For automotive and industrialsSoftware is becoming the product. Measure it like one.
Vehicles and machines are now defined by their software, built across large in-house teams and deep supplier networks. Arrio reads what all of that development produces, on one independent measure, so the software estate is as governed as the physical one.
The problem
A software estate no one can see across
The value of a modern vehicle or machine increasingly sits in its software, and that software is built across in-house platforms and a long tail of suppliers. Each reports differently, and no one has a single, comparable view of what all of it produces.
The risk is rising with the volume. Duplicated code blocks are up 81% and cross-file reuse is down 35% (GitClear, 2026), while 45% of AI-generated code has shipped with a security vulnerability (Veracode, 2025), a serious matter where software touches safety.
What is needed is an independent measure that reads the work itself across in-house and supplier code alike, and benchmarks what each actually delivers against what it costs.
- Increase in duplicated code blocks across software estates. (GitClear, 2026)
- +81%
- Increase in duplicated code blocks across software estates. · GitClear, 2026
- Of AI-generated code introduced a security vulnerability. (Veracode, 2025)
- 45%
- Of AI-generated code introduced a security vulnerability. · Veracode, 2025
- Forecast worldwide IT spending in 2026, up 14.2% on 2025. (Gartner, 2026)
- $6.37tn
- Forecast worldwide IT spending in 2026, up 14.2% on 2025. · Gartner, 2026
What you get
Supplier output benchmarking
Every supplier and external team on the same independent scale, against what they charge, so sourcing decisions rest on evidence.
In-house and outsourced on one measure
Internal platforms and supplier code read on the same terms, so the whole estate is comparable.
Quality, debt and security
The real state of the code across the estate, read directly, where reliability and safety carry real cost.
The AI shift across the estate
How much is now built by AI and whether it is delivering, tracked over time across teams and suppliers.
How a manufacturer uses it
A vehicle or machine programme now runs on software built across in-house teams, tier-one suppliers and contracted specialists. Very few organisations can see across the whole of it.
01Map the estate you cannot currently see
Every in-house team, supplier and contracted partner contributing software to the programme, on one map, sized by what it costs and what it delivers.
02Benchmark suppliers against each other, and against your own teams
Supplier reporting is written by the supplier. An independent read of what each one actually delivered turns the next contract review into a conversation about evidence.
03Read quality and debt where safety depends on it
Technical debt, complexity and security exposure read from the code, in an estate where a serious defect is a recall rather than a patch.
04Answer the AI question for the whole programme
How much of the software is now AI-built, and whether it holds to the standard the product requires. Volume is easy to see; whether it is safe to ship is not.
05Govern software the way you already govern the physical product
The engineering organisation gets the quality discipline the factory has had for decades, from measurement rather than assertion.
Questions
The questions worth asking
Can it read across many different suppliers and teams?
Yes. That is the point of an independent measure. In-house platforms and supplier codebases are read on the same terms, so a large, distributed estate becomes comparable rather than a set of unrelated reports.
How does it handle safety-relevant or regulated code?
Access is read-only, sandboxed and audit-trailed, with the option to run inside your own cloud so nothing leaves your environment, and source code is not stored. It surfaces quality and security findings from the code as it stands, which matters most where software touches safety.
Do suppliers have to cooperate or install anything?
It runs from read-only access to the repositories in scope, deployed to suit your security posture. It reads the work itself rather than depending on each supplier's own reporting.
Sources
- GitClear, 2026 Maintainability Gap study, 211M lines of code: the share of new code rewritten within two weeks rose from 3.3% to 7.1%; duplicated code blocks up 81%; cross-file reuse down 35%; refactoring moves down 70%.
- Veracode, 2025 45% of AI-generated code introduced a security vulnerability.
- Gartner, 2026 Worldwide IT spending forecast, $6.15 trillion for 2026.
Govern the software estate as closely as the physical one.

