IRSF
International Revenue Share Fraud sends traffic to premium or high-cost destinations to collect revenue share.
What we watchVolume and spend toward high-risk destination prefixes, especially at odd hours.
Smart Gravity Shield learns what is normal for each of your customers, scores unusual activity from 0 to 100, and alerts your team about 30 to 60 seconds after calls are recorded. Genuine call-centre traffic is judged against its own baseline, so it is less likely to be blocked by a one-size-fits-all rule.
Sample data. Illustrative interface only, not real customer traffic.
Most fraud is found at billing time or after an upstream carrier complains. By then the minutes are already terminated and the cost is yours. Smart Gravity Shield watches the call records as they arrive.
International Revenue Share Fraud sends traffic to premium or high-cost destinations to collect revenue share.
What we watchVolume and spend toward high-risk destination prefixes, especially at odd hours.
Artificial call volume is generated to inflate termination fees on specific numbers.
What we watchConcentration on a few destinations, volume spikes and unusual call duration patterns.
One-ring calls tempt people to call back an expensive number.
What we watchVery short, unanswered calls in bulk and the numbers they point to.
A compromised account suddenly places toll-fraud calls, often at 3 a.m.
What we watchBehaviour that leaves that account's own history: new destinations, new hours, new volume.
Traffic is terminated through local SIM cards to bypass proper interconnect rates.
What we watchIndicators such as call duration, ASR and answer patterns on a route that do not fit normal profiles.
Fake caller IDs and automated campaigns expose you to complaints and traceback requests.
What we watchCaller-ID patterns and robocall exposure indicators per customer.
A new customer builds trust, then runs up large usage and disappears.
What we watchSpend ramping faster than the account's history and agreed spend limits.
Smart Gravity Shield sits beside your switch, not in the call path. It reads records, compares them with each customer's normal, and tells your team.
Reads new call records from the softswitch every 5 to 10 seconds.
Compares activity with each customer's own baseline using live counters.
A risk engine scores each customer and route from 0 to 100.
Alerts the team and, if allowed, limits or blocks. Everything is logged.
Built around how carriers actually work: per-customer context, graduated response and a human in control.
Each customer is judged against their own history and traffic profile. We alert when CPS jumps from 80 to 400 or ASR collapses from 5% to 0.5%.
High-risk destinations, volume and spend spikes, Wangiri patterns, odd-hour activity and ASR/ACD drops. Thresholds are editable per customer.
One number per customer and route, so your team knows where to look first.
Alert, then rate-limit, then block. Every action is reversible with one click, and whitelists protect trusted traffic.
Telegram and email, with WhatsApp optional. Each alert names the account, pattern, risk level and suggested action.
Explains each alert in plain English or Roman Urdu and helps you query the dashboard. The decision stays with you.
Live fraud feed, riskiest customers, destinations and routes, plus a full trail of every block, unblock and rule change.
Each company's data, users, rules and whitelists are fully isolated. Roles: Admin, Analyst, Viewer, with 2FA.
A small agent or API push sends CDR to the platform. Direct database access is not required.
Short calls and low answer rates are normal for auto-dialer campaigns. A fixed rule sees "fraud" and blocks a paying customer. Smart Gravity Shield only alerts when behaviour leaves that customer's normal. See how per-customer baselines work.
Generic fixed rule
Blocked. Normal traffic looks like fraud to a one-size rule.
Smart Gravity Shield
No alert while normal. Alert when behaviour leaves the band.
Illustrative example, not real traffic.
Move the slider to see the default action at each level. Bands and actions are configurable per customer.
Default bands: Low 0 to 29, Medium 30 to 59, High 60 to 84, Critical 85 to 100.
Your team is alerted and, if automation is enabled for this customer, traffic is rate-limited. Everything can be reversed in one click.
Optional fingerprint login lets you know who started a campaign, without storing biometrics or recording a single call.
A fingerprint proves who logged in, not who placed every call. Works best when the call centre uses your portal or softphone, or when the contract requires it.
The agent unlocks their passkey with a fingerprint on their own device. The biometric never leaves it.
Only a cryptographic signature is sent to the platform. No fingerprint data is stored.
The campaign and its calls are linked to that agent's identity, with an audit trail.
The assistant turns a risk score into a plain-language explanation in English or Roman Urdu, and answers questions about the dashboard. It advises. You decide.
HIGH · Acct 1187 · CPS 80 → 400 in 4 min
Pattern: volume spike toward a high-risk prefix. Suggested action: rate-limit and review.
Subject: [Critical] Acct 2291 odd-hour IRSF pattern
Risk 91. Calls to a flagged destination began at 03:02. One-click block available in the dashboard.
Sample
A small collector agent or an API push sends call records to the platform over an encrypted connection. Direct database access is not required.
Automatic blocking depends on your switch exposing an account or route control. Detection and alerting work from call records alone.
The platform reads call records, not call content, and keeps each company's data separate.
Data is encrypted in transit and when stored.
Admin, Analyst and Viewer roles, with two-factor sign-in.
Fingerprint data stays on the user's device.
Data, users, rules and whitelists are separated by company.
Choose how long call records and logs are kept.
Every block, unblock and rule change is recorded.
Smart Gravity Shield is designed to help operators meet local telecom and data-protection obligations. Compliance depends on your configuration and jurisdiction, and should be validated with your legal advisers.
Nothing is blocked until you decide it can be.
We review your switch, traffic profiles and risk priorities.
1 to 2 weeksCDR flows in, baselines are learned, alerts go to your team. No automatic action.
Days to weeksThresholds and whitelists are adjusted per customer from real alerts.
Rate-limit and block are enabled gradually, customer by customer.
Rules are reviewed regularly. Machine-learning anomaly detection is coming after roughly 2 to 3 months of history.
Indicative, varies by network size and switch interface.
Pricing depends on traffic volume and the features you switch on. Tell us about your network and we will propose a plan.
For a single team that wants visibility first.
Custom pricing
For teams ready to act automatically.
Custom pricing
For larger or multi-company operations.
Custom pricing
Short guides for fraud and NOC teams: what each attack looks like in call records and how to reduce exposure.
Revenue share fraud explained, with warning signs in call records.
One-ring callback fraud and what it looks like in CDRs.
How inflated traffic earns termination fees, and the signs to watch.
How hijacked accounts show up, and what to check first.
Indicators of bypass traffic, and why they are indicators, not proof.
Why fixed rules block genuine traffic, and what to do instead.
No. It reads call detail records (CDR) and is not in the call path. A separate, optional SIP-proxy add-on can enable pre-call blocking.
Yes. Every deployment starts in monitor-only mode with a learning period of 1 to 2 weeks. Automation is switched on gradually, customer by customer.
No. It does not record calls or analyse call audio. It works from call records and live counters.
Every action is reversible with one click. Whitelists protect trusted traffic, and thresholds are tuned per customer to reduce repeat false positives.
Detection is near-real-time, typically about 30 to 60 seconds after calls are recorded. It does not stop the very first call before it connects, and no fraud system catches every case.
VeriSwitch is supported now. Asterisk, FreeSWITCH, VOS3000 and others are on the adapter roadmap.
Each company's data, users, rules and whitelists are fully isolated in a multi-tenant design, with role-based access inside each company.
TLS in transit and encryption at rest, role-based access with 2FA, per-company isolation, configurable retention and full audit logs. Biometric data is never stored.
Tell us about your network. We will reply to arrange a walkthrough and discuss a monitor-only pilot.