CallerAPI Falcon · open source

Robocall mitigation software that runs next to your switch

Robocall mitigation software for carriers, CPaaS and UCaaS that verifies STIR/SHAKEN, names the provider that signed each call, and blocks fraud by number, IP or signer. One binary. Your data stays on your host. The switch never waits.

falcon · traffic · live tail screening
decision from signer shaken reason
ALLOW +16505550142 Harbor Voice LLC verified · A clean
REJECT +13125550188 Kestrel Gateway failed · A signature invalid
REJECT +18135550031 none no shaken scanner user agent
FLAG +19725550907 Redwood Transit verified · C attestation C
REJECT +14045550260 Kestrel Gateway failed · A deny rule on signer
ALLOW +12065550414 Harbor Voice LLC verified · A clean

Example data. Signer names are fictitious.

0

calls held. Falcon answers from a local process. A cold certificate fetch returns within the budget and warms the cache for the next call.

1

binary and one SQLite file. The same build runs on a laptop and on a fleet of switches.

9

checks on every PASSporT, from signature to revocation to the calling number, visible per call.

See who signed the call, not just the number it shows

Scammers rotate numbers every week. They cannot rotate the certificate they sign with. Falcon reads the Service Provider Code from every signing certificate and puts it on every event, so the provider behind a campaign stands out in one table.

In a 2025 enforcement case the FCC traced one impersonation campaign to a single provider that had signed 97% of it. A deny rule on that signer stops the next batch of numbers before anyone complains.

falcon · signers · last 24 hours
SPC signer calls reject verified failed
7421 Harbor Voice LLC 4,182 2% 4,101 12
3390 Redwood Transit 2,907 6% 2,880 9
8080 Kestrel Gateway 1,366 94% 0 1,366
6613 Blue Ridge Wireless 988 3% 975 4

Beside the switch, never in the call

Your switch asks, Falcon answers with an action and the reasons. Signaling and media never move.

1 · INVITE arrives

Asterisk, FreeSWITCH, Kamailio, any SBC

Ten lines of dialplan post the INVITE headers to Falcon on localhost. Fail open if it does not answer.

2 · Falcon decides

Verify, identify, score

  • STIR/SHAKEN verified, signer named
  • Source IP mapped to its provider
  • Your allow and deny rules applied
  • Header shape, velocity, scanner signatures scored

3 · allow or flag

The call continues

With X-Falcon headers: score, verstat, signer, provider.

3 · reject

603 from your own switch

Nothing was proxied. The event and its evidence are in your dashboard.

event #4471 · PASSporT failed · A
  • Identity header parsed as a PASSporT
  • Algorithm is ES256
  • Signature verifies with the x5u certificate
  • Certificate chains to a trusted STI-CA
  • Certificate is within its validity period
  • Certificate is not on the STI-PA CRL
  • iat is within 60 seconds
  • orig tn matches the calling number
  • dest tn includes the called number

signer

SPC 8080 · Kestrel Gateway

issuer

Example STI-CA Root

Every check, every call, on the record

Attestation A means nothing when the signature fails or the token was minted for another number. Falcon keeps the full result beside the raw SIP, so a traceback is one search, not a night in the CDRs.

Before With Falcon
Traceback request Hours in CDRs One search, evidence attached
Spoofed A attestation Trusted Signature checked, rejected
Dirty upstream Found after the complaint Visible by signer and IP
New scam numbers Blocked one by one Denied by signer, all at once
Subscriber numbers Sent to a vendor Never leave your host

Built for the people who get the traceback email

Gateway and intermediate providers must answer tracebacks in 24 hours and know their upstream. Falcon makes both a query.

Carriers and wholesale

Every screened call carries the signer, the source provider, the attestation, and the verification result. When the traceback lands, search the signer and export the evidence. When an upstream turns dirty, one deny rule covers every number it signs.

Prometheus metrics, CSV export, and a live event stream for your NOC.

CPaaS and UCaaS

Clean inbound protects answer rates and agents. Sell the screen as a protection tier.

VoIP and PBX operators

Scanners, toll fraud probes, and INVITE floods are scored on header shape and velocity, no external data needed.

Security teams

Certificate URLs from strangers are fetched only over https to public addresses, with hard caps. Strict content security policy. Raw SIP has its own short retention. Telemetry is on by default and never carries the called number; one flag turns it off. The System view lists every destination data can leave to.

First screened call in an afternoon

The engine, verification, lists, IP intel, dashboard, and API are free and open. Paid connections add the spam database feed, the hosted telecom IP intel table, and the live voice firewall lookup.

  1. Run the binary

    Docker or a single executable. Set a token. The STI-PA trust list loads on its own.

  2. Add the adapter

    Asterisk, FreeSWITCH, or Kamailio snippets are in the repo. Any SBC that can make an HTTP call works.

  3. Open the dashboard

    Watch the live tail, tune thresholds, deny the first bad signer.

Robocall mitigation software questions

See who is signing your traffic today

Run Falcon next to one switch this afternoon. The signers table fills itself.