Prototype
WebCDR Private CDR Processing
CPNI protection for telecom usage records.
The working WebCDRMask prototype masks selected fields before records enter onward processing, helping reduce unnecessary exposure of customer-identifying telecom usage data.
Protect identifiers while preserving authorized processing
The intended pattern separates the party that holds identifying information from a downstream processor that may not need it in clear form. A carrier-defined field policy determines what is masked, passed through, or retained for an authorized purpose.
Why reducing readable CPNI matters
Recent FCC settlements show that customer-information incidents can bring eight-figure civil penalties, extensive corrective obligations, or both. Outcomes depend on the facts of each case, but the enforcement record makes data minimization, retention, and downstream exposure practical business concerns.
Vendor-held CPNI
AT&T agreed to a $13 million civil penalty in 2024 after a breach in a vendor cloud environment affected CPNI relating to nearly 9 million wireless customers. The FCC settlement emphasized vendor oversight, data inventories, and retention and disposal controls.
Penalty plus remediation
T-Mobile agreed to a $15.75 million civil penalty and a separate $15.75 million cybersecurity investment after multiple breaches. The required program included data minimization, inventory and disposal measures alongside broader security controls.
Repeated API exposure
TracFone agreed to a $16 million civil penalty following investigations into three API-related breaches. Protecting selected CDR fields does not replace API security, but it can reduce the readable sensitive data present when another control fails.
The WebCDRMask value proposition is deliberately bounded. Protecting selected sensitive fields before onward processing can reduce readable CPNI in copied, retained, or vendor-processed records. It cannot prevent every breach or replace access controls, secure interfaces, key management, vendor governance, retention policies, monitoring, or incident response.
Prototype processing flow
1. Define fields
Identify the record fields required, maskable, or unnecessary for a particular workflow.
2. Mask locally
WebCDRMask transforms selected values before onward record processing.
3. Process records
Authorized mediation, rating, billing, assurance, or reporting operates on the resulting dataset.
4. Control recovery
Where recovery is required, access and key responsibilities remain explicitly controlled.
What has been demonstrated
- A Rust implementation delivered as a single binary.
- Carrier-defined field selection and masking behavior.
- Reversible protection using authenticated encryption where the approved design requires recovery.
- A prototype test suite covering the demonstrated processing behavior.
Important boundary
WebCDRMask is a masking and encryption prototype and is not yet integrated with production WebCDR. It does not perform A2P analysis and does not generate reports of offending P2P originating addresses. Those functions belong to WebCDR A2P Revenue Protection.
Private CDR Processing is not represented as a complete CPNI-compliance program. Compliance depends on the carrier’s full legal, technical, organizational, access-control, retention, and operating context.
Evaluate a bounded private-processing use case
Begin with a non-sensitive description of record format, fields, processing purpose, trust boundary, and recovery requirements.