Acceptable use policy

Last updated 28 Jul 2026

This document is not yet complete. The registered legal entity name and company registration number have not been set. Until they are, this document names the trading brand only and should not be relied on as a final agreement. See config/company.php.

A shared network only works if nobody abuses it. This policy exists mostly because of toll fraud and nuisance calling, both of which cost real money and get ranges blocked for everyone on them.

What you must not do

Fraud and theft of service

  • Placing calls you do not intend to pay for, or using credentials you are not entitled to use
  • Traffic pumping — artificially generating calls to revenue-sharing destinations
  • Reselling termination in a way that disguises the true origin of traffic

Caller ID

  • Presenting a number you do not own or are not authorised to present
  • Presenting a number designed to mislead the person you are calling, including one resembling an emergency or government line

Presenting your own verified number, or a number your customer has authorised you to present on their behalf, is fine and expected. Anything else is spoofing, and it is illegal in most jurisdictions we route to.

Unsolicited calling

  • Automated or bulk calling without the recipient's consent, where consent is required
  • Ignoring do-not-call registers that apply to the destination
  • Silent or abandoned calls from a dialler

Harm to the network

  • Attempting to gain access to another customer's account or configuration
  • Deliberately generating load intended to degrade the service
  • Scanning or probing our infrastructure without written permission

What we do about it

We monitor for the patterns that indicate compromise: sudden bursts of international calls, concurrent calls far above an account's normal shape, and calls to destinations an account has never used. Where the signal is strong we suspend outbound calling immediately and contact you. That is deliberately biased toward false positives — an hour of interruption is cheaper for both of us than a night of fraudulent international traffic.

New accounts cannot dial international destinations until the first top-up. This is not a sales tactic; it is the single most effective control against stolen credentials on accounts with no payment history.

Your own security

Most compromises we see are not of our systems but of a customer's PBX: a default password, an open SIP port, or an extension reachable from the internet. Use the credentials we generate rather than one you can remember, restrict where your PBX accepts SIP from, and rotate a secret the moment you suspect it has leaked.

Reporting abuse

If you receive an unwanted call that originated on our network, write to abuse@voip.so with the number that called, the number called, and the approximate time. We can trace that precisely and will act on it.


Contact

Questions about this policy go to info@voip.so.