode deployment for any model change: new weights run in parallel against production scores before cutover.

Rollout plan

Weeks 1–6
Phase 1 — Pilot

Claims-history + one live telemetry source (GPS or OBD) on a bounded pilot fleet. Validate score calibration against a major company's actual loss data.

Weeks 7–14
Phase 2 — Scale

Add remaining data layers, stand up the feature store and event bus for full fleet volume, integrate RapidRate into underwriting workflow.

Weeks 15+
Phase 3 — Full Engine

ClaimSense fraud detection live on claims intake, PredictEdge portfolio reporting for reserving, broker-facing risk-improvement reporting.