Security & Compliance
Voice infrastructure touches every customer conversation. Miuda.ai is built so the secure path is the default path — at the network edge, in the call path, and in the console.
Encryption in Transit
TLS for SIP and HTTPS/WSS, SRTP for media — DTLS-SRTP on WebRTC legs and automatic SDES negotiation on SIP legs. No plaintext media unless a carrier cannot do encryption.
Edge Protection
Deny-by-default ACLs, per-trunk IP allowlists, a built-in scanner User-Agent blacklist, and frequency limits that absorb registration floods before they reach authentication.
Access Control
Role-based permissions for console users, scoped API tokens for automation, and tenant isolation on the wholesale side — enforced at the API, not just the UI.
Audit & Evidence
Call records with leg timelines and per-call media evidence, optional recording with per-segment artifacts, SipFlow signaling capture, and immutable access logs.
Resilient by Design
Memory-safe Rust core, clustered session registry, drain-then-exit upgrades, and circuit breakers that isolate bad routes instead of cascading failures.
Deploy Your Way
Run on-premise, in your VPC, or air-gapped. Data (recordings, CDRs, signaling) stays in storage you control; nothing is sent to Miuda.ai at runtime.
Your Data, Your Boundary
- Data residency: media, CDRs and capture live in your database and object storage (S3/Azure/GCS or on-prem). Choose the region.
- GDPR posture: analytics on this website are consent-gated; in-product data is yours to retain or delete under your retention policy.
- License validation: the only outbound call Miuda.ai sees is license verification — no call content, no CDRs.
- Retention control: storage lifecycle rules and archives keep or purge evidence on your schedule.
- Backups: config in Git, database snapshots, recordings mirrored to object storage.
Hardening Baseline
The first-48-hours checklist we recommend for every public deployment.
1 · ACL deny-by-default
Allow internal ranges and carrier egress; deny everything else.
2 · Scanner blacklist
Built-in User-Agent blacklist rejects SipVicious-class tools at the door.
3 · Frequency limits
Rate-limit registration and INVITE floods; watch the block list for intrusion signals.
4 · Per-trunk trust
Pin each carrier to its egress IPs; challenge-response where registration is used.
5 · Encryption everywhere
TLS on SIP and console, SRTP for media, topology hiding at the border.
6 · Least-privilege access
Role-based console accounts, scoped API tokens, registration closed after bootstrap.
Full details: Hardening a public PBX in our blog.
Responsible Disclosure
Found a vulnerability? Email security@miuda.ai with reproduction steps. We acknowledge reports within two business days and will credit researchers who request it.