Enterprise deployment

Your PBX. Your voice.
Your infrastructure. Our AI.

Lumaa runs the same engine for a three-agent brokerage and a top-tier developer. This page is for the organisations that need it inside their stack rather than on top of it, with complex integrations to match: SIP and PBX integration, routing and escalation rules you define, a persona that is yours and not Maya, dedicated or on-premise deployment, a written SLA, and encryption keys you hold.

Book an architecture call See the deployment tiers
SIP
Your PBX, trunks & DIDs
SLA
Written into the agreement
BYOK
Keys carried in a 5-minute JWT
1-tenant
Dedicated or on your own servers
Who Lumaa is built for

From a single line
to a full custom build.

Lumaa is not a small-business tool with an enterprise sticker, and not an enterprise suite that talks down to a brokerage. The same platform serves the whole range, and the amount of it in your hands scales with you.

Small agencies and clinics

Live in days, on your own number

One registered line, an approved script, a list imported from the portal. Maya calls, qualifies, books, and hands you the recording and transcript. No IT project, no integration work.

Two to twenty seats · managed service
Growing and mid-size teams

Several campaigns, several lines, your CRM in the loop

Multiple agents with their own scripts, voices and hours; parallel lines with caps and pacing; a website form that triggers a call; webhooks feeding outcomes into your CRM or reporting stack.

Twenty to two hundred seats · managed service plus API
Top-tier developers, banks, insurers, contact centres

A fully custom solution, engineered with your IT team

Your PBX, trunks and DIDs; routing and escalation rules you define; a persona and voice that are yours; dedicated or on-premise infrastructure; keys you hold; a written SLA. Scoped by our engineers with yours, and built to your change-control process.

Enterprise agreement · the rest of this page
Deployment tiers

Three ways to run Lumaa.
Two of them live inside your telephony.

The managed service is what a brokerage or a clinic buys: Lumaa runs the calling on your registered numbers. Enterprise deployments are different in kind. Your gateway registers into Lumaa's PBX, or Lumaa's AI attaches to the PBX you already operate as one endpoint in your own dialplan. Both tiers have a written onboarding guide and a REST API behind them.

Tier 1 · Managed

Lumaa runs the calling on your numbers

Your registered UAE lines, your approved scripts, CSV or XLSX import, results in your dashboard with the recording and transcript.

  • Maya, or a persona named for your brand
  • Calling window enforced per campaign
  • No PBX work on your side
Agencies, clinics, dealerships, brokers
Tier 2 · Your gateway → Lumaa PBX + AI

Your trunks and DIDs, our PBX and AI

Your SIP trunk or GSM gateway registers against Lumaa's hosted FreeSWITCH or Asterisk PBX with per-trunk credentials and an IP allow-list. Your DIDs are registered and verified on every outbound call.

  • Per-trunk username, password and CIDR allow-list
  • Routing and escalation rules configured per persona
  • Multi-line concurrent campaigns with caps and pacing
  • Webhooks into your CRM or data warehouse
Contact centres, developers, insurers
Tier 3 · Your PBX → Lumaa AI only

You keep the phone system. We supply the agent.

Your Asterisk or FreeSWITCH keeps control of every call. Lumaa's AI attaches over ARI for call control and AudioSocket for media, or through the synchronous and streaming API. Your IVR, queues and VIP rules stay exactly where they are.

  • One endpoint in your dialplan; transfer and DTMF preserved
  • BYOK encryption with the JWT key workflow
  • Dedicated or on-premise deployment available
  • Keys held by you: AWS KMS or your own vault
IT directors who own the telephony stack
What enterprise means here

Every "we need" an IT director asks for,
answered on this page.

☎️

PBX and telephony integration, not a single phone line

Lumaa is a platform with a PBX layer, not a lightweight app over one number. Enterprise deployments connect your SIP trunks, GSM gateways (Dinstar and similar) and existing DIDs to Lumaa's hosted FreeSWITCH or Asterisk PBX, or attach Lumaa's AI to your own PBX as a media endpoint. SIP is IP-allow-listed per trunk, credentials are encrypted at rest, and line health is tracked so dialling stops within seconds on a bad line.

  • SIP trunk registration with a per-trunk CIDR allow-list
  • ARI call control and AudioSocket media on your Asterisk or FreeSWITCH
  • Your DIDs registered, checked against the caller ID on every outbound call
  • Multi-line concurrent campaigns; per-client line routing per campaign
; your dialplan — Lumaa's AI is one endpoint in it [lumaa-inbound] exten => _X.,1,NoOp(Lumaa AI call from ${CALLERID(num)}) same => n,Set(CHANNEL(rtp_codec),ulaw) same => n,AudioSocket(<lumaa-host>:<port>,${UNIQUEID}) same => n,Hangup() ; or: your trunk registers into Lumaa's PBX trunk per-trunk credential, issued at onboarding allow-list your gateway's IP range only DIDs registered, checked on every outbound call
🔀

Routing rules and human escalation you define

"If a VIP investor calls back, route to their relationship manager; if no answer in ten seconds, hand to the AI" is a routing rule, and it is yours to set. Escalation rules map a condition to an action per persona: an angry caller, a billing question or a request for a human transfers to a named number or team with the conversation's context attached. On your own PBX the rule lives in your dialplan; Lumaa's AI is one leg of it.

  • Per-persona escalation rules: condition → transfer target
  • Human first, AI on overflow; or AI first, human on request
  • Keypad (DTMF) input and warm transfer preserved
  • Per-account kill switch, three audited stop levels
🎙️

Your voice, your persona, your vocabulary

Maya is the default on the managed service. On an enterprise deployment the persona name, voice, opening line, system prompt, knowledge base, speech model, language model, temperature, reply length and interruption sensitivity are set per client and per campaign. Brand-voice matching is available. The knowledge base is built from your own documents, so the agent talks about your payment plans and your communities, not generic ones.

  • Any voice, including a voice matched to your brand
  • English and Arabic in production, mixed speech handled
  • Second-pass transcription biased to your vocabulary
  • Scripts approved by you before any call goes live
🏗️

Dedicated infrastructure, or your own

Enterprise deployments run single-tenant on dedicated infrastructure, or on servers and cloud accounts you own and administer, in the region you choose. Encryption keys can be held by you through AWS KMS or your own vault. AI provider accounts can be yours, stored encrypted per client. On a dedicated deployment, where the data lives is your decision.

  • Single-tenant, or installed on your own systems
  • Client-held keys: AWS KMS or your vault
  • Your own speech and language-model accounts, if you prefer
  • Nightly off-machine backups with a row-count check
📜

A service level agreement, in writing

Enterprise agreements carry an SLA: an availability commitment, response and resolution times by severity, a named account manager, and an escalation path that reaches a human. The figures are set in the agreement, which is why no uptime percentage appears on this site. Underneath it, eleven platform components are monitored continuously with 90 days of history and automatic incident opening on the public status page, and a watchdog restarts and escalates on failure.

  • Availability and response-time commitments per severity
  • Named account manager and human escalation path
  • Public status page plus a status endpoint for your monitoring
  • Annual audit right written into the DPA
🔐

BYOK encryption with a JWT key workflow, set up by us

Bring Your Own Key lets you encrypt sensitive caller fields with a key Lumaa never stores. Your server generates a content encryption key per request, signs a short-lived JSON Web Token containing it with HS256 using a signing secret issued once at setup, and sends the token with the request. Lumaa verifies the signature, the issued-at time and a five-minute maximum age, uses the key in memory for that request only, and discards it. Our engineers stand the whole workflow up with your team during the integration sprint.

  • Key never stored, never logged; used in memory and discarded
  • Token age capped at 300 seconds, clock skew tolerated at 5 seconds
  • On top of AES-256-GCM at rest and TLS 1.2+ with HSTS in transit
  • Scoped, hashed, revocable API keys; HMAC-signed webhooks with retries
# your side, per request 1. generate a fresh AES key # never sent raw, never stored by Lumaa 2. wrap it in a JWT, sign with HS256 # secret issued once at setup 3. send the token with the request # 5-minute ceiling on token age # Lumaa's side, every request verify signature · reject future-dated or stale tokens use the key in memory · discard it when the request ends
🔗

Salesforce, HubSpot, Oracle, your CRM: bidirectional, in real time

CRM integration is bidirectional and happens in real time: your CRM (Salesforce, HubSpot, Oracle, Zoho, Pipedrive, Bitrix24 or a custom system) sends Lumaa a lead or a trigger and the call is placed; Lumaa writes the outcome, the transcript and the recording back to the lead record as each call ends, over HMAC-signed webhooks with retries. Lumaa's engineers build the connection during onboarding, so there is no plugin to install and nothing for your team to maintain. Underneath it: a REST API with an OpenAPI specification, scoped keys and idempotent call placement, and signed events for completed and failed calls, transcripts and recordings, plus monthly call analytics. It is an integration our engineers build on the API rather than a marketplace plugin, and it works with any CRM that has one.

  • CRM to Lumaa: new lead or status change triggers a call
  • Lumaa to CRM: outcome, transcript, recording and callback time on the record
  • Built and tested by Lumaa during the integration sprint
🏠

Built and operated in-house. Nothing outsourced.

Lumaa's orchestrator, the system that runs the conversation, the telephony, the routing and the compliance controls, is built and operated in-house by Lumaa in Dubai. Nothing is outsourced to a third-party calling vendor; the only external components are the speech and language models, which are selectable per client and can run on your own provider accounts. That is why routing, escalation, encryption and the calling window can be changed for you in configuration rather than negotiated with a vendor behind us, and why the same engineers who built it run your deployment.

🧾

Audit, retention and UAE calling duties

Every call placed, every opt-out and every data event is written to an audit log kept for seven years; kill-switch, key-change and administrative actions are in it too. Recording retention defaults to 90 days and is set per client in the DPA. Calling windows under Cabinet Resolution 56 of 2024 are enforced per campaign and fail closed; every call is recorded with the notice in the approved script; do-not-call flags are honoured.

How a rollout runs

Four stages, scoped in writing
after the first call.

The calendar depends on your PBX and your change-control process, so we scope it after the architecture call rather than quote a number here.

01

Architecture call

Choose the tier. Map your numbers, trunks, routing and escalation rules, CRM touchpoints, data-residency and key-custody requirements. You leave with a written scope.

02

Integration sprint

SIP trunk or PBX connection, DIDs registered, persona and knowledge base built from your documents, escalation rules set, webhooks into your systems, and where used, the BYOK JWT workflow and dedicated infrastructure stood up.

03

Pilot

One line, one community or one queue, with scripts you approved. Recordings, transcripts and outcomes reviewed together; routing and vocabulary tuned.

04

Production under SLA

Named account manager, escalation path, status endpoint in your monitoring, annual audit right, and the commercial model you chose: flat monthly per line or per connected minute.

Managed vs enterprise

Same engine.
Different amount of it in your hands.

CapabilityManaged serviceEnterprise deployment
TelephonyYour registered UAE numbers; Lumaa runs the linesYour SIP trunks, GSM gateways and DIDs into Lumaa's PBX, or Lumaa's AI inside your own Asterisk or FreeSWITCH
Routing and escalationScript-defined handoff; callbacks kept automaticallyPer-persona escalation rules; VIP-first, AI-on-overflow or AI-first, human-on-request; warm transfer with context; your dialplan on Tier 3
Persona and voiceMaya, or a persona named for youFully custom: name, voice or brand-matched voice, prompt, knowledge base from your documents, models and tuning per campaign
InfrastructureLumaa-operated, multi-tenantSingle-tenant dedicated, or installed on infrastructure you own, in the region you choose
Key custodyLumaa-managed keys, AES-256-GCM at restClient-held keys via AWS KMS or your vault; BYOK per-request keys in a 5-minute HS256 JWT, never stored
IntegrationCSV or XLSX import to start; CRM integration added when you want itBidirectional real-time CRM integration (Salesforce, HubSpot, Oracle, custom) built by Lumaa's engineers on the REST API and HMAC-signed webhooks; OpenAPI spec; idempotent call placement; monthly analytics
Who builds and runs itLumaa's own orchestrator, built and operated in-house in DubaiThe same, deployed inside your stack by the engineers who built it; nothing outsourced to a third-party calling vendor
Support and SLAFounder-led support on WhatsAppWritten SLA: availability, response and resolution by severity, named account manager, human escalation path
Audit7-year audit log; recordings 90 days by defaultSame, plus annual audit right in the DPA and retention set per client
Commercial modelFlat monthly per line, or per connected minuteSame two models, scoped in writing with the SLA and any dedicated infrastructure

Everything in the enterprise column is documented in Lumaa's onboarding guides and API reference and was re-verified against the running system on 4 September 2026; the security controls are written down in the privacy policy and data processing agreement. Lumaa publishes no uptime percentage, no rate and no customer names; those go in the agreement. Where a capability is not offered, such as a marketplace CRM plugin you install yourself (our engineers build the integration instead), this page says so.

Enterprise questions

The questions an IT director asks
before the commercial team is allowed in.

Can Lumaa integrate with our existing PBX and contact centre?
Yes. Your SIP trunk or GSM gateway registers against Lumaa's hosted FreeSWITCH or Asterisk PBX with per-trunk credentials and an IP allow-list, or Lumaa's AI attaches to your own Asterisk or FreeSWITCH as a media endpoint over ARI and AudioSocket so your dialplan keeps control of every call. Your existing DIDs are registered and checked on every outbound call. Multiple concurrent lines are routed per campaign. This is a documented enterprise tier with an onboarding guide, not a custom favour.
Can we use our own voice and persona instead of Maya?
Yes. Maya is the default agent on the managed service; on an enterprise deployment the persona name, voice, opening line, system prompt, knowledge base, speech model, language model, temperature, reply length and interruption sensitivity are all set per client and per campaign. Brand-voice matching is available. The knowledge base is built from your own documents, so the agent speaks about your payment plans, your communities and your policies, not generic ones. Scripts are approved by you before any call goes live.
Does Lumaa support call routing rules and escalation to a human?
Yes. Escalation rules are configured per persona and map a condition to an action, for example an angry caller or a billing question transferred to a named number or team. Routing can send a VIP caller to their relationship manager first and hand the AI the call only if that manager does not answer within a set time, or put the AI in front and transfer to a human with the full context of the conversation. On your own PBX the routing lives in your dialplan and Lumaa's AI is one endpoint in it. A per-account kill switch pauses every AI call with one request.
Can Lumaa run on our own infrastructure?
Yes. Enterprise deployments can run single-tenant on dedicated infrastructure, or on servers and cloud accounts you own and administer, in the region you choose. Encryption keys can be held by you through AWS KMS or your own vault, and the AI provider accounts can be yours, stored encrypted per client. On a dedicated deployment, where the data lives is your decision. The shared managed service does not make a UAE data-residency claim; a dedicated deployment on your own infrastructure is how residency is achieved.
Does Lumaa offer a service level agreement (SLA)?
Yes. Enterprise agreements carry a written SLA: an availability commitment, response and resolution times by severity, a named account manager, and an escalation path with a human on the other end. The figures are set in the agreement rather than on a web page, which is why Lumaa publishes no uptime percentage on its site. Underneath it, eleven platform components are monitored continuously with 90 days of history and automatic incident opening, published on the public status page, and a watchdog restarts and escalates to a human on failure.
What is the BYOK encryption and JWT workflow?
Bring Your Own Key (BYOK) lets you encrypt sensitive caller fields with a key Lumaa never stores. Your server generates a content encryption key per request, signs a short-lived JSON Web Token (JWT) containing it with HS256 using a signing secret issued once at setup, and sends the token with the request. Lumaa checks the signature, the issued-at time and a five-minute maximum age, uses the key in memory for that request only, and discards it. Lumaa's engineers set the workflow up with your team, including key generation, token signing and the token exchange, as part of the integration sprint. This sits on top of AES-256-GCM encryption at rest and TLS 1.2 or newer in transit.
Does Lumaa integrate with Salesforce, HubSpot, Oracle or our internal CRM?
Yes. CRM integration is bidirectional and happens in real time: your CRM (Salesforce, HubSpot, Oracle, Zoho, Pipedrive, Bitrix24 or a custom system) sends Lumaa a lead or a trigger and the call is placed; Lumaa writes the outcome, the transcript and the recording back to the lead record as each call ends, over HMAC-signed webhooks with retries. Lumaa's engineers build the connection during onboarding, so there is no plugin to install and nothing for your team to maintain. Underneath it is a REST API with scoped, hashed, revocable keys, an OpenAPI specification and HMAC-signed webhooks with retries for completed and failed calls, transcripts and recordings. It is an integration built on the API rather than a marketplace plugin, so it works with any CRM that has an API, including internal ones.
Is Lumaa an outsourced service or its own platform?
Its own platform. Lumaa's orchestrator, the system that runs the conversation, the telephony, the routing and the compliance controls, is built and operated in-house by Lumaa in Dubai. Nothing is outsourced to a third-party calling vendor; the only external components are the speech and language models, which are selectable per client and can run on your own provider accounts. Managed means Lumaa's engineers operate the deployment for you; it does not mean the work is passed to someone else.
Can Lumaa handle enterprise call volumes on multiple concurrent lines?
Yes. Campaigns run on multiple lines at once, with per-client line routing assignable per campaign, concurrent-call, daily and monthly caps, randomised pacing, and line health tracked so dialling stops within seconds on a bad line. Launch-day campaigns use parallel lines. Idempotent call placement stops a retrying system from double-dialling a lead. Calling windows are enforced per campaign and fail closed under Cabinet Resolution 56 of 2024.
How long does an enterprise rollout take?
It runs in four stages: an architecture call to choose the deployment tier and map numbers, routing and escalation; an integration sprint covering SIP trunk or PBX connection, DIDs, escalation rules, webhooks and, where used, the BYOK JWT setup and dedicated infrastructure; a pilot on one line or one community with approved scripts; then production under the SLA with a named account manager. The calendar depends on your PBX and change-control process, so Lumaa scopes it in writing after the architecture call rather than quoting a number here.

Page last updated . Capabilities checked against the onboarding guides, API reference and running system the same day.

Book the architecture call.

Bring your IT lead. We will map your PBX, routing, key custody and deployment tier on the call and send a written scope afterwards. No deck, no rates on a web page.

We reply on WhatsApp, usually within a few hours, and follow up with a written scope.

✓ Message sent. We'll be in touch on WhatsApp shortly.