Hosted PBX operators
Contain fraud without handing the app general root.
Prevent · Detect · Contain · Recover
A fail-closed operations platform for telephony security — not a public dashboard. It connects live ESL events to operator evidence, least-privilege containment, and controlled recovery on 127.0.0.1:8099.
For hosted-PBX operators, security teams and on-call engineers who need detection, lockdown and unlock runbooks — not another Grafana wallpaper.
When outbound fraud and recovery are split across logs, firewalls and memory, teams typically hit:
One platform: CHANNEL_CREATE outbound → ESL normalize → Redis windows → fraud_incident row → broker lockdown → operator HTML email → two-step unlock (carrier re-enable separate)
flowchart TB Prevent[Prevent: SIP ACL Lua dialplan] --> FS[FreeSWITCH ESL] FS --> Nest[NestJS orchestrator] Nest --> Redis[(Redis windows)] Nest --> PG[(PostgreSQL audit)] Nest --> Broker[Allowlisted broker] Nest --> Email[Operator HTML email] API[127.0.0.1:8099] --> Broker
This product is a productized delivery of the documented engineering case study — evidence stays on this page so you do not have to guess what was shipped.




Full case study with video and FAQ →
Configure this scope & send RFQ →
Contain fraud without handing the app general root.
Readable critical email with a first-response checklist.
ESL rules plus independent Lua/ACL prevention.
Per-instance monitor in the estimator — not a public GUI.
| Traditional setup | This product direction |
|---|---|
| Find fraud in the carrier invoice | ESL + Redis windows while the call is still happening |
| SSH and iptables from memory | Incident row first, then allowlisted broker actions |
| App has root on FreeSWITCH | Least-privilege broker allowlist |
| Unlock reopens the gateway | Unlock clears lockdown; carrier re-enable is gated separately |
Unifies alerting, explainable rules, durable PostgreSQL incidents and recovery that does not silently reopen billing. Call-path prevention (digest, ACL, Lua) stays independent if ESL, Redis or Postgres fail.
Estimates are scope-based planning figures — not binding quotes. Taxes, carrier deposits, DIDs and third-party AI usage are scoped in discovery.
No. Digest auth, ACL and Lua/dialplan guards stay independent of monitor health.
Not in this design — bind 127.0.0.1:8099. Remote exposure needs a separate security design.
No. Unlock clears lockdown after preflight and confirm; carrier reactivation is a separate procedure.
No. The case study does not invent attack volume or SMTP delivery stats.
Yes — ESL rules, broker containment and runbooks scoped to your carriers.
Per-instance pricing in the quote builder.
Optional requirement — outbox exists; production delivery is scoped.
This product is BYOC / own SIP — CPaaS pass-through is not the fraud path.