Skip to content
BitsPath Voice
Carrier-grade softswitch / pure Rust

A softswitch a bank
can actually audit.

Pure Rust, end to end: no unsafe code anywhere the caller's bytes are parsed. SIP over UDP, TCP, TLS on 5061 and WebSocket, all listening at once. Every leg anchored on the engine. Recordings encrypted at rest and swept on each tenant's own retention policy. Running in Bangladesh, under Bangladeshi law. Every capability below is marked live, partial or planned, because a telephony page that blurs that line is not worth reading.

4
SIP transports live
0
Unsafe on the SIP path
BD
Hosting jurisdiction
sip-trace·TLS 5061
pcap / live
  1. UAC to UAS: REGISTER

    sip:alice@bitspath over TLS on 5061

  2. UAS to UAC: SIP/2.0 401 Unauthorized

    WWW-Authenticate: Digest, single-use nonce

  3. UAC to UAS: REGISTER

    Authorization: Digest response=…

  4. UAS to UAC: SIP/2.0 200 OK

    Binding stored; up to 5 per account

  5. UAC to UAS: INVITE

    sip:bob@bitspath; SDP offer (PCMU/PCMA/G722)

  6. UAS to UAC: SIP/2.0 100 Trying

    Admission control: tenant slot acquired

  7. UAS to UAC: SIP/2.0 180 Ringing

    B2BUA dispatched the outbound leg

  8. UAS to UAC: SIP/2.0 200 OK

    SDP answer; both legs anchored on the engine

  9. UAC to UAS: ACK

    Dialog confirmed; symmetric RTP latches

  10. UAC to UAS: BYE

    Call detail record written; recording closed

Transport
UDP / TCP / TLS / WS
Auth
Digest MD5 / SHA-256
Media
RTP / SRTP (zero-copy)

One call leg end to end: REGISTER, the 401 digest challenge, the authenticated REGISTER, then INVITE, 100, 180, 200, ACK and BYE. The 100 Trying is where admission control runs, and the BYE is where the call detail record is written and the recording closed.

What is BitsPath Voice

A pure-Rust telephony engine, headless by design.

It issues no identity of its own and renders no screen of its own. It switches calls, and it tells you precisely which parts of that job it does today.

BitsPath Voice is the carrier-grade softswitch sitting underneath theBitsPathunified-comms platform. It is the voice plane, and nothing else. Two processes carry the product: a SIP server holding the 5060, 5061 and 5066 listeners on host networking, and a control-plane API of roughly 217 routes beside it. The call engine reloads its configuration from the database rather than from a file on the host, so a routing change needs no restart.

About 127,000 lines of Rust across ten crates. The SIP parser, the transaction machines, the transports, the back-to-back user agent and the whole RTP and SRTP path are first-party code, and none of them contains a single unsafe block. What that buys is narrow and worth saying plainly: the class of vulnerability that comes from parsing a stranger's packet in a memory-unsafe language is closed by construction rather than by patching.

The operator console lives in the BitsPath portal at bitspath.com/voice. The control plane is reached over the platform gateway at /api/voice/*.

Built onPure Rust 2024Axum + TokioPostgreSQL 18rustlsNo unsafe code in the call path

Capability ledger

Every line says whether it runs today.

A telephony page that does not separate what is shipped from what is planned is not worth reading. So this one marks every capability, and the programme items stay on the page rather than disappearing from it.

Live
Runs on the production switch today.
Partial
Runs, with the limit named on the line.
Planned
Programme work. Not offered today, and not sold as though it were.

No parity score, no capacity benchmark and no customer name appears on this page. Sizing is done against a deployment, not against a slide.

A back-to-back user agent is the product, not a module inside one. Every leg terminates on the engine, so there is no direct media path between two endpoints and nothing bypasses the switch.

  • Pure-Rust B2BUA softswitch

    Live

    Ten crates plus an Axum API host. The SIP parser, the transaction machines, the transports, the back-to-back user agent and the whole RTP and SRTP path are first-party Rust, and none of them contains an unsafe block.

  • Full media anchor on every leg

    Live

    Each leg gets its own RTP port and the bridge relays or transcodes. No endpoint-to-endpoint media path exists to be misrouted.

  • Registrar with digest auth

    Live

    Single-use nonce with replay protection, and up to five simultaneous bindings for one account.

  • Inbound resolution in three steps

    Live

    Direct number lookup, then a regular-expression inbound route, then extension fan-out, resolving to one of fifteen route actions each with its own failure response.

  • Per-tenant admission control

    Live

    One choke point derives the tenant, acquires a concurrency slot, and answers 503 with Retry-After when the tenant is over its cap.

  • Hold and resume

    Live

    The bridge pauses rather than tearing down, so resume does not rebuild the media path from scratch.

  • Blind transfer

    Live

    Wired to a real REFER and NOTIFY exchange on the call path.

  • Attended transfer

    Partial

    The consultation step works, but the Replaces header on an incoming REFER is read only as a flag and the consultation dialog is never bridged. It behaves as a blind transfer with an extra hold step rather than an RFC 3891 attended transfer, and the control API rejects any transfer type other than blind.

  • Directed and group call pickup

    Live

    Answer a call ringing on another extension, by naming it or through a shared pickup group.

  • Call park and retrieval

    Partial

    Park and retrieve work over the SIP feature code with live media. The expiry sweep does not yet recall a forgotten parked call: it tears the call down instead of ringing it back, so park is for a deliberate hand-off rather than a parking lot left unattended.

  • Call forwarding, unconditional

    Live

    Forward every call for an extension to another destination. Database driven and reachable from a live call.

  • Call forward on busy or no answer

    Planned

    Conditional forwarding is not wired to a live call today. Only unconditional forwarding is, so a rule that should fire on busy or on timeout is programme work.

  • Dial plan with least cost routing

    Live

    A rule matcher over a closed set of conditions and route actions, with least cost routing evaluated inside that matcher rather than by a separate engine. Deliberately no arbitrary code runs in the call path.

  • Carrier trunking with interop hardening

    Live

    Persistent TCP with keepalive and dead detection, backoff reconnect, dialog stickiness, 401 and 407 challenge handling, RFC 3263 FQDN targets, and 423 Min-Expires honoured.

  • Early media (183 with SDP)

    Partial

    Implemented and shipped switched off. 183-with-SDP interop varies by carrier, so it is an operator opt-in rather than a default.

  • Ring groups with real strategies

    Live

    Members are loaded from the database at boot, so a ring group rings the people in it. Ring-all and sequential strategies are selected per group.

  • SIP transaction duplicate absorption

    Live

    A retransmitted request is absorbed at the transaction layer instead of being processed twice, which is what stops a duplicated INVITE from raising a second call leg on a lossy carrier link.

  • Live-call failover across nodes

    Planned

    Active standby with streaming replication is a deployment pattern available now. Replicating dialog and media state so calls in flight survive a node loss is not built, and the approved answer is an external session border pattern.

Wire-level support

Every RFC 3261 transport. The codecs you can actually use in production.

All four transports listen at once, and TLS is terminated inside the SIP process rather than at the edge, because the engine needs the real client address to place a registration and to latch media through NAT. Outbound offers stay on a conservative profile so hardware phones do not answer 415.

Transports
  • UDP:5060Live
    Default RFC 3261 transport with retransmission
  • TCP:5060Live
    Pooled connections, keepalive and dead detection
  • TLS:5061Live
    Terminated in the SIP process, real public certificate
  • WS:5066Live
    RFC 7118 for browsers, sip subprotocol enforced
Codecs
  • G.711 mu-lawLive
    Narrowband PSTN trunks
    PT 08 kHz
  • G.711 A-lawLive
    EU and carrier PSTN trunks
    PT 88 kHz
  • G.722Live
    Wideband HD voice, IP to IP
    PT 916 kHz
  • OpusLive
    On by default, offered first on the browser leg
    PT 11148 kHz
  • RFC 2833 DTMFLive
    Tone events carried outside the stream
    eventn/a
  • G.729Planned
    Scoped against a carrier's interconnect test plan
    PT 188 kHz

What is actually different

Four claims that survive a technical review.

Not a feature list. These are the four properties a bank's technical reviewer can check independently, and the four that a mature C softswitch cannot match without rewriting itself. Each one runs on the production switch today.

4
SIP transports live at once
5061
TLS port, terminated in-process
3
Codecs fully transcoded, plus Opus
0
Unsafe blocks on the SIP and media path

The switch is the product

Live

A dedicated SIP process holds UDP, TCP, TLS and WebSocket on host networking while the control API runs beside it. Every leg terminates on the engine, so there is no direct media path between two endpoints.

The tape is encrypted and swept, per tenant

Live

Recordings are written per call, encrypted at rest under AES-256-GCM, and deleted by a retention sweep that runs on the switch under each tenant's own policy. Making the tape a precondition of connecting the call is still being finished, and the ledger says so.

No unsafe code where the attacker writes

Live

The SIP parser, the transaction machines, the B2BUA, SDP handling and the entire RTP and SRTP path contain no unsafe code. That closes a whole class of vulnerability by construction rather than by patching.

Bangladeshi company, Bangladeshi jurisdiction

Live

The switch runs in Bangladesh, operated by a Bangladeshi company. The point is jurisdiction rather than location: an in-country data centre run by a foreign provider is still reachable under that provider's home law.

Compared honestly

vs an open-source C softswitch, a SIP proxy, and a cloud voice API.

Each of these is the right answer for somebody, and a mature open-source engine carries far more feature breadth than this one does. The comparison worth having is narrower: where a regulated operator needs memory safety on the parsing surface, recording it cannot accidentally skip, and a jurisdiction its regulator accepts.

Read the Planned row honestly: the mature open-source engines ship an operator-scriptable dial plan and this one does not, which is a real gap and a deliberate trade, since a fixed rule matcher means no arbitrary code runs in the call path. A SIP proxy remains an excellent front end for any of these.

The shipped reality

One switch, reproducible from source.

BitsPath Voice runs in production at voice.bitspath.com. The SIP server holds the listeners on host networking, the control plane runs beside it, PostgreSQL 18 carries the schema, and the running images are built from a named commit, so the binaries in production and the source tree agree. Rollback restores the previous images and configuration without touching the database or the media relay.

Auth chain

Wenme OAuth 2.1 with PKCE issues the session, and token audience, issuer and algorithm are validated rather than assumed. Darwan answers the permission question per action, so a role change takes effect without reissuing a session.

Media security

SRTP with SDES on the SIP legs, AES-CM-128 with HMAC-SHA1-80, and DTLS-SRTP with server-side ICE and a real TURN client on the browser leg. Recordings are encrypted at rest under AES-256-GCM with the master key held as deployment configuration.

Tenancy

Tenancy is in the schema from the first migration rather than bolted on afterwards, so tenant scope is a column on the tables that carry tenant data. Concurrency caps and recording policy are per tenant and enforced at admission.

Observability

Prometheus metrics for transactions, calls, rate limits and cache. RTCP receiver reports run on every leg, including the bridged two-party path, so round trip, jitter and loss are measured on the call that happened. Each cleared call closes its own record with billable seconds, clearing cause and a rated cost row.

~127K
Lines of Rust across ten crates
~217
REST control-plane routes
1
Production switch, reproducible from source
29
Unsafe sites, none on untrusted input
Built from

Rust 2024 edition. Axum with macros, multipart and websockets. Tokio. SQLx against PostgreSQL 18. rustls for TLS on the SIP leg. Release profile: opt-level 3, link-time optimization, codegen-units 1, panic abort.

$ cargo build --release
Compiling sip v0.1.0
Compiling media v0.1.0
Compiling call v0.1.0
Compiling pbx v0.1.0
Finished `release` profile [optimized] target(s)

Jurisdiction

The point is jurisdiction, not location.

An in-country data centre operated by a foreign provider still sits under that provider's home law. An in-country service operated by a Bangladeshi company does not. Everything below names the instrument it rests on, with its circular, its clause and its date, so a compliance officer can check it rather than take it.

What this page does not claim

Whether the 2026 telecommunications amendment on licensing telecom equipment reaches software is an open question for a bank's telecom counsel. We raise it rather than paper over it. Internal extension-to-extension calling needs no operator licence; calls to the public network ride a licensed operator's trunks, and the lawful intercept and record-retention duties that come with that licence are the licensee's, not the bank's.

Programme

What is not built yet, named on the page rather than found in a pilot.

These are the six pieces of work between the engine as it runs today and the engine a bank-wide rollout needs. They are on the roadmap with the engineering org behind them, and none of them is offered as a shipped capability anywhere else on this page.

The honest line on high availability: active standby with database streaming replication is deployable today and is a deployment pattern rather than engine work. Live-call failover is not built, and the approved answer is an external session border pattern in front of the switch. Both of the mature C softswitches document the same answer, so this is not a case of falling behind either of them specifically.

Frequently asked

Six questions a technical reviewer asks.

Answers are mirrored to JSON-LD so they are quotable by AI answer engines and search.

What is BitsPath Voice?

BitsPath Voice is a carrier-grade multi-tenant softswitch written end to end in pure Rust: ten crates plus an Axum control-plane host, roughly 127,000 lines. It speaks SIP RFC 3261 over UDP, TCP, TLS on 5061 and WebSocket, anchors media on every leg through a back-to-back user agent, and carries a WebRTC leg with server-side ICE for browsers. It runs in production on one switch in Bangladesh, reproducible from the repository.

Which capabilities are running today and which are programme work?

Every capability on this page carries a marker, and the page uses three. Live means it runs on the production switch: the softswitch and its four transports, media anchoring with G.711, G.722 and Opus transcoding, SRTP on the SIP legs and DTLS-SRTP on the browser leg, per-call recording with pause and resume, recordings encrypted at rest with a per-tenant retention sweep, closed billing records, a conference mixer with acoustic echo cancellation, queue agent pause, RTCP quality measurement on every leg, toll fraud controls with per-tenant thresholds, ring groups, queues, IVR, voicemail, presence and busy lamp field, token-gated device provisioning, Wenme sign-on and Darwan authorization, and in-country hosting. Partial means it works with a named limit, such as early media shipping switched off or the conference mixer lacking moderator controls. Planned means programme work that is not offered today: the mobile and browser softphone apps, live-call failover across nodes, fail-closed recording on every answer path, tamper seals and the access audit, supervisor listen, whisper and barge, conference moderation controls, per-tenant SRTP policy, call forward on busy or no answer, operator-scriptable dial plans, and the SIGTRAN carrier tier.

What does memory safety actually buy a bank here?

It removes a class of vulnerability from the surface an attacker can reach without anybody having to patch. Unsafe code appears 29 times in the whole tree and is confined to raw operating-system socket options and one audio library binding. There is no unsafe code at all in the SIP parser, the transaction state machines, the transports, the back-to-back user agent, SDP handling, or the RTP, RTCP and SRTP path. Those are exactly the places that parse bytes sent by a stranger. A mature engine written in C carries decades more feature breadth, and carries that whole class of risk with it.

How is recording different from recording on a conventional open-source PBX?

What is live is the part after the call is recorded, and it is the part a conventional open-source PBX leaves to the administrator. The file is encrypted at rest under AES-256-GCM with the master key held as deployment configuration, each tenant sets its own retention, and the sweep that applies it runs on the switch rather than in somebody's cron notes. What is not yet a guarantee, and is marked Planned rather than implied: making the tape a precondition of connecting the call on every answer path. A fail-closed policy exists in the engine, it is off by default, and three answer branches still connect without applying it. Also programme work: a hash seal computed at call end, an audit trail of every playback and export with a mandatory access reason, and legal hold. The Foreign Exchange Risk Management Guideline clause 2.2 requirement to tape dealing-room conversations is the target this is being finished against.

Why does hosting in Bangladesh matter if a global provider has a local region?

Because the question is jurisdiction, not location. The Bangladesh Bank Guidelines on Cloud Computing, BRPD Circular No. 05 of 16 March 2023, clauses 2.3.1.2 and 2.3.4.5, restrict customer financial and sensitive data from a cross-border public or hybrid cloud without prior approval. Separately, the US CLOUD Act, codified at 18 U.S.C. section 2713, obliges a US provider to produce data in its possession, custody or control wherever it is stored, which a local region does not change. A service run in Bangladesh by a Bangladeshi company sits outside both: no cross-border hosting, so no approval case, and no US order that reaches it.

What determines how many calls a node carries?

Bandwidth and port allocation rather than signalling. Every leg is anchored, so each one takes an RTP port from a configurable range, and the two-party bridge forwards packets without decoding and re-encoding whenever both legs settled on the same codec. Per-tenant and global concurrency caps are enforced at admission, and a tenant over its cap receives 503 with Retry-After rather than a failed call. RTCP receiver reports run on every leg, so what a node is actually carrying is measured rather than estimated. BitsPath Voice publishes no benchmark figure and no capacity claim: sizing is done against the trunk bandwidth, the port range and the recording storage a given deployment needs.

BitsPath Voice / live today

Switch the calls
in a language that does not leak.

Four transports, every leg anchored, recording enforced before the call connects, and no unsafe code where a stranger's packet is parsed. Sessions come from Wenme, every action is checked against Darwan, and the switch runs in Bangladesh. What is not built yet is marked Planned on this page rather than left for a proof of concept to discover.

On the wire, right now
  • SIP over UDP, TCP, TLS on 5061 and WebSocket, all listening at once
  • B2BUA with every leg anchored, and G.711, G.722 and Opus fully transcoded
  • Per-call recording, encrypted at rest, swept on each tenant's retention
  • SRTP on the SIP legs, DTLS-SRTP and server-side ICE on the browser leg
  • Ring groups, queues, IVR, voicemail, presence and busy lamp field, transfer
  • Toll fraud thresholds per tenant, RTCP on every leg, closed billing records
  • Wenme sign-on, Darwan authorization per action, hosted in Bangladesh