Voice Fraud & Compliance Wiki

    Call Authentication

    STI-PASecure Telephone Identity Policy Administrator

    The central authority that decides which providers are eligible to obtain STIR/SHAKEN signing certificates and issues the tokens needed to request them.

    In the United States the STI-PA role is performed by iconectiv. It validates that a provider holds an OCN, is registered with the FCC, and is listed in the Robocall Mitigation Database before granting a Service Provider Code token.

    That token is what a provider presents to an approved STI-CA to obtain the certificate used for signing. The STI-PA also publishes the trusted certificate list that verification services check against.

    Why it matters to carriers

    Losing eligibility — for example through removal from the Robocall Mitigation Database — cuts off certificate renewal, and once your certificate expires your traffic goes out unsigned.

    Handling sti-pa on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.