Two front doors, a pool of voice servers and a hot-standby management platform. Lose a part and the next call finds another way. Break any of them yourself, right on this page.
Calls keep connecting for 24 hours without managementHot standby, one commandEvery call quality-scored
Break it yourself
Take any part down. Watch the calls reroute.
This is the shape of the platform: phones, two front doors, a pool of voice servers, and a management platform with a hot standby. Press any box to take it down, and read what happens to your calls.
Failover simulatorLive demo
A diagram of a ProjectPBX cluster. Desk phones, the browser phone and the Android app connect through two front doors to three voice servers. A management platform with a hot standby supplies configuration. Press any part to take it down. The panel then says whether new calls still connect, whether changes are applied, and why. Calls already in progress on a failed part end. Buttons run common scenarios or play a guided tour.
Your people
Phones
Desk phone
Browser phone
Android app
Front doors different hosts
Voice servers health-checked
Management one shared address
New calls connectYesChanges appliedYes
Everything is up.
New calls spread across three voice servers. Edits reach every phone in about ten seconds.
Front doors are the first thing every phone and every call meets. Press a box to take it down, and press it again to bring it back. A part that is down is filled in and says so.
Every case, in words
What happens to calls and changes, part by part.
A front door
Calls connectChanges apply
Phones use the backup front door their company is given, on another host.
A voice server
Calls connectChanges apply
Health-aware routing sends the next call to a healthy server.
The management platform
Calls connectChanges wait
Last-known-good keeps working phones calling. Changes apply once it is back.
Then one command
Calls connectChanges in about 20 s
The hot standby takes over, behind the same address.
A company moving servers
Calls connectChanges apply
Both servers serve the company until the old one is empty.
A call already in progress on a failed front door or voice server ends, and the very next call connects on another.
24hCalls keep connecting for a full day, even with the management platform offline.
20sFor the hot standby to take over, with one command. Drilled both ways: 19 s and 20 s.
2Front doors. Every company can have a primary and a backup, on different hosts.
10sFrom saving a change to it being live on every phone. No restarts.
Safety nets
Safety nets that work on their own.
Health-aware routing and last-known-good need no setup, and 4voice keeps the hot standby in step. The one choice that is yours is encrypted desk phones, which you set per company.
Health-aware routing
Calls only go to voice servers that are healthy. One drops out and the very next call lands on another, with no one touching anything.
A backup front door
Front doors hide the voice servers, relay media and get phones through NAT. Each company gets a primary and a backup, on different hosts.
Last-known-good, 24 hours
Front doors keep every company's route, encrypted-phone mode and call-rate cap. Voice servers keep their directory and dialplan. Working phones keep calling.
Hot standby, one command
A live copy of the management database waits on a second server behind the same address. One command moves it into place in about twenty seconds.
Live company migration
Both servers serve the company during the move. Front doors flip routing, phones re-register, the old server drains, and voicemail boxes follow.
Every front door and every voice server keeps the last good copy of what it needs, saved to disk for up to 24 hours. A restart in the middle of an outage keeps it too.
Front doors remember
Every company's route, its encrypted-phone mode and its call-rate cap.
Voice servers remember
Each server's agent keeps the last good directory and dialplan.
No lost call records
Records of calls that end during the outage are kept and re-sent once management is back.
Proven in a live test
With the management platform blocked for 3 min 12 s, calls through both front doors kept connecting.
Outage timeline, 3 min 12 sLive demo
BeforeOutageAfter
Management platform
UpBlockedUp
New calls, front door A
Connecting
New calls, front door B
Connecting
Edits go live
AppliedWaitingApplied
Call records
SavedQueuedRe-sent
Proven. Nothing new applies until the management platform is back, and the records of calls that ended meanwhile are re-sent.
Hot standby
One command. Twenty seconds.
A streaming replica of the management database sits on a second server behind one shared address. Switch over or fail over with a single command, and watch the clock.
The old box is fenced first
Never a second primary.
A box that comes back
After a failover it fences itself.
Calls never wait
New calls keep connecting the whole time. Edits go live once the standby answers.
Drilled both ways
19 s and 20 s without a management platform, nothing lost, and a test call through each front door.
The standby drillLive demo
A real-time clock counts the twenty seconds of a standby takeover. New calls keep connecting the whole time. Changes wait until the standby is in place, and then they go live again. Press Run the drill to watch it, or read the final state shown by default.
00:20standby in place
1The old box is fenced.
2The standby replays everything and is promoted.
3The shared address moves to it.
4Calls and call records land on the new box.
New calls
Connecting
Edits go live
Waiting, about 20 sApplied
The standby is in place after about 20 seconds. Edits wait for it, and calls do not.
Live migration
Move a company. Never strand a phone.
Moving a company to another voice server runs in four phases, and at every one of them the company has a server to call through. Drag the slider and watch it happen.
Move a company between voice serversLive demo
A slider from 0 to 100 moves a company between two voice servers in four phases: overlap, cutover, drain and finalize. Twelve phones re-register from the old server to the new one, three calls finish on the old server, and the move finalizes only when the old server is empty.
New calls go toboth servers
Voice server 1
Serving
12phones registered
3calls in progress
Voicemail boxes here
Voice server 2
Serving too
0phones registered
0calls in progress
Waiting to receive them
Both servers serve the company. Nothing has moved yet, and nothing has to: every phone still has a home.
Mailboxes follow the move, and the old server is only let go once it is genuinely empty.
Call quality
Every call gets a score.
A monitor measures every call that crosses the front doors and scores it from 1 to 5 (MOS). When quality slips, a flag goes up before anyone has to complain.
Every leg scored
Browser phone and trunk legs are scored from the voice server's own measurements, so there is nothing for a phone to configure.
Flags that mean something
A score under 3.5, or packet loss above 5 percent, raises an alert in our monitoring.
Alerts where you work
With chat alerts on, poor calls are posted to Slack or Google Chat, as an add-on.
A report to match
Call quality scores show the average per day and per extension, as an add-on.
Score a callLive demo
A call setup ladder from a phone through a front door to a voice server, then the audio, then the hang-up. Two sliders, packet loss and one-way delay, change the call's score on a scale from 1 to 5. A score below 3.5, or loss above 5 percent, raises a flag.
PhoneFront doorVoice server
INVITE
100 Trying
180 Ringing
200 OK
ACK
Audio both waysScored here
BYE
200 OK
Call score (MOS)4.4Healthy
3.5
Quality is healthy. No flag.
Add-onCall quality scores, chat alerts and the network readiness test.
Encrypted desk phones
Encrypt every desk phone, at your pace.
Set it per company: Off, Offered or Required. Phones use SIP over TLS with the certificate and its name checked, and SRTP audio, ending at the front door.
Off
Standard SIP over UDP, until you are ready to encrypt.
Offered
Phones are provisioned for TLS while UDP still works, so you move across at your own pace.
Required
Front doors accept only TLS from the company's phones.
Browser phone
Audio is encrypted with DTLS-SRTP.
Encryption mode, per companyLive demo
Set it per company
Desk phone
TLS + SRTP
Front door
inside the network
Voice server
Offered: switch phones over at your pace.
Phones are provisioned for SIP over TLS, with the certificate and its name checked, and SRTP audio. The front door still accepts UDP from the company while phones move across.
Available per company. Browser phone audio is encrypted with DTLS-SRTP.
Watched and backed up
Every server reports in. Every company is backed up.
A short list of conditions raises a flag in our monitoring, a public status page tells you the rest, and your data is copied off-site on a schedule.
The call path runs on FreeSWITCH, Kamailio, rtpengine and PostgreSQL, tied together by a Python management platform. Transcription and voices run on our own servers.
KamailioFront doors
rtpengineMedia relay
FreeSWITCH 1.10Voice servers
PostgreSQL 16Settings and call records
Python + FastAPIManagement platform
LiveKitVideo
coturnTURN relay
WhisperTranscripts
PiperVoices
Every reliability feature
Everything that keeps the phones ringing.
Each one is live in ProjectPBX today. Open any of them for the full detail.
No. Health-aware routing and last-known-good work on their own, and 4voice keeps the hot standby in step. The one choice that is yours is encrypted desk phones, which you set per company: Off, Offered or Required.
What happens to a call that is already in progress?
If the front door or voice server carrying it fails, that call ends and the very next call connects on a healthy one. If the management platform goes offline, working phones keep registering and calling on last-known-good, so calls in progress carry on and new calls keep connecting.
How does the hot standby take over?
With one command. A streaming replica of the management database waits on a second server behind the same shared address. The old box is fenced first so it can never become a second primary, the standby is promoted and the address moves to it. Practiced both ways, it took 19 s and 20 s, with a test call through each front door.
How would we know an outage is happening?
Our monitoring raises an alert on bursts of failed calls, poor call quality and a management platform that stops answering. You can follow incidents and planned maintenance on status.4voice.io, and open incidents show as a banner in every portal.
Can you reserve a server for us?
Yes. A voice server can be reserved for a single company, and shared companies stay densely packed on the rest. Ask us on your demo and we will walk through how it would look.
See it live
Bring your worst what-if.
Tell us the outage that keeps you up at night. We will show you ProjectPBX running and talk through how it would go.