VOIMAR
Security

Nothing in the clear, and nobody out of scope

vKOM Secure is built for organisations that expect to be probed. The controls below are built and running in the pilot.

Nothing in the clear from the internet

Built, in pilot testing
  • Signalling only over TLS (SIP-TLS and secure WebSocket)
  • Voice encrypted to phones and browsers (SRTP and DTLS-SRTP)
  • Default-deny firewalls on every server
  • Network topology hidden from the outside

Toll-fraud and attack shield

Built, in pilot testing
  • Flood detection, scanner blocking and automatic bans pushed into the firewall
  • Brute-force lock-outs
  • Per-customer limits on simultaneous calls and calls per minute
  • Phones cannot fake their identity

Administrator security

Built, in pilot testing
  • Single sign-on with Voimar ID, VOIMAR's identity service (being switched on), with multi-factor sign-in for administrators
  • One sealed emergency administrator account, which raises alerts when it is used
  • Two-step sign-in and a complete audit log

API security

Built, in pilot testing
  • Keys tied to one customer and to approved server addresses
  • Encrypted, certificate-pinned connections
  • Abuse detection

Resilience

Built, in pilot testing
  • Emergency calling keeps working through an outage of the central database

Sovereignty

Built, in pilot testing
  • No foreign cloud: everything runs on VOIMAR or customer hardware in South Africa
  • It is designed to run with no internet at all inside a closed network

Rolling out now

Rolling out

Built, and being switched on across the platform.

  • Encryption of every link between vKOM Secure's own servers, using a WireGuard mesh with an extra preshared-key layer, a hedge against future quantum attacks
  • Regional emergency caller ID, with Cape Town and Durban numbers being allocated
  • Voimar ID sign-in for all customers

vKOM Secure is built for defence and government security requirements. We do not claim any certification or accreditation for it.