VoIP fraud detection for carriers

Stop VoIP fraud in minutes, not at month-end billing.

Smart Gravity Shield learns what is normal for each of your customers, scores unusual activity from 0 to 100, and alerts your team about 30 to 60 seconds after calls are recorded. Genuine call-centre traffic is judged against its own baseline, so it is less likely to be blocked by a one-size-fits-all rule.

  • Starts in monitor-only mode
  • No call recording
  • Works with your existing softswitch

Sample data. Illustrative interface only, not real customer traffic.

Built for VoIP carriers Wholesale / transit providers Providers serving call centres VoIP resellers
The problem

Fraud losses arrive late. The bill does not.

Most fraud is found at billing time or after an upstream carrier complains. By then the minutes are already terminated and the cost is yours. Smart Gravity Shield watches the call records as they arrive.

IRSF

International Revenue Share Fraud sends traffic to premium or high-cost destinations to collect revenue share.

What we watchVolume and spend toward high-risk destination prefixes, especially at odd hours.

IRSF detection guide

Traffic pumping

Artificial call volume is generated to inflate termination fees on specific numbers.

What we watchConcentration on a few destinations, volume spikes and unusual call duration patterns.

Traffic pumping guide

Wangiri

One-ring calls tempt people to call back an expensive number.

What we watchVery short, unanswered calls in bulk and the numbers they point to.

Wangiri fraud guide

PBX / SIP hijack

A compromised account suddenly places toll-fraud calls, often at 3 a.m.

What we watchBehaviour that leaves that account's own history: new destinations, new hours, new volume.

SIP toll fraud guide

SIM-box / grey routes

Traffic is terminated through local SIM cards to bypass proper interconnect rates.

What we watchIndicators such as call duration, ASR and answer patterns on a route that do not fit normal profiles.

SIM box fraud guide

CLI spoofing & robocalls

Fake caller IDs and automated campaigns expose you to complaints and traceback requests.

What we watchCaller-ID patterns and robocall exposure indicators per customer.

Subscription fraud & bust-out

A new customer builds trust, then runs up large usage and disappears.

What we watchSpend ramping faster than the account's history and agreed spend limits.

How it works

Four steps from call record to action.

Smart Gravity Shield sits beside your switch, not in the call path. It reads records, compares them with each customer's normal, and tells your team.

  1. Collect

    Reads new call records from the softswitch every 5 to 10 seconds.

  2. Analyse

    Compares activity with each customer's own baseline using live counters.

  3. Decide

    A risk engine scores each customer and route from 0 to 100.

  4. Act

    Alerts the team and, if allowed, limits or blocks. Everything is logged.

SoftswitchCDR from switchCollectorAgent or API pushLive countersCPS, ASR, ACDRules + baselinePer-customer normalRisk scoreScore 0 to 100ResponseAlert, limit, blockDashboard · Audit log · Telegram / email alertsEvery block, unblock and rule change is logged SoftswitchCDR from switchCollectorAgent or API pushLive countersCPS, ASR, ACDRules + baselinePer-customer normalRisk scoreScore 0 to 100ResponseAlert, limit, blockDashboard · Audit logTelegram / email alerts
Features

Everything a NOC and fraud team needs, nothing it doesn't.

Built around how carriers actually work: per-customer context, graduated response and a human in control.

Per-customer baselines

Each customer is judged against their own history and traffic profile. We alert when CPS jumps from 80 to 400 or ASR collapses from 5% to 0.5%.

Real-time rules engine

High-risk destinations, volume and spend spikes, Wangiri patterns, odd-hour activity and ASR/ACD drops. Thresholds are editable per customer.

Risk score 0 to 100

One number per customer and route, so your team knows where to look first.

Graduated response

Alert, then rate-limit, then block. Every action is reversible with one click, and whitelists protect trusted traffic.

Instant alerts

Telegram and email, with WhatsApp optional. Each alert names the account, pattern, risk level and suggested action.

AI assistant

Explains each alert in plain English or Roman Urdu and helps you query the dashboard. The decision stays with you.

Dashboard & audit log

Live fraud feed, riskiest customers, destinations and routes, plus a full trail of every block, unblock and rule change.

Multi-company isolation

Each company's data, users, rules and whitelists are fully isolated. Roles: Admin, Analyst, Viewer, with 2FA.

Secure data feed

A small agent or API push sends CDR to the platform. Direct database access is not required.

Call-centre ready

Built for call centres and auto-dialers.

Short calls and low answer rates are normal for auto-dialer campaigns. A fixed rule sees "fraud" and blocks a paying customer. Smart Gravity Shield only alerts when behaviour leaves that customer's normal. See how per-customer baselines work.

  • Learning period. A 1 to 2 week monitor-only period builds each baseline before any automation.
  • Whitelists. Trusted campaigns and destinations are protected from automatic action.
  • One-click unblock. If a genuine customer is limited, you reverse it instantly and tune the threshold.

Generic fixed rule

fixed rule: ASR < 20% genuine auto-dialer, ASR about 5%

Blocked. Normal traffic looks like fraud to a one-size rule.

Smart Gravity Shield

this customer's normal band ASR 5% (normal) → 0.5% (alert)

No alert while normal. Alert when behaviour leaves the band.

Illustrative example, not real traffic.

Risk score and response

A score, then a proportionate response.

Move the slider to see the default action at each level. Bands and actions are configurable per customer.

72High

Default bands: Low 0 to 29, Medium 30 to 59, High 60 to 84, Critical 85 to 100.

Default action

Alert plus rate limit

Your team is alerted and, if automation is enabled for this customer, traffic is rate-limited. Everything can be reversed in one click.

Agent Identity Lock

Tie campaigns and calls to a verified person.

Optional fingerprint login lets you know who started a campaign, without storing biometrics or recording a single call.

  • WebAuthn / Passkeys, a standard built into modern devices.
  • The fingerprint stays on the device and is never stored by us.
  • Campaigns and calls are linked to a verified agent, with re-verification when needed.
  • No call recording and no call-content analysis.

A fingerprint proves who logged in, not who placed every call. Works best when the call centre uses your portal or softphone, or when the contract requires it.

  1. Fingerprint check

    The agent unlocks their passkey with a fingerprint on their own device. The biometric never leaves it.

  2. Signed challenge

    Only a cryptographic signature is sent to the platform. No fingerprint data is stored.

  3. Verified agent recorded

    The campaign and its calls are linked to that agent's identity, with an audit trail.

AI assistant and alerts

Alerts that explain themselves.

The assistant turns a risk score into a plain-language explanation in English or Roman Urdu, and answers questions about the dashboard. It advises. You decide.

Telegram alert · Sample

HIGH · Acct 1187 · CPS 80 → 400 in 4 min

Pattern: volume spike toward a high-risk prefix. Suggested action: rate-limit and review.

Email alert · Sample

Subject: [Critical] Acct 2291 odd-hour IRSF pattern

Risk 91. Calls to a flagged destination began at 03:02. One-click block available in the dashboard.

Sample

Switch support and integrations

Works with the switch you already run.

A small collector agent or an API push sends call records to the platform over an encrypted connection. Direct database access is not required.

VeriSwitchSupported now
AsteriskAdapter on the roadmap
FreeSWITCHAdapter on the roadmap
VOS3000Adapter on the roadmap
OthersAdapters on the roadmap

Automatic blocking depends on your switch exposing an account or route control. Detection and alerting work from call records alone.

Security and privacy

Your traffic data stays yours.

The platform reads call records, not call content, and keeps each company's data separate.

TLS and encryption at rest

Data is encrypted in transit and when stored.

Role-based access with 2FA

Admin, Analyst and Viewer roles, with two-factor sign-in.

Biometrics never stored

Fingerprint data stays on the user's device.

Per-company data isolation

Data, users, rules and whitelists are separated by company.

Configurable data retention

Choose how long call records and logs are kept.

Full audit logs

Every block, unblock and rule change is recorded.

Smart Gravity Shield is designed to help operators meet local telecom and data-protection obligations. Compliance depends on your configuration and jurisdiction, and should be validated with your legal advisers.

Getting started

Start in monitor-only mode. Switch on automation when you trust it.

Nothing is blocked until you decide it can be.

  1. Discovery

    We review your switch, traffic profiles and risk priorities.

    1 to 2 weeks
  2. Monitor-only pilot

    CDR flows in, baselines are learned, alerts go to your team. No automatic action.

    Days to weeks
  3. Tuning

    Thresholds and whitelists are adjusted per customer from real alerts.

  4. Automatic actions

    Rate-limit and block are enabled gradually, customer by customer.

  5. Ongoing optimisation

    Rules are reviewed regularly. Machine-learning anomaly detection is coming after roughly 2 to 3 months of history.

Indicative, varies by network size and switch interface.

Pricing

Plans that fit your network.

Pricing depends on traffic volume and the features you switch on. Tell us about your network and we will propose a plan.

Starter

For a single team that wants visibility first.

Custom pricing

  • Monitor-only dashboard
  • Per-customer baselines
  • Real-time rules engine and risk score
  • Telegram and email alerts
Contact us for pricing
Most popular

Growth

For teams ready to act automatically.

Custom pricing

  • Everything in Starter
  • Graduated response: alert, rate-limit, block
  • AI assistant in English and Roman Urdu
  • Agent Identity Lock
  • Roles, 2FA and full audit log
Contact us for pricing

Enterprise

For larger or multi-company operations.

Custom pricing

  • Everything in Growth
  • Multi-company management
  • Custom retention and onboarding
  • Optional pre-call SIP-proxy add-on
  • Priority support
Contact us for pricing
Guides

How telecom fraud works, in plain language.

Short guides for fraud and NOC teams: what each attack looks like in call records and how to reduce exposure.

Wangiri

One-ring callback fraud and what it looks like in CDRs.

Wangiri fraud

Browse all VoIP fraud guides

FAQ

Straight answers.

No. It reads call detail records (CDR) and is not in the call path. A separate, optional SIP-proxy add-on can enable pre-call blocking.

Yes. Every deployment starts in monitor-only mode with a learning period of 1 to 2 weeks. Automation is switched on gradually, customer by customer.

No. It does not record calls or analyse call audio. It works from call records and live counters.

Every action is reversible with one click. Whitelists protect trusted traffic, and thresholds are tuned per customer to reduce repeat false positives.

Detection is near-real-time, typically about 30 to 60 seconds after calls are recorded. It does not stop the very first call before it connects, and no fraud system catches every case.

VeriSwitch is supported now. Asterisk, FreeSWITCH, VOS3000 and others are on the adapter roadmap.

Each company's data, users, rules and whitelists are fully isolated in a multi-tenant design, with role-based access inside each company.

TLS in transit and encryption at rest, role-based access with 2FA, per-company isolation, configurable retention and full audit logs. Biometric data is never stored.

Request a demo

See Smart Gravity Shield on your own traffic.

Tell us about your network. We will reply to arrange a walkthrough and discuss a monitor-only pilot.

  • Start in monitor-only mode, zero risk to live traffic.
  • No call recording and no call-content analysis.
  • Pilot programme available. Ask about terms.
Please enter your full name.
Please enter a valid work email.
Please enter your company name.
Please tick the box so we can reply to you.

We ask only for what we need to reply. Details are used for this request and are not shared for marketing. How we handle your data.