Communication Security Architecture
Cainiao Voice employs a multi-layer security architecture with full encryption from signaling to media streams, ensuring end-to-end communication security. Our security framework covers the network layer, transport layer, and application layer, providing carrier-grade security for enterprise customers.
SIP TLS Signaling Encryption
Uses TLS 1.2/1.3 protocols for full-link encryption of SIP signaling, preventing eavesdropping, interception, or tampering of signaling data to ensure the security of call setup and control processes.
SRTP Media Encryption
Voice media streams are transmitted via the SRTP protocol using AES-128/256 encryption algorithms to protect voice payload data, preventing call content from being intercepted or recorded.
IP Whitelisting
Strict IP access control policies allow only authorized endpoint IP addresses to connect to SIP trunks, effectively preventing unauthorized access and malicious attacks.
Firewall & DDoS Protection
Multi-layer network protection including border firewalls, intrusion detection systems, and DDoS traffic scrubbing to ensure high availability and stability of the communication platform.
Toll Fraud Prevention System
Toll fraud is one of the most common security threats in VoIP communications. Cainiao Voice has built a comprehensive multi-layer fraud prevention system, combining technical measures with manual monitoring to fully protect customers from financial losses.
- Real-time CDR Monitoring: Real-time analysis of all Call Detail Records (CDRs) with automatic detection of abnormal calling patterns, such as sudden high traffic volumes or large volumes of calls outside business hours
- Automatic Rate Limiting & Threshold Alerts: Dynamic thresholds based on account historical call data, with automatic alerts and rate limiting triggered when call volume, duration, or costs exceed predefined ranges
- Per-Account Concurrent Call Limits: Maximum concurrent call limits set for each account to prevent large-scale fraudulent calling caused by account credential breaches
- Special Rules for High-Risk Destinations: Special approval processes and stricter restriction policies for known high-risk call destinations
- 24/7 NOC Team Monitoring: Professional Network Operations Center (NOC) team on duty around the clock for manual review and rapid response to anomalous events
International Compliance Framework
Cainiao Voice strictly complies with telecommunications regulatory requirements in each country and region, ensuring compliant operation of voice communication services. Below is an overview of compliance in our primary service markets:
| Country/Region | Regulator | Key Compliance Requirements |
|---|---|---|
| Singapore | IMDA | Licensed operator qualification, SBO (Services-Based Operator) registration |
| Philippines | NTC | ICF (International Carrier Facility) registration, number allocation compliance |
| Malaysia | MCMC | NFP (Network Facilities Provider) registration, DID number KYC requirements |
| UAE | TDRA | Licensed telecommunications operator, strict VoIP regulatory policies |
| Indonesia | Kominfo | PSE (Private Electronic System) registration, local entity company required |
| Thailand | NBTC | Type 3 telecommunications license, number portability compliance |
| Vietnam | MIC | Telecommunications operation license, local partner required |
| UK | Ofcom | General authorization regime, number allocation management |
| EU | National regulators | GDPR compliance, ePrivacy Directive compliance |
DID Number Compliance
The application and use of virtual numbers (DIDs) are strictly regulated by telecommunications authorities in each country. Cainiao Voice assists customers in completing compliance procedures to ensure the lawful use of DID numbers.
KYC Document Requirements
Depending on the country/region requirements, DID number applications typically require the following documents:
- KYC Identity Verification Documents: Business license copy, organization registration certificate, or other valid registration documents
- Local Address Proof: Some countries (such as Singapore, UK, Malaysia) require proof of a local office address
- Company Registration Documents: Certificate of incorporation, tax registration certificate, and other statutory documents
- Usage Declaration Form: A declaration document detailing the number usage scenarios and business purposes
Specific KYC document requirements may vary by country/region. Please refer to the DID KYC Document Requirements Guide by Country for detailed information.
Data Protection
Cainiao Voice places great importance on data security and privacy protection, following strict security standards throughout the entire data processing lifecycle.
- CDR Retention Policy: Call detail records are retained for periods determined by legal requirements and business needs, with expired data automatically and securely destroyed
- Data Localization: Compliance with data localization regulations in specific countries/regions, ensuring data storage and processing meet local legal requirements
- GDPR Compliance: For data processing activities involving EU users, strict adherence to GDPR (General Data Protection Regulation) requirements, including data minimization, purpose limitation, and user rights protection principles
- Secure Data Transmission: All data transmissions use encrypted channels (TLS 1.2+) to prevent data interception or leakage during transit
Security Certifications & Audits
Cainiao Voice continuously invests in security. Below is the current status of each security capability:
| Security Capability | Status | Details |
|---|---|---|
| SIP TLS / SRTP Encrypted Transport | ✅ Implemented | Full-link SIP signaling encryption + voice media AES-128/256 encryption |
| Quarterly Security Assessments | ✅ Implemented | Internal security assessments every quarter to identify and remediate risks |
| Annual Third-Party Penetration Testing | ✅ Implemented | Annual pen testing by independent security firms covering network, application, and business logic. Summary available under NDA |
| ISO 27001 | ⏳ Aligned | Information security management system built in alignment with ISO 27001 standards. Formal certification not yet obtained |
| SOC 2 Type II | ⏳ In Progress | SOC 2 Type II compliance work is underway. Certification not yet completed |
Frequently Asked Questions
How does Cainiao Voice ensure SIP signaling transmission security?
Cainiao Voice uses SIP over TLS (TLS 1.2/1.3) to encrypt SIP signaling across the entire link, preventing eavesdropping or tampering. Combined with SRTP for AES-128/256 encryption of voice media streams, we achieve dual-layer security for both signaling and media.
How does Cainiao Voice prevent toll fraud?
Cainiao Voice has established a multi-layer toll fraud prevention system, including real-time CDR anomaly pattern monitoring, automatic rate limiting and threshold alerts, per-account concurrent call limits, special rules for high-risk destinations, and 24/7 NOC team manual monitoring to ensure timely detection and blocking of abnormal call behavior.
What compliance documents are required to apply for DID numbers?
DID number applications typically require KYC identity verification documents, including a business license, legal representative identification, local address proof (required by some countries), and a number usage declaration form. Specific requirements vary by country and region. Please refer to our DID KYC document requirements guide by country for details.
Is Cainiao Voice compliant with GDPR data protection requirements?
Yes, Cainiao Voice follows GDPR requirements in data processing, including clear data retention policies, secure data transmission channels, data localization considerations, and comprehensive data access and deletion mechanisms to ensure full protection of personal data.
What security certifications does Cainiao Voice hold?
Cainiao Voice maintains high-standard security practices. Implemented: SIP TLS/SRTP full-link encryption, quarterly security assessments, annual third-party penetration testing (summary available under NDA). Aligned: ISO 27001 information security management system (formal certification not yet obtained). In Progress: SOC 2 Type II compliance (certification not yet completed). We continuously invest in security to protect our customers' communication infrastructure.