Home · Network

Network & infrastructure

Callivex runs a tightly engineered EU-primary network with a UK edge, with every component monitored.

Primary PoP - Frankfurt

EU-central placement for low-latency reach across Germany, Benelux, France, Switzerland, Austria, Poland, the Nordics, the UK, and the Mediterranean. Active-active SBC pair behind a single FQDN.

Edge - London

UK edge for sub-15ms reach to BT, Vodafone, Virgin Media. Failover for Frankfurt-primary customers; primary for UK-domestic customers.

Carrier interconnects

Direct SIP interconnects with EU wholesale carriers for A-Z termination. Multi-carrier LCR per destination with ASR-weighted failover.

Edge protection

SIP scanner mitigation and automated banning at the SBC, source-IP enforcement, signaling rate limits per source. DDoS protection at the network layer.

Carrier-grade components, run with discipline

The signal path uses the same proven carrier-grade components every serious operator relies on.

  • SIP edge - registration, authentication, ACL, dispatcher, least-cost routing
  • Media layer - relay, SRTP termination, codec negotiation and normalization
  • Rating engine - real-time per-second rating and hard balance enforcement
  • Provisioning and archive - account state, CDR archive, audit log
  • Observability - metrics, dashboards, SIP capture for incident forensics
  • Edge defence - automated source-IP banning on SIP authentication failures
# Signal path - outbound call caller (your SBC) ↓ SIP INVITE [ SIP edge ] ← AUTH, ACL, dispatcher, LCR ↓ INVITE (re-routed) [ B2BUA ] ← codec negotiation, transcoder ↓ media anchor [ Media relay ] ← RTP relay, SRTP ↓ SIP + RTP upstream carrier ↓ PSTN delivery # Billing path - parallel, real-time [ Rating ] ← rate, balance, cut-off
# Signaling + media - security profile Signaling: SIP / UDP, TCP, TLS 1.2+ Media: RTP / SRTP (AES-128 / AES-256) Codecs: G.711 a-law, G.711 u-law, G.722, G.729, opus DTMF: RFC 2833, SIP INFO Fax: T.38 (transcoding on request) Transports: UDP, TCP, TLS Auth options: IP whitelist, digest, mutual TLS Source-IP cap: 8 IPs per trunk default CIDR support: /29 to /32, /28 on review

Encryption-ready, IP-locked, scanner-shielded

Encryption is available on every leg from customer SBC to carrier (where the carrier supports TLS+SRTP). IP authentication is the default for high-volume trunks. SIP registration is available for PBX and office deployments.

  • TLS 1.2+ on signaling for any customer that requests it
  • SRTP on media (AES-128 / AES-256) end-to-end where carrier-supported
  • Mutual TLS (mTLS) on request for sensitive deployments
  • Source-IP whitelisting enforced at SBC, not just provisioning DB
  • SIP scanner mitigation: fail-rate based banning, signature filtering
  • Per-customer signaling rate limits

Engineering ops, not "we'll look at logs if you call"

Every leg is captured, every CDR is rated, every metric is graphed. Customer-facing dashboards show per-route ASR, NER and PDD. Internal alerts fire before customers feel impact.

  • Per-customer dashboard: ASR, attempts, billable mins, top destinations
  • Per-route quality metrics windowed at 5/15/60-minute intervals
  • Full SIP capture retained for incident forensics
  • Active synthetic call probes from each PoP, every minute
  • PagerDuty escalation on threshold breaches
# Quality probe - last 24h, all routes ASR NER PDD all routes 52% 81% 2.1s UK · Mobile 61% 87% 1.8s DE · Mobile 58% 85% 2.0s FR · Landline 54% 82% 2.2s PL · Landline 47% 78% 2.4s # Internal alert thresholds ASR drop >15% in 15min → page on-call PDD >5s on top route → page on-call Carrier 5xx >2% / 5min → auto-fallback

Curious about a specific deployment detail?

Engineering happily talks to your engineering team. Send a question; we'll answer in plain English.

Talk to engineering →