Communication Security Architecture

Cainiao Voice employs a multi-layer security architecture with full encryption from signaling to media streams, ensuring end-to-end communication security. Our security framework covers the network layer, transport layer, and application layer, providing carrier-grade security for enterprise customers.

SIP TLS Signaling Encryption

Uses TLS 1.2/1.3 protocols for full-link encryption of SIP signaling, preventing eavesdropping, interception, or tampering of signaling data to ensure the security of call setup and control processes.

SRTP Media Encryption

Voice media streams are transmitted via the SRTP protocol using AES-128/256 encryption algorithms to protect voice payload data, preventing call content from being intercepted or recorded.

IP Whitelisting

Strict IP access control policies allow only authorized endpoint IP addresses to connect to SIP trunks, effectively preventing unauthorized access and malicious attacks.

Firewall & DDoS Protection

Multi-layer network protection including border firewalls, intrusion detection systems, and DDoS traffic scrubbing to ensure high availability and stability of the communication platform.

Toll Fraud Prevention System

Toll fraud is one of the most common security threats in VoIP communications. Cainiao Voice has built a comprehensive multi-layer fraud prevention system, combining technical measures with manual monitoring to fully protect customers from financial losses.

  • Real-time CDR Monitoring: Real-time analysis of all Call Detail Records (CDRs) with automatic detection of abnormal calling patterns, such as sudden high traffic volumes or large volumes of calls outside business hours
  • Automatic Rate Limiting & Threshold Alerts: Dynamic thresholds based on account historical call data, with automatic alerts and rate limiting triggered when call volume, duration, or costs exceed predefined ranges
  • Per-Account Concurrent Call Limits: Maximum concurrent call limits set for each account to prevent large-scale fraudulent calling caused by account credential breaches
  • Special Rules for High-Risk Destinations: Special approval processes and stricter restriction policies for known high-risk call destinations
  • 24/7 NOC Team Monitoring: Professional Network Operations Center (NOC) team on duty around the clock for manual review and rapid response to anomalous events

International Compliance Framework

Cainiao Voice strictly complies with telecommunications regulatory requirements in each country and region, ensuring compliant operation of voice communication services. Below is an overview of compliance in our primary service markets:

Country/RegionRegulatorKey Compliance Requirements
SingaporeIMDALicensed operator qualification, SBO (Services-Based Operator) registration
PhilippinesNTCICF (International Carrier Facility) registration, number allocation compliance
MalaysiaMCMCNFP (Network Facilities Provider) registration, DID number KYC requirements
UAETDRALicensed telecommunications operator, strict VoIP regulatory policies
IndonesiaKominfoPSE (Private Electronic System) registration, local entity company required
ThailandNBTCType 3 telecommunications license, number portability compliance
VietnamMICTelecommunications operation license, local partner required
UKOfcomGeneral authorization regime, number allocation management
EUNational regulatorsGDPR compliance, ePrivacy Directive compliance

DID Number Compliance

The application and use of virtual numbers (DIDs) are strictly regulated by telecommunications authorities in each country. Cainiao Voice assists customers in completing compliance procedures to ensure the lawful use of DID numbers.

KYC Document Requirements

Depending on the country/region requirements, DID number applications typically require the following documents:

  • KYC Identity Verification Documents: Business license copy, organization registration certificate, or other valid registration documents
  • Local Address Proof: Some countries (such as Singapore, UK, Malaysia) require proof of a local office address
  • Company Registration Documents: Certificate of incorporation, tax registration certificate, and other statutory documents
  • Usage Declaration Form: A declaration document detailing the number usage scenarios and business purposes

Specific KYC document requirements may vary by country/region. Please refer to the DID KYC Document Requirements Guide by Country for detailed information.

Data Protection

Cainiao Voice places great importance on data security and privacy protection, following strict security standards throughout the entire data processing lifecycle.

  • CDR Retention Policy: Call detail records are retained for periods determined by legal requirements and business needs, with expired data automatically and securely destroyed
  • Data Localization: Compliance with data localization regulations in specific countries/regions, ensuring data storage and processing meet local legal requirements
  • GDPR Compliance: For data processing activities involving EU users, strict adherence to GDPR (General Data Protection Regulation) requirements, including data minimization, purpose limitation, and user rights protection principles
  • Secure Data Transmission: All data transmissions use encrypted channels (TLS 1.2+) to prevent data interception or leakage during transit

Security Certifications & Audits

Cainiao Voice continuously invests in security. Below is the current status of each security capability:

Security CapabilityStatusDetails
SIP TLS / SRTP Encrypted Transport✅ ImplementedFull-link SIP signaling encryption + voice media AES-128/256 encryption
Quarterly Security Assessments✅ ImplementedInternal security assessments every quarter to identify and remediate risks
Annual Third-Party Penetration Testing✅ ImplementedAnnual pen testing by independent security firms covering network, application, and business logic. Summary available under NDA
ISO 27001⏳ AlignedInformation security management system built in alignment with ISO 27001 standards. Formal certification not yet obtained
SOC 2 Type II⏳ In ProgressSOC 2 Type II compliance work is underway. Certification not yet completed

Frequently Asked Questions

How does Cainiao Voice ensure SIP signaling transmission security?

Cainiao Voice uses SIP over TLS (TLS 1.2/1.3) to encrypt SIP signaling across the entire link, preventing eavesdropping or tampering. Combined with SRTP for AES-128/256 encryption of voice media streams, we achieve dual-layer security for both signaling and media.

How does Cainiao Voice prevent toll fraud?

Cainiao Voice has established a multi-layer toll fraud prevention system, including real-time CDR anomaly pattern monitoring, automatic rate limiting and threshold alerts, per-account concurrent call limits, special rules for high-risk destinations, and 24/7 NOC team manual monitoring to ensure timely detection and blocking of abnormal call behavior.

What compliance documents are required to apply for DID numbers?

DID number applications typically require KYC identity verification documents, including a business license, legal representative identification, local address proof (required by some countries), and a number usage declaration form. Specific requirements vary by country and region. Please refer to our DID KYC document requirements guide by country for details.

Is Cainiao Voice compliant with GDPR data protection requirements?

Yes, Cainiao Voice follows GDPR requirements in data processing, including clear data retention policies, secure data transmission channels, data localization considerations, and comprehensive data access and deletion mechanisms to ensure full protection of personal data.

What security certifications does Cainiao Voice hold?

Cainiao Voice maintains high-standard security practices. Implemented: SIP TLS/SRTP full-link encryption, quarterly security assessments, annual third-party penetration testing (summary available under NDA). Aligned: ISO 27001 information security management system (formal certification not yet obtained). In Progress: SOC 2 Type II compliance (certification not yet completed). We continuously invest in security to protect our customers' communication infrastructure.