SIP firewall that drops fraud before it reaches your switch
A SIP firewall for carriers, VoIP and CPaaS. Every INVITE is screened against spam data refreshed every minute, STIR/SHAKEN attestation, and proof on registered brand numbers. Clean calls route through. A spoof of a brand you protect never rings.
02:41:07 +18882211161 C ✕ DROP 603 43 complaints
02:41:08 +16502530000 A ✓ PASS 200 verified
02:41:08 +12099009302 B ✕ DROP 603 robocall
02:41:09 +447476937994 A ✓ PASS 200 → sbc-us-east
02:41:11 +18006343169 C ✕ DROP 603 list hit
INVITE, attestation, decision, reason
0
fraud INVITEs reach your switch. The drop happens at the edge, before setup.
60s
between spam data updates behind every decision. New campaigns are blocked in the same minute.
1
SIP domain to point at us. No switch replacement, no dialplan surgery.
In the call path, out of your way
Point a SIP domain at the firewall, register your SBC endpoints, done. Traffic flows through the screen and clean calls land on the nearest healthy endpoint.
Inbound
All SIP traffic
Every INVITE from carriers, trunks and the open internet hits the firewall first.
Screen
CallerAPI SIP firewall
Spam score from minute-fresh complaint data, STIR/SHAKEN attestation, and a proof check on registered brand numbers. Decision logged with origin IP and raw SIP.
Clean out
Your SBC or switch
Passing calls route to the nearest healthy endpoint, region-aware.
Dropped
603 at the edge
Fraud never reaches your capacity. Only the log line remains.
Firewalls guard your packets. Nothing guards your voice.
Fraud rides straight into switches, queues and agents because signaling is trusted by default. An SBC hides topology and handles media. It does not know which numbers are running a scam campaign right now. This is the missing layer.
Every drop traces back to a consumer complaint, the same record behind the spam call blocking API and the spam phone number database. When a customer asks why a call was refused, you show the record.
| SBC alone | SIP firewall in front | |
|---|---|---|
| Knows the caller is a scam campaign | No | Yes, from complaints |
| Uses STIR/SHAKEN attestation | Passes it along | Part of every decision |
| Fraud consumes channels | Yes | Dropped before setup |
| Evidence per blocked call | None | Complaint, attestation, IP, raw SIP |
| Deployment | Already there | One SIP domain, keep the SBC |
The voice firewall for carriers, VoIP and CPaaS
Anyone who terminates or originates SIP at volume pays for fraud twice: once in capacity, once in the customers it reaches.
Carriers and wholesale
Interconnect minutes spent on fraud are minutes you paid for and cannot bill. The firewall drops the campaign at the edge, keeps the attestation level on every log line for compliance reviews, and hands your SBC only traffic worth carrying.
Want the list on your own switch as well? Host the spam phone number database for a flat fee.
VoIP providers and PBX operators
Toll fraud and scam floods stop at the domain boundary. Your tenants never see them, and neither does your support queue.
CPaaS and UCaaS
Sell the firewall as a network-level protection tier. Your customers get clean inbound traffic, you get a new line on the invoice.
Live analytics for every decision
Origin IP, user agent, attestation, spam score and the drop or pass decision for every screened call, in a dashboard you can hand to your NOC. Region-aware routing sends passing calls to the nearest healthy SBC endpoint.
Three steps to the first screened call
Plans scale with the number of SBC endpoints. Nothing else changes in your network.
-
Create a SIP domain
One domain in the dashboard. Point your inbound trunks at it.
-
Register SBC endpoints
Add each SBC or switch with its region. Passing calls route to the nearest healthy one.
-
Watch the decisions
Drops and passes stream into analytics with the evidence attached. Tune from there.
SIP firewall questions
Put a firewall in front of your voice
Set up a SIP domain and see your first screened calls today, or walk us through your topology first.