Security & Compliance

Voice infrastructure touches every customer conversation. Miuda.ai is built so the secure path is the default path — at the network edge, in the call path, and in the console.

Encryption in Transit

TLS for SIP and HTTPS/WSS, SRTP for media — DTLS-SRTP on WebRTC legs and automatic SDES negotiation on SIP legs. No plaintext media unless a carrier cannot do encryption.

Edge Protection

Deny-by-default ACLs, per-trunk IP allowlists, a built-in scanner User-Agent blacklist, and frequency limits that absorb registration floods before they reach authentication.

Access Control

Role-based permissions for console users, scoped API tokens for automation, and tenant isolation on the wholesale side — enforced at the API, not just the UI.

Audit & Evidence

Call records with leg timelines and per-call media evidence, optional recording with per-segment artifacts, SipFlow signaling capture, and immutable access logs.

Resilient by Design

Memory-safe Rust core, clustered session registry, drain-then-exit upgrades, and circuit breakers that isolate bad routes instead of cascading failures.

Deploy Your Way

Run on-premise, in your VPC, or air-gapped. Data (recordings, CDRs, signaling) stays in storage you control; nothing is sent to Miuda.ai at runtime.

Your Data, Your Boundary

  • Data residency: media, CDRs and capture live in your database and object storage (S3/Azure/GCS or on-prem). Choose the region.
  • GDPR posture: analytics on this website are consent-gated; in-product data is yours to retain or delete under your retention policy.
  • License validation: the only outbound call Miuda.ai sees is license verification — no call content, no CDRs.
  • Retention control: storage lifecycle rules and archives keep or purge evidence on your schedule.
  • Backups: config in Git, database snapshots, recordings mirrored to object storage.
Platform settings including security controls

Hardening Baseline

The first-48-hours checklist we recommend for every public deployment.

1 · ACL deny-by-default

Allow internal ranges and carrier egress; deny everything else.

2 · Scanner blacklist

Built-in User-Agent blacklist rejects SipVicious-class tools at the door.

3 · Frequency limits

Rate-limit registration and INVITE floods; watch the block list for intrusion signals.

4 · Per-trunk trust

Pin each carrier to its egress IPs; challenge-response where registration is used.

5 · Encryption everywhere

TLS on SIP and console, SRTP for media, topology hiding at the border.

6 · Least-privilege access

Role-based console accounts, scoped API tokens, registration closed after bootstrap.

Full details: Hardening a public PBX in our blog.

Responsible Disclosure

Found a vulnerability? Email security@miuda.ai with reproduction steps. We acknowledge reports within two business days and will credit researchers who request it.

Security review for your deployment?

We'll walk your team through the hardening baseline, deployment options and data boundary.

Talk to Security

We use cookies for anonymous analytics to improve the site. Nothing is loaded until you accept. Privacy Policy