Skip to content
§
§ · build vs buy

Telecom Fraud Management Software: Build Custom or Buy Subex

Most operators should not build. If your outbound international exposure is small, bar international by default with opt in, set a low per customer ceiling, and you have removed the catastrophic case for nothing.

Custom Software Development software overview illustration for Telecom Fraud Management Software Build vs Buy Guide.
The short answer

Most operators should not build. If your outbound international exposure is small, bar international by default with opt in, set a low per customer ceiling, and you have removed the catastrophic case for nothing. If you are a large carrier with a staffed fraud function, buy Subex or Mobileum. Building fits the middle: hosted voice and wholesale operators who need rule changes in hours rather than release cycles.

What Subex, Mobileum, TransNexus and Araxxe actually do well

Friday evening, a customer's on premise private branch exchange with a weak Session Initiation Protocol password gets registered by someone who is not the customer. Short test calls first, then sustained concurrent traffic to a premium range in a country you have never terminated to. It runs all weekend. On Monday the calls are minutes on somebody's switch, the premium revenue has already been shared upstream, and your wholesale carrier will invoice you for every second.

Subex and Mobileum are the serious names here and they are serious for good reason. Their platforms carry deep telecom domain knowledge accumulated across large carrier deployments, with control libraries covering International Revenue Share Fraud, Wangiri callback bait, subscription fraud and bypass. Mobileum in particular brings roaming and fraud heritage together, which matters if your loss profile is retail mobile. Araxxe takes a genuinely different angle by generating real test transactions and verifying they appear correctly on the bill. Xintec is credible in adjacent detection. TransNexus is genuinely good at Session Initiation Protocol layer analytics and call authentication, and many hosted voice providers already run it without realising how much of the problem it covers.

Before any of that, there is a control that costs nothing and beats every platform on return. Bar international outbound by default and require opt in per customer. Set a hard destination allow list for customers who genuinely need it. Apply a low per customer credit ceiling. If most of your customers rarely call abroad, do that this week and stop reading, because almost all catastrophic single event loss in this category is outbound international.

Where they stop: your detection latency is your billing cycle

Most operators detect fraud from call detail records after mediation, which arrive in a batch hours after the calls and sometimes the next day. That is fine for revenue assurance and useless here, because the exposure window in an International Revenue Share Fraud event is measured in hours. A detection system running on yesterday's records is an expensive way of reading your own invoice early.

The enterprise suites can consume near real time feeds, so the gap is not capability. It is fit and control. They are scoped, priced and implemented for operators with a fraud team and a multi quarter deployment. Tuning to your traffic is a professional services engagement, and every subsequent tuning cycle is another one. When your engineer sees a new pattern on Saturday afternoon, filing a ticket is not a defence.

The second stopping point is action. Plenty of operators have alerting. Very few have automated blocking, because blocking wrong takes a paying customer's phones down. The way out is graduated response rather than a single switch: cap concurrent channels to one destination without dropping live calls, bar one prefix range for one customer, suspend international outbound while leaving domestic and emergency calling intact, deregister a compromised endpoint and force re authentication. Each tier is reversible and scoped to one account, and each has to be wired into your own session border controllers, which no vendor can do generically.

The third is baselining. A dental practice that has never called abroad and a freight forwarder that calls Lagos daily need different thresholds. A single global spend limit catches crude attacks and generates false positives against exactly the customers you least want to annoy, until support raises the limit permanently and the control quietly stops existing.

The arithmetic: cost per subscriber versus a build

Fraud platforms are usually priced per subscriber or per seat per month, sometimes per event volume, with implementation and tuning quoted separately. Ask for the three year total including professional services, because the first year figure understates it consistently.

Now the build. A real time detection and automated blocking layer runs $80,000 to $175,000 in our delivery experience, covering live event ingestion from your switch or session border controller, rolling counters, per customer behavioural baselines, a rule engine your team can edit, graduated actions and a case queue with audit. Amortise the midpoint over five years, add year two support at the rate below, and you carry roughly $33,000 to $41,000 a year.

At $0.40 per seat per month, that build costs the same as roughly 6,900 to 8,500 seats. At $1.00 per seat it falls to about 2,800 to 3,400. For a wholesale operator the honest denominator is minutes: at 40 million billable international minutes a year the build is about a tenth of a cent per minute, which disappears against a single weekend event.

The number that decides it is not on either quote. Take your largest fraud loss in the last three years, or your most plausible one if you have been lucky, and divide by the annual build cost above. For most hosted voice operators the answer is between one and four, which means the build pays for itself on one incident it prevents. If you cannot name a plausible five figure event, you are in the buy or cap group and should stay there.

What a custom build actually costs

A first release covering out of band event ingestion, rolling counters per customer, trunk, destination prefix and originating address, per customer behavioural baselines, an editable rule engine, graduated automated actions wired into your controls, a case queue with full audit and shadow mode against live traffic runs $80,000 to $175,000 across 12 to 18 weeks.

Extending into learned scoring, subscription and identity swap detection, bypass detection and revenue assurance reconciliation against wholesale invoices runs $220,000 to $500,000 phased over 8 to 14 months.

Data migration is 10 to 25 percent of build cost, and in this category it is mostly historical call detail records and your existing case history. You want at least twelve months of records to establish baselines that survive seasonality, plus labelled outcomes for every incident you can reconstruct. Those labels are what make later scoring worth anything, and reconstructing them from ticket threads is slower than anyone estimates.

Year two runs 15 to 20 percent of build cost annually. The specific driver is that fraud patterns change faster than any software category we work in. You are funding continuous rule development, not maintenance, and the operator who can adapt in an hour beats the one waiting on a release. Budget engineering time for your own team as well, because the rule set is the asset and it should be written by people who watch your traffic.

The four situations where building wins

  • Regulatory and standards fit. Call authentication obligations, the attestation your outbound traffic carries, and the numbering plan rules under which premium ranges are allocated all sit in your signalling path. If you already run authentication at the session border controller, fraud detection belongs beside it rather than in a separate platform reading records after the fact. Detection must also be strictly out of band, because a fraud feed that can affect call flow is a worse risk than the fraud.
  • Scale economics. Past roughly 3,000 seats on typical per seat pricing, or any wholesale operation with meaningful international termination, the arithmetic above turns.
  • A workflow that is your advantage. Your rule set accumulates your operation's knowledge of how you get attacked. If detection quality is part of what you sell to enterprise customers, that logic is a commercial asset and should not sit inside a vendor's tenancy where you cannot read it or take it with you.
  • Integration sprawl across three or more systems. Count them: the softswitch or class 4 platform, the session border controller, provisioning, the billing or rating platform for exposure, and the reseller hierarchy where the account you must suspend sits three levels below the one you bill. Once three or more must agree to contain an event, the orchestration is the product.

How to decide in a week

Pull one week of call detail records, ideally a week containing an incident. For every customer compute four things: the set of destination countries they had never called before that week, peak concurrent channels, the hour of day distribution, and the ratio of answered to attempted calls. Then write one rule on paper: a first ever destination combined with rising concurrency outside their normal hours.

Apply that rule to your worst historical incident and note the timestamp it would have fired. Compare it against when a human actually noticed. That interval, in hours, multiplied by your termination cost at the concurrency observed, is the value of the whole project and it takes an analyst a day to produce.

Run the second test on your controls, not your data. Time how long it takes, right now, to bar a single destination prefix for a single customer without affecting anyone else. If the answer involves a change window, a vendor ticket or a global configuration file, you do not have a containment capability and no detection product will give you one.

Finally, ask your prospective supplier or developer to describe the International Revenue Share Fraud signature specifically: what the test phase looks like, why concurrency matters more than call count, and why a destination being new to that customer is the strongest single feature. That question separates people who have worked in telecom from people who have built generic anomaly detection.

If the tests point to building, take a paid discovery phase rather than a proposal. Digital Heroes runs discovery to a signed product requirements document covering the ingestion path, the rule model, graduated action tiers and acceptance criteria. The specification is yours to take to any other firm you are considering. We are the wrong partner if you have nobody who will own the rule set, because rules nobody tunes decay within a quarter. We are an India LLP with US LLC and UK LTD entities so intellectual property assigns under your own law, with more than fifty specialists, over 2,000 projects delivered, a named team you meet before signing, and a public record on Clutch, Trustpilot, Fiverr Vetted Pro and D-U-N-S.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. The average developer spends more than 17 hours a week dealing with maintenance issues such as debugging and refactoring, and about four of those hours on 'bad code' - waste that equates to nearly $85 billion annually worldwide in opportunity cost. Source: Stripe (2018) →
  2. Deloitte's research found that digitally advanced small businesses experienced revenue growth nearly 4x as high as the prior year, were about 3x as likely to have exported, were nearly 3x as likely to have created new jobs, and were more than 3x as likely to have seen more sales inquiries in the last year. Source: Deloitte (research summarized by Google) (2017) →
  3. SMS reminders that stated the specific cost of the appointment to the health system reduced missed appointments in Trial One, with the DNA (did-not-attend) rate falling from 11.1% (control) to 8.4% (specific-costs message) - an odds ratio of 0.74 (95% CI 0.61-0.89), i.e. roughly a 24-26% relative reduction - at no additional cost. (Trial Two replicated this at an 8.2% DNA rate.). Source: PLOS ONE (Hallsworth et al.) (2015) →
  4. Retailers connecting point-of-sale and loyalty data in an omnichannel strategy reported up to 15% lower cost per purchase and nearly 20% higher incremental store revenue. Source: Deloitte (2024) →
FAQ

Frequently asked questions

Why do we still owe the wholesale bill after a revenue share attack?

Because the calls genuinely traversed the network and your upstream carrier genuinely paid termination on them. Unlike a card chargeback there is nothing to reverse, and the premium revenue has already been split among parties in jurisdictions where you have no recourse. That is why the only effective control is reducing time to detection and containment rather than planning to dispute the charges after the weekend.

How fast can fraud actually be detected and blocked?

If you ingest call events from your switch or session border controller in near real time and maintain rolling counters, detection on a clear revenue share pattern lands within seconds to a couple of minutes, and graduated blocking can fire automatically from there. Systems reading post mediation record batches inherit that batch delay, which in an attack measured in hours is most of your exposure window gone before anyone looks.

Will automated blocking take down legitimate customers by mistake?

Not if the actions are graduated and scoped to one account. Capping concurrent channels to a single destination, barring one prefix range for one customer, or suspending international outbound while leaving domestic and emergency calling intact are all reversible and narrow. Running every new rule in shadow mode against live traffic before arming it is the other half of the answer, and it is cheap to build in from the start.

Do we need machine learning for this?

Not at the beginning, and starting there is usually a mistake. Without a labelled history of confirmed fraud and confirmed false positives a model has nothing to learn from, so it produces confident noise. Per customer behavioural baselines plus an editable rule engine catch the large loss patterns. Learned scoring becomes genuinely useful later as a precision layer that shrinks the review queue rather than as the detection itself.

How long does a fraud management build take?

Twelve to eighteen weeks for a first release with live ingestion, baselines, rules, graduated actions and a case queue. The largest schedule risk is not development. It is getting access to production traffic events and a safe path to write controls into your session border controllers, both of which run through your network team's change process rather than the project calendar. Start those conversations in week one.

Can it detect bypass and subscription fraud as well?

Yes, but they are different signatures and usually a second phase. Bypass shows as international traffic terminating as domestic mobile with characteristic patterns and often needs test call generation to confirm. Subscription fraud shows in account age, provisioning velocity and immediate international usage on new accounts. Both reuse the same ingestion and case infrastructure, which is why they are cheaper to add once the core exists than to scope up front.

Who owns the detection rules if an agency builds this?

You should, along with the repository, the cloud accounts and the right to hire another developer, written into the contract before kickoff. At Digital Heroes the client owns the repository and the detection rules from the first commit. The rule set matters most, because it accumulates your operation's knowledge of how you get attacked, and that is not something to leave inside a vendor's system you may need to leave.

What is the difference between fraud management and revenue assurance?

Fraud management is about preventing loss caused by deliberate abuse, and it is judged on time to containment, so it runs on live event streams. Revenue assurance is about reconciling systems that should agree and finding money quietly not billed or overpaid, and it runs on periodic batches. They share ingestion and case handling but have opposite latency requirements, which is why one platform doing both tends to be tuned for the wrong one.

Should a small hosted voice provider build anything at all?

Probably not. Barring international outbound by default with per customer opt in, a hard destination allow list and a low credit ceiling removes almost all catastrophic exposure and costs nothing but a policy decision. We would rather tell you that than sell a project. The picture changes once a material share of your customers genuinely need international calling, because then a blanket bar is no longer commercially acceptable.

How do we ingest call events without risking the call path?

Out of band, always. Detection must never sit inline with signalling, because a fraud feed that can break calling is a worse risk than the fraud it prevents. Any competent telecom engineer says that unprompted, and if a prospective developer proposes anything inline you should stop the conversation there. Events are tapped, buffered and processed alongside the network rather than within it.

How do we get years of data out of our old system and into the new one?

Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.

How many people should be working on my software project?

A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.

Is it cheaper to customize Salesforce than to build a custom CRM from scratch?

If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.

Should I ask for a fixed price or pay the agency hourly?

Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.

What does a $50,000 custom software budget actually buy?

One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.

Does it matter which tech stack the agency wants to use?

Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply