Sharing a project I help maintain — Flowcat, an Apache-2.0 native-Rust runtime for real-time voice AI agents (phone + WebRTC). It runs the whole voice pipeline (STT → LLM → TTS, or a single speech-to-speech model) as one self-contained binary you host yourself — in your own VPC or fully air-gapped. No hosted control plane, bring your own keys, and a call’s audio never leaves your infra.

It’s a clean-room counterpart to pipecat’s architecture, but native Rust:

  • each pipeline stage is its own tokio task behind a bounded mpsc channel (natural backpressure)
  • the hot audio frame is an Arc<AudioFrame>, so each hop moves a pointer, not a PCM copy
  • no GIL, so one process uses all cores and holds a flat tail under load (measured: flat ~0.6ms p99 framework overhead from 10 to 2,000 concurrent calls on one box)
  • native SIP/RTP, so a single binary can terminate phone calls with no FreeSWITCH

The linked writeup has the full Rust design + a reproducible benchmark vs pipecat (with the honest caveat that it’s framework overhead, not end-to-end voice latency — that’s provider-bound).

Repo: https://github.com/AreevAI/flowcat

Apache-2.0, pre-1.0, built in the open. Disclosure: I help maintain it — happy to talk architecture or the SIP stack.

  • suriyan@programming.devOP
    link
    fedilink
    arrow-up
    1
    arrow-down
    4
    ·
    21 days ago

    That’s a fair concern and I won’t pretend it away. Robocall spam predates AI by decades — predictive dialers and prerecorded scams already made billions of calls a year — but AI absolutely makes it cheaper and more convincing, and I get calls like that too.

    Two honest observations from working in this space: the scam operations don’t need open-source projects — they already run on cheap hosted APIs and have for years. And the actual fix lives at the carrier layer, not the software layer: STIR/SHAKEN attestation, enforcement against the VoIP providers who knowingly sell to spammers, and liability for carriers that terminate that traffic. Software bans won’t stop them; making unverified caller ID worthless will.

    What a self-hosted runtime does change is who legitimate users have to trust — a clinic or a bank running voice agents on-prem instead of streaming call audio to a third party. That’s the use case I care about. But yeah, the spam problem is real, and it’s going to get worse before regulation catches up.

    • Hirom@beehaw.org
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      21 days ago

      Scammers may not use this specific project yet, but do use tools like This with LLM integration. They absolutely will use an OSS tool if it’s good enough and cheap enough.

      STIR/SHAKEN would help, but it would remain a game of cat and mouse. SPF/DKIM/… is widely deployed and enrorfced and yet spam email continue. There’s financial insentives to keep spamming one way or another.

      LLMs enable spam call at a much larger scale with few to no human involved. They won’t quit nor blow the whistle on their shitty boss. LLMs are the least useful, most harmful kind of AI. It should be abandonned and/or regulated to death.

      • hendrik@palaver.p3x.de
        link
        fedilink
        English
        arrow-up
        8
        ·
        21 days ago

        High chance you’re talking to an AI, by the way. Starts with an affirmation, has lots of em-dashes…

        • Hirom@beehaw.org
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          20 days ago

          For fuck’s sake. If that’s an undisclosed bot then it should be banned.