Lumaa runs the same engine for a three-agent brokerage and a top-tier developer. This page is for the organisations that need it inside their stack rather than on top of it, with complex integrations to match: SIP and PBX integration, routing and escalation rules you define, a persona that is yours and not Maya, dedicated or on-premise deployment, a written SLA, and encryption keys you hold.
Lumaa is not a small-business tool with an enterprise sticker, and not an enterprise suite that talks down to a brokerage. The same platform serves the whole range, and the amount of it in your hands scales with you.
One registered line, an approved script, a list imported from the portal. Maya calls, qualifies, books, and hands you the recording and transcript. No IT project, no integration work.
Multiple agents with their own scripts, voices and hours; parallel lines with caps and pacing; a website form that triggers a call; webhooks feeding outcomes into your CRM or reporting stack.
Your PBX, trunks and DIDs; routing and escalation rules you define; a persona and voice that are yours; dedicated or on-premise infrastructure; keys you hold; a written SLA. Scoped by our engineers with yours, and built to your change-control process.
The managed service is what a brokerage or a clinic buys: Lumaa runs the calling on your registered numbers. Enterprise deployments are different in kind. Your gateway registers into Lumaa's PBX, or Lumaa's AI attaches to the PBX you already operate as one endpoint in your own dialplan. Both tiers have a written onboarding guide and a REST API behind them.
Your registered UAE lines, your approved scripts, CSV or XLSX import, results in your dashboard with the recording and transcript.
Your SIP trunk or GSM gateway registers against Lumaa's hosted FreeSWITCH or Asterisk PBX with per-trunk credentials and an IP allow-list. Your DIDs are registered and verified on every outbound call.
Your Asterisk or FreeSWITCH keeps control of every call. Lumaa's AI attaches over ARI for call control and AudioSocket for media, or through the synchronous and streaming API. Your IVR, queues and VIP rules stay exactly where they are.
Lumaa is a platform with a PBX layer, not a lightweight app over one number. Enterprise deployments connect your SIP trunks, GSM gateways (Dinstar and similar) and existing DIDs to Lumaa's hosted FreeSWITCH or Asterisk PBX, or attach Lumaa's AI to your own PBX as a media endpoint. SIP is IP-allow-listed per trunk, credentials are encrypted at rest, and line health is tracked so dialling stops within seconds on a bad line.
"If a VIP investor calls back, route to their relationship manager; if no answer in ten seconds, hand to the AI" is a routing rule, and it is yours to set. Escalation rules map a condition to an action per persona: an angry caller, a billing question or a request for a human transfers to a named number or team with the conversation's context attached. On your own PBX the rule lives in your dialplan; Lumaa's AI is one leg of it.
Maya is the default on the managed service. On an enterprise deployment the persona name, voice, opening line, system prompt, knowledge base, speech model, language model, temperature, reply length and interruption sensitivity are set per client and per campaign. Brand-voice matching is available. The knowledge base is built from your own documents, so the agent talks about your payment plans and your communities, not generic ones.
Enterprise deployments run single-tenant on dedicated infrastructure, or on servers and cloud accounts you own and administer, in the region you choose. Encryption keys can be held by you through AWS KMS or your own vault. AI provider accounts can be yours, stored encrypted per client. On a dedicated deployment, where the data lives is your decision.
Enterprise agreements carry an SLA: an availability commitment, response and resolution times by severity, a named account manager, and an escalation path that reaches a human. The figures are set in the agreement, which is why no uptime percentage appears on this site. Underneath it, eleven platform components are monitored continuously with 90 days of history and automatic incident opening on the public status page, and a watchdog restarts and escalates on failure.
Bring Your Own Key lets you encrypt sensitive caller fields with a key Lumaa never stores. Your server generates a content encryption key per request, signs a short-lived JSON Web Token containing it with HS256 using a signing secret issued once at setup, and sends the token with the request. Lumaa verifies the signature, the issued-at time and a five-minute maximum age, uses the key in memory for that request only, and discards it. Our engineers stand the whole workflow up with your team during the integration sprint.
CRM integration is bidirectional and happens in real time: your CRM (Salesforce, HubSpot, Oracle, Zoho, Pipedrive, Bitrix24 or a custom system) sends Lumaa a lead or a trigger and the call is placed; Lumaa writes the outcome, the transcript and the recording back to the lead record as each call ends, over HMAC-signed webhooks with retries. Lumaa's engineers build the connection during onboarding, so there is no plugin to install and nothing for your team to maintain. Underneath it: a REST API with an OpenAPI specification, scoped keys and idempotent call placement, and signed events for completed and failed calls, transcripts and recordings, plus monthly call analytics. It is an integration our engineers build on the API rather than a marketplace plugin, and it works with any CRM that has one.
Lumaa's orchestrator, the system that runs the conversation, the telephony, the routing and the compliance controls, is built and operated in-house by Lumaa in Dubai. Nothing is outsourced to a third-party calling vendor; the only external components are the speech and language models, which are selectable per client and can run on your own provider accounts. That is why routing, escalation, encryption and the calling window can be changed for you in configuration rather than negotiated with a vendor behind us, and why the same engineers who built it run your deployment.
Every call placed, every opt-out and every data event is written to an audit log kept for seven years; kill-switch, key-change and administrative actions are in it too. Recording retention defaults to 90 days and is set per client in the DPA. Calling windows under Cabinet Resolution 56 of 2024 are enforced per campaign and fail closed; every call is recorded with the notice in the approved script; do-not-call flags are honoured.
The calendar depends on your PBX and your change-control process, so we scope it after the architecture call rather than quote a number here.
Choose the tier. Map your numbers, trunks, routing and escalation rules, CRM touchpoints, data-residency and key-custody requirements. You leave with a written scope.
SIP trunk or PBX connection, DIDs registered, persona and knowledge base built from your documents, escalation rules set, webhooks into your systems, and where used, the BYOK JWT workflow and dedicated infrastructure stood up.
One line, one community or one queue, with scripts you approved. Recordings, transcripts and outcomes reviewed together; routing and vocabulary tuned.
Named account manager, escalation path, status endpoint in your monitoring, annual audit right, and the commercial model you chose: flat monthly per line or per connected minute.
| Capability | Managed service | Enterprise deployment |
|---|---|---|
| Telephony | Your registered UAE numbers; Lumaa runs the lines | Your SIP trunks, GSM gateways and DIDs into Lumaa's PBX, or Lumaa's AI inside your own Asterisk or FreeSWITCH |
| Routing and escalation | Script-defined handoff; callbacks kept automatically | Per-persona escalation rules; VIP-first, AI-on-overflow or AI-first, human-on-request; warm transfer with context; your dialplan on Tier 3 |
| Persona and voice | Maya, or a persona named for you | Fully custom: name, voice or brand-matched voice, prompt, knowledge base from your documents, models and tuning per campaign |
| Infrastructure | Lumaa-operated, multi-tenant | Single-tenant dedicated, or installed on infrastructure you own, in the region you choose |
| Key custody | Lumaa-managed keys, AES-256-GCM at rest | Client-held keys via AWS KMS or your vault; BYOK per-request keys in a 5-minute HS256 JWT, never stored |
| Integration | CSV or XLSX import to start; CRM integration added when you want it | Bidirectional real-time CRM integration (Salesforce, HubSpot, Oracle, custom) built by Lumaa's engineers on the REST API and HMAC-signed webhooks; OpenAPI spec; idempotent call placement; monthly analytics |
| Who builds and runs it | Lumaa's own orchestrator, built and operated in-house in Dubai | The same, deployed inside your stack by the engineers who built it; nothing outsourced to a third-party calling vendor |
| Support and SLA | Founder-led support on WhatsApp | Written SLA: availability, response and resolution by severity, named account manager, human escalation path |
| Audit | 7-year audit log; recordings 90 days by default | Same, plus annual audit right in the DPA and retention set per client |
| Commercial model | Flat monthly per line, or per connected minute | Same two models, scoped in writing with the SLA and any dedicated infrastructure |
Everything in the enterprise column is documented in Lumaa's onboarding guides and API reference and was re-verified against the running system on 4 September 2026; the security controls are written down in the privacy policy and data processing agreement. Lumaa publishes no uptime percentage, no rate and no customer names; those go in the agreement. Where a capability is not offered, such as a marketplace CRM plugin you install yourself (our engineers build the integration instead), this page says so.
Page last updated . Capabilities checked against the onboarding guides, API reference and running system the same day.
Bring your IT lead. We will map your PBX, routing, key custody and deployment tier on the call and send a written scope afterwards. No deck, no rates on a web page.