SIP firewall that drops fraud before it reaches your switch

A SIP firewall for carriers, VoIP and CPaaS. Every INVITE is screened against spam data refreshed every minute, STIR/SHAKEN attestation, and proof on registered brand numbers. Clean calls route through. A spoof of a brand you protect never rings.

sip-firewall · live decisions screening
02:41:07 +18882211161  C  ✕ DROP 603  43 complaints
02:41:08 +16502530000  A  ✓ PASS 200  verified
02:41:08 +12099009302  B  ✕ DROP 603  robocall
02:41:09 +447476937994 A  ✓ PASS 200  → sbc-us-east
02:41:11 +18006343169  C  ✕ DROP 603  list hit
INVITE, attestation, decision, reason

0

fraud INVITEs reach your switch. The drop happens at the edge, before setup.

60s

between spam data updates behind every decision. New campaigns are blocked in the same minute.

1

SIP domain to point at us. No switch replacement, no dialplan surgery.

In the call path, out of your way

Point a SIP domain at the firewall, register your SBC endpoints, done. Traffic flows through the screen and clean calls land on the nearest healthy endpoint.

Inbound

All SIP traffic

Every INVITE from carriers, trunks and the open internet hits the firewall first.

Screen

CallerAPI SIP firewall

Spam score from minute-fresh complaint data, STIR/SHAKEN attestation, and a proof check on registered brand numbers. Decision logged with origin IP and raw SIP.

Clean out

Your SBC or switch

Passing calls route to the nearest healthy endpoint, region-aware.

Dropped

603 at the edge

Fraud never reaches your capacity. Only the log line remains.

Firewalls guard your packets. Nothing guards your voice.

Fraud rides straight into switches, queues and agents because signaling is trusted by default. An SBC hides topology and handles media. It does not know which numbers are running a scam campaign right now. This is the missing layer.

Every drop traces back to a consumer complaint, the same record behind the spam call blocking API and the spam phone number database. When a customer asks why a call was refused, you show the record.

SBC alone SIP firewall in front
Knows the caller is a scam campaign No Yes, from complaints
Uses STIR/SHAKEN attestation Passes it along Part of every decision
Fraud consumes channels Yes Dropped before setup
Evidence per blocked call None Complaint, attestation, IP, raw SIP
Deployment Already there One SIP domain, keep the SBC

The voice firewall for carriers, VoIP and CPaaS

Anyone who terminates or originates SIP at volume pays for fraud twice: once in capacity, once in the customers it reaches.

Carriers and wholesale

Interconnect minutes spent on fraud are minutes you paid for and cannot bill. The firewall drops the campaign at the edge, keeps the attestation level on every log line for compliance reviews, and hands your SBC only traffic worth carrying.

Want the list on your own switch as well? Host the spam phone number database for a flat fee.

VoIP providers and PBX operators

Toll fraud and scam floods stop at the domain boundary. Your tenants never see them, and neither does your support queue.

CPaaS and UCaaS

Sell the firewall as a network-level protection tier. Your customers get clean inbound traffic, you get a new line on the invoice.

Live analytics for every decision

Origin IP, user agent, attestation, spam score and the drop or pass decision for every screened call, in a dashboard you can hand to your NOC. Region-aware routing sends passing calls to the nearest healthy SBC endpoint.

Three steps to the first screened call

Plans scale with the number of SBC endpoints. Nothing else changes in your network.

  1. Create a SIP domain

    One domain in the dashboard. Point your inbound trunks at it.

  2. Register SBC endpoints

    Add each SBC or switch with its region. Passing calls route to the nearest healthy one.

  3. Watch the decisions

    Drops and passes stream into analytics with the evidence attached. Tune from there.

SIP firewall questions

Put a firewall in front of your voice

Set up a SIP domain and see your first screened calls today, or walk us through your topology first.