Live team-state everywhere, conference calling on Cisco desk phones, a full transfer toolkit in the web softphone, install-as-an-app for the web client, smarter call history, proactive warning banners, and a large batch of reliability fixes from the first partner field testing.
New
- Conference calling on Cisco desk phones. Cisco 8800-series enterprise phones don't merge
three-way calls on the phone — they ask their call manager to do it. Exovo now answers that
request: press Conference, dial the second party, press Conference again, and the
system joins all three of you. Works for phones on a site connector and on the built-in VPN
alike, with nothing to change on the phones.
- A full transfer toolkit in the web softphone. The transfer panel now offers three ways to
hand a caller off: Blind (straight over), Attended ("ask first" — the caller waits on
hold while you announce them, then one click completes the handover, or hang up to take them
back), and Voicemail (drop the caller into a colleague's mailbox to leave a message). The
target field searches your extensions and contacts as you type.
- Install the web client like an app. Exovo can now be installed straight from the browser —
look for the install icon in the address bar — and opens in its own window with its own icon,
on desktop and mobile. No download, nothing to keep updated: it's the web client, one click
closer.
- Live call state, everywhere. The system now streams call-state changes the moment they
happen: the Exovo app's programmable keys light up per-key as extensions ring, talk, or hold;
Team dots follow along; and the Trunks page's Online column updates by itself the moment a
trunk registers or drops — including right after "Refresh registration".
- Per-trunk codec priority. Each trunk can now carry its own codec order — pre-filled from
the provider's template (voip.ms, for example, wants G.711/G.729) and editable on the trunk
page. Calls out that trunk offer exactly those codecs, in that order, which fixes providers
that refuse calls led by a codec they don't carry.
- The console speaks up when something needs you. Administrators now see a clear banner —
not a buried log line — when a saved setting needs a phone-system restart (with a link to
Services, self-clearing once the restart happens), when the phone system stops responding,
when scheduled backups are being skipped because no backup passphrase is set, and when SIP
scanning from the internet is detected — the sign of a port-forward rule left over from a
previous phone system that should be removed. The setup guide now calls that trap out
prominently too.
- Dial-by-name directory. The IVR's "Name Directory" option now works: callers spell the
first letters of a name on the keypad and are connected to the matching extension.
- End a call from the Panel. Administrators get an End action on any live call in the
operator panel — audited, admin-only.
- The Exovo app for Windows keeps itself up to date. The desktop app now installs from
the website as a signed package that checks for updates automatically. This release's app
also ships a 40% smaller install, automatic tunnel reconnection after a network drop, and a
Directory tab with the full phonebook — Personal, Group, Company, and CRM-synced contacts
alongside your extensions.
Improved
- Call history knows who that was. Recents in the apps now name what the phone network
didn't: calls to the voicemail or conference service, ring groups, queues, and IVRs show
their names, and external numbers match your phonebook in any format — +1 513 742 3100 and
513-742-3100 land on the same contact. Applies to existing history too.
- Cisco 8800 provisioning refined from field testing. The 8845/8865 video models get their
own template with the correct firmware family (the shared template could offer them the wrong
load), the in-call recording indication beep is gone, and dialing completes a second faster.
- MP3 uploads now play. Hold music, IVR greetings, and announcements uploaded as MP3 play
correctly — previously they were accepted but played silence (WAV remains the recommended
format). Already-uploaded MP3s start working on update, no re-upload needed.
- IVR "connect to external number" now routes through your outbound rules — the right
trunk, caller ID, and dialing permissions — instead of failing with dead air.
- The web softphone shows the codec each call actually negotiated instead of a fixed label,
and its Conference button now works (call, New Call, second party, Conference — all
three joined).
- Setup guide additions: a "set the time zone first" step, and every copy-pasteable number
range in the docs now pastes cleanly into firewall configs.
Fixed
- Emergency calls could fail during a rare internal race. A concurrency bug in the call
routing path could leave a 911 call unroutable and has been eliminated; emergency-call
notifications now run fully isolated from call setup. Related: filtering the Event Log no
longer errors.
- Answering the web softphone from a desk phone produced silent calls. The system offered
the browser an unreachable media address in one direction; both directions now connect
reliably.
- Ghost calls clean themselves up. A call that ended uncleanly (for example a transfer that
went wrong mid-flight) could linger forever as a phantom "active call", light up busy lamps,
and hold presence — the system now reconciles against the switch every minute and clears
such remnants automatically.
- The Exovo app's microphone audio now reaches every destination: calls bridged to outside
numbers were silent toward the far party (the audio was sent in oversized packets carriers
discard); the app now paces standard 20 ms media. Echo tests were unaffected, which is why
this hid.
The Exovo app for Windows — a full desktop softphone over the encrypted tunnel, with chat and SMS shared live with the web client — plus route context on ringing calls, on-demand recording, and self-service app enrollment.
New
- The Exovo app for Windows. A compact desktop softphone that connects to your system over
the same encrypted tunnel the connectors use — one outbound connection, no VPN, no port
forwarding, working from anywhere. Calls ring on your PC with your headset: dialer with live
name-and-number suggestions, hold with music, blind and attended transfer ("ask first",
then hand the caller over), in-call keypad, mute, and a programmable-key strip that mirrors
your desk phone's keys — tap a key to dial, or to transfer the caller mid-call. Team presence,
company directory, call history, and voicemail (with transcriptions, playback, and a Saved
folder that follows you between devices) are all live views of your system. Light and dark
theme, keyboard dialing, and a fixed-width companion layout designed to sit beside your work.
- Chat, everywhere you're signed in. The app carries your Exovo chat — direct messages,
groups, and channels — live in both directions with the web client: send from either side and
it appears on the other instantly, read state and unread counts included. SMS conversations
from your text-enabled trunks appear in the same list, with delivery status on every message
and the same claim-on-reply teamwork rules as the web client.
- Sign in, and the app sets itself up. Enter your system's address and the app shows that
system's own sign-in options — the same ones your web client login offers, including your
identity provider. Signing in enrolls the device automatically: certificate, phone
registration, and data access in one step, shown as a short setup checklist. Prefer not to
type a password into a device? Any signed-in web client can mint a one-time pairing code
(or QR, for the mobile apps to come) from the "Provision apps" button — it works once and
expires. Every enrolled device is listed under Connectivity → Mobile, and revoking one
cuts off its calls and its data access together.
- Know which line is ringing. Calls that reach you through a ring group or queue now show
their route — via Ring All 802 — while ringing and in your call history, so reception knows
how to answer before picking up. Ringing calls also gain a third choice beside answer and
decline: send to voicemail.
- Set your status from the app. The presence menu sets your profile (Available, Away, Do Not
Disturb, and your custom profiles) plus a free-text status note — visible to your team in the
app and honored by your forwarding rules, same as changing it in the web client.
- Record a call while it's happening. A Record control in the app starts and stops recording
on the live call; recordings land in the system's recording store, and users whose extension
allows it can play back and manage their own recordings right in the app.
- Desk phone control. Point the app's dialer at your desk phone instead: dialing from the
app (or a programmable key, or call history) rings your desk phone and places the call there —
the classic CTI workflow, with the app as the directory and the phone as the handset.
- Made for the front desk. System-wide keyboard shortcuts (answer, hang up, mute, transfer,
and more — recordable on the Hotkeys page and working even when the app isn't focused), call
controls from HID headsets (answer, hang up, and mute from the headset's own buttons, with
the headset's lights kept in sync), echo cancellation, and a CRM screen pop that opens
your CRM to the caller's record on ring or on answer using a URL template.
- Lives in your tray. The app minimizes to the system tray, can start when you sign in to
Windows (minimized if you like), and can bring itself to the front when a call rings.
- Meetings at hand. The app lists your scheduled meetings and standing rooms, starts your
meeting room in one click, and joins by code — video meetings open in the browser as before.
- Trial licensing. New systems can start on a 30-day trial of a real capacity band and
convert to a paid license in one step, keeping everything in place.
Improved
- One look across every surface. The app and the web client now share the same design
language end to end — including a full dark theme in the app — and primary buttons across the
product use a deeper accent shade that meets WCAG AA contrast with white text.
- Voicemail message actions. The app's voicemail rows expand in place with the full
transcription, mark themselves heard as you read, and support save and delete.
Fixed
- Your other devices' messages now appear live in the web client. Previously, a message you
sent from one device (for example the new app) reached the other side instantly but didn't
appear in your own open web client until a refresh.
- Exports and downloads through the phone connector. Downloading files from a phone's web
interface proxied through an on-site connector (for example a Yealink diagnostics export) now
saves correctly instead of failing silently.
Cisco 8800 Series phones on Enterprise firmware — on-site, behind a connector, or over their built-in VPN — plus inter-PBX bridges, a real event log, and a round of fixes from the first on-site deployment.
New
- Cisco 8800 Series on Enterprise firmware. Cisco's 8800 desk phones (8841, 8845, 8851, 8861,
8865) running the standard Enterprise (CUCM) SIP load can now be provisioned by Exovo — no
reflash to Multiplatform firmware required. Turn on the opt-in TFTP server under
Connectivity → TFTP, and the phones pick up their configuration exactly the way they would
from a CUCM: per-phone config, dial plan, soft keys, an XML directory on the Directories key
(extensions and company contacts), and locale packs. Phones at a remote site work through an
on-site Exovo connector, which serves their provisioning locally. A Multiplatform-firmware
template for the same models is included too.
- Cisco phone VPN. Remote Cisco Enterprise phones can now connect straight to Exovo over the
phone's built-in AnyConnect VPN — no connector or site-to-site tunnel needed. Exovo runs the VPN
service itself, and the phone authenticates with its factory-installed Cisco certificate, so there
is nothing to type on the phone: plug it in at home, and it registers. Enable it under
Connectivity → VPN; the phone's configuration is updated automatically. The VPN is built to stay
up unattended: it uses SIP over TCP so a dropped connection is detected and re-established within
seconds, provides its own in-tunnel DNS, and is multi-tenant aware — each tenant gets its own VPN
address space and gateway. A watchdog that can restart a phone remotely remains as a backstop.
- Bridges between phone systems. The Trunks page gains Add Bridge: join two Exovo systems —
or an Exovo system and a 3CX — so extensions on either side can call each other directly by
number. Between Exovo systems the bridge rides the same encrypted tunnel the connectors and mobile
apps use (one outbound port on the remote side, no SIP or media exposed to the internet); a direct
SIP bridge is available for 3CX. The Trunks list shows each bridge's live status, and creating one
hands you a one-time credential card for the other end.
- A real event log. The system Event Log is rebuilt around a catalogue of named events with
severity, a source, and structured details you can expand in place. Filter by source or event
type, page through history, set how long events are kept, and — under Alerts — have Exovo
email you when selected events occur or when anything at or above a chosen severity is logged.
Resource monitoring (CPU, memory, disk, recording quota) now raises events too, with hysteresis so
a value hovering at its limit doesn't flood you.
Improved
- Trunks and Devices. DECT base stations and analog (FXS) adapters move from the Trunks page to
their own Devices page, so Trunks now lists only carriers, gateways and bridges. Bridge
counts on the Trunks page are now accurate, and a phone's web password can be copied from its
row. The VPN page is organised into tabs.
- Provisioning on sites without internal DNS. Phones provisioned over the local network are now
given a provisioning address they can actually reach — the system's LAN IP, served over plain
HTTP — instead of the public host name. Previously a phone on a network that couldn't resolve the
system's public address would fetch its configuration once and then loop forever trying to
re-provision.
- IP Phone settings. The Network Interface selector on a user's IP Phone tab now lists the
system's configured LAN address (it previously listed internal container addresses), and the
choice is remembered per phone.
- Analog adapters over cellular internet. Grandstream HT80x adapters on an OpenVPN connection
that rides a cellular or other reduced-MTU WAN now register, place calls and serve their web UI
reliably; the adapters' codec settings are also rendered correctly (previously a mismatch could
silently leave the factory codec in place).
- The Event Log no longer logs every periodic trunk or bridge re-registration — only genuine
up/down transitions.
- Supporting services (the connector terminator and the phone web-UI proxy) now survive a restart
of the telephony core without needing to be restarted themselves.
Fixed
- Saving a user with an assigned phone silently reverted your changes. Editing the name or any
other field of a user who had a desk phone assigned reported success, but the phone save that
followed overwrote the user record with its previous values. Users without phones were unaffected,
which made it look specific to phones imported from 3CX.
- Users imported from 3CX (or created through the API without a group) had no group membership at
all; the editor showed "Default" selected but nothing was saved until you re-selected it.
Every user now belongs to the default group unless another is chosen, and existing users are
corrected the next time they are saved.
- A legacy caller ID or mobile number in a non-E.164 format — common after a 3CX import — blocked
every save on that user, even when you hadn't touched the number. Validation now applies only to
numbers you change.
- Transferring an inbound call to an external number via a BLF key was rejected as a toll-fraud
attempt when the carrier sends from an address other than its registrar. Calls transferred by an
authenticated extension are now recognised as such.
- The local (HTTP) provisioning address was redirected to HTTPS, which a phone provisioning by IP
address cannot complete. Provisioning now stays on plain HTTP while everything else still redirects.
- The phone web-UI proxy's auto-login could submit the phone's login form twice.
Free Exovo addresses — set up a new system as yourcompany.exovo.us with DNS and HTTPS handled for you — plus phone-home and remote-storage fixes.
New
- Free Exovo addresses. Setting up a new system no longer requires bringing your own domain:
the setup wizard now offers "Get a free Exovo address" — pick a name, and your system becomes
yourcompany.exovo.us (or .exovo.net). The DNS record is created for you, the HTTPS
certificate still issues automatically, and the address follows your public IP — if your
internet connection's address changes, the record is corrected within about a minute, with no
dynamic-DNS service or router configuration on your side. Your traffic still flows directly to
your system — only the DNS record is managed centrally, nothing is proxied. Partners can also
reserve an address for a license key ahead of an install, straight from the Portal.
Fixed
- A system could show as offline in the Portal — "last seen" frozen for hours — while running
perfectly. One slow Portal response could silently stop the system's periodic check-in until the
next restart. Check-ins now shrug off a slow or failed contact and simply retry.
- With remote storage enabled but no path saved, the archive cycle failed every minute with a
cryptic low-level error. An empty target is now treated as "not configured," and the storage
page refuses to save an enabled configuration without one.
Faster, smarter voicemail transcription and a hardened FreeSWITCH core — plus the security fixes from FreeSWITCH 1.11.2.
New
- Faster transcription with the Large v3 Turbo model. The transcription model picker adds
Large v3 Turbo — close to Large v3's accuracy at several times the speed, with under half the
download and RAM. A good default when you want high-quality transcripts without a large machine.
- Skip silence. Transcription now detects speech before it runs: a voicemail or recording with
no speech is left with an empty transcript instead of being run through the model, and audio
padded with silence (most voicemail) is trimmed to just its speech first — so transcripts come
back sooner and use less CPU. On by default; find it under Admin → Integrations →
Transcription. The small speech-detection model it needs downloads itself the first time.
Improved
- A hardened telephony core. Exovo now runs FreeSWITCH 1.11.2, which brings extensive upstream
security hardening across the media and SIP paths. On top of that, Exovo locks the engine down to
exactly the capabilities it uses — shell execution, scripting and other unused internals are
switched off entirely, so a would-be attacker has far less to reach for even in the event of a
breach elsewhere. No configuration changes are required.
Fixed
- Remote analog adapters and desk phones behind an on-site connector could, after a brief network
hiccup at the connector, be handed an unusable address for their outbound proxy and stop
registering until reconfigured. The connector now only ever advertises a real, reachable address,
and Exovo refuses anything else — so a momentary blip can no longer knock those phones offline.
Grandstream HT801 V2 and HT802 V2 support with fully automatic OpenVPN — a remote analog adapter is now plug-in-anywhere — plus a device web console and registration status for adapters and gateways.
New
- Grandstream HT801 V2 / HT802 V2 support, with zero-touch VPN. Exovo now provisions
Grandstream's current analog telephone adapters — and on these models, the built-in VPN needs
no hands at all: choose OpenVPN as the connection when adding the device, and it receives
its certificates inside its configuration file, brings up the tunnel, and registers through it.
A fax machine, elevator phone or door intercom at a remote site becomes a
plug-in-anywhere-with-internet device — no router changes, no certificate uploads, nothing
exposed. See analog devices over VPN.
- Device web console for adapters and gateways. The same proxied web-UI access desk phones
have is now on every DECT/FXS device and VoIP gateway: ⋮ → Open Device GUI opens the
device's own interface in a new tab, wherever the device is — including a VPN adapter at a
remote site, reached over its tunnel. Adapters sign you in automatically with their
provisioning-time password; gateways open at their login page.
- Copy Provisioning URL. One click on a device or gateway row puts the provisioning address
on your clipboard, ready to paste into the device's config-server field.
Improved
- The Trunks page tells you what's registered. Trunks & gateways and DECT/FXS devices each
have their own labelled section with a live registration count, DECT/FXS rows show per-port
status ("2 / 2 registered" — a base with one dead handset no longer looks healthy), and a new
DECT/FXS stat card sits alongside the gateway card.
- Grandstream devices no longer talk to Grandstream's cloud. The HT80x V2 family ships from
the factory with TR-069 enabled and pointed at Grandstream's own management service, where an
unclaimed device sits waiting to be adopted. Exovo's configuration now switches that off — your
devices are managed by your system and nothing else.
- Provisioned devices ignore DHCP redirects. All Grandstream adapter and FXS-gateway
templates now disable DHCP option 66 override once the device is configured, so a site router
handing out its own provisioning address can't quietly redirect a working device. A factory-
fresh device can still bootstrap from option 66 — it just stops listening once it's yours.
Fixed
- Automatic re-provisioning of DECT/FXS devices and gateways works reliably now. The
configuration Exovo served was overwriting the device's own config-server address with an
empty value, so the first fetch succeeded and every later one silently never happened —
changes made in the console only reached the device after a manual reconfigure. Devices now
keep their provisioning address and pick up changes on their normal schedule.
Full 3CX and Yeastar backups can now be imported from the server instead of the browser, however large they are, and imported call recordings archive on schedule again.
New
- Import a backup straight from the server. A backup of a busy phone system with years of call
recordings runs to tens of gigabytes, which is more than a browser upload can carry reliably. Copy
the file to
/var/lib/exovo/import-drop on the Exovo host and the restore wizard lists it with its
size and date — pick it and the import starts immediately. Nothing is copied and nothing is
uploaded, so the size of the backup stops mattering. Exovo reads the file where it sits and leaves
it alone afterwards, so it is yours to keep or delete. Browser upload is still there and still the
easier route for anything up to a few gigabytes. See
migrating from 3CX and
from Yeastar.
Improved
- Large backups are no longer rejected. The wizard previously refused any upload over 2 GB, which
ruled out most real 3CX backups. That limit is gone — free disk space is now the only constraint.
Plan on having roughly twice the size of the backup file free while the import runs: the archive and
the recordings unpacked from it briefly exist side by side. The space is released when the import
finishes.
- Reading a backup is now isolated from the phone system. Backups are opened by a separate,
purpose-built program rather than inside the web application. A corrupt, truncated or malicious
backup file can no longer disturb the running system — the worst it can do is fail its own import
and report why.
Fixed
- Imported call recordings now archive on schedule. Remote archiving decides what to move by a
recording's age, but it was using the date the record was added to Exovo rather than the date of the
call. Imported recordings therefore looked brand new no matter how old the calls were, so they stayed
on local disk for the full retention window — and then all became eligible at once. Age is now taken
from the call itself, which is what the retention setting has always meant.
- Imports no longer leave their working files behind. Extracted call data was kept after each import
and could accumulate to several gigabytes on a large system.
- An interrupted import no longer discards the work in progress. Closing the browser or losing
connection part-way through left the import running but cleared the files it was still reading.
- Backup and recording sizes over a gigabyte are now shown in GB rather than as four- and five-digit
megabyte figures.
Upgrading
- This release adds a mount for the new import directory, so apply it with
docker compose up -d
rather than only pulling the new images.
- If you have previously imported call history, those recordings become eligible for remote
archiving immediately, so the next archive cycle will move a large batch to your remote store in one
pass instead of doing nothing. This is the intended behaviour and the recordings remain available
from the remote store, but it is worth expecting rather than discovering.
Partner management arrives on the dashboard and in the portal, licensed extension limits are now enforced, and the SBC appliance gets dramatically lighter.
New
- Your partner, on your dashboard. The LICENSE INFORMATION card now shows the partner looking
after your system, and an admin can set, change or clear the six-digit partner ID from the
dashboard at any time. Linking is always your choice — the system stays yours, and you can unlink
just as easily.
- A portal for partners. Partners signing in at portal.exovo.tel get a fleet view of every
system assigned to them — status, version, extensions and licence health, worst first — along
with the licence keys issued to them and a direct support channel back to Exovo. Each partner
keeps a company profile that feeds the public partner directory.
- Support runs through your partner. Exovo is sold and supported through partners, so the
customer portal now names the partner who looks after your system — phone, email and website —
rather than offering a ticket form. They are the fastest route to a fix, and they escalate to us
when they need to.
Improved
- The licensed extension limit is now enforced. Your licence band — for example "50
extensions" — was shown but never applied. Creating an extension beyond the band is now blocked
with a clear message and an upgrade path, and the users page shows how many of your licensed
extensions are in use. Nothing is ever removed: a system already above its band keeps every
extension it has, and only new ones are refused. See
licensing.
- Licence type reads as a band. The dashboard and the portal now say "50 extensions" instead of
a plan name, matching the published pricing.
- A much lighter SBC appliance. The on-site SBC and the tunnel terminator now ship as native
binaries. The images are 44% smaller — 340 MB down to 191 MB — and the SBC settles at around 7 MB
of memory instead of 63 MB. Worth having if you run the appliance on modest hardware.
Fixed
- Portal sign-in links no longer fail on the first click. Mail-scanning systems that pre-fetch links
were spending the single-use token before it reached you; signing in now takes one explicit
confirmation step, so the link still works when you get there.
- The extension count on the dashboard no longer includes the machine operator, so it agrees with
the total shown on the users page.
Release channels arrive — follow stable or latest per system — plus clearer service naming and operator-console fixes.
New
- Release channels. Every system now follows a channel: stable (tested releases,
moved only when a release like this one is promoted), latest (every published build),
or an exact version pin. Set with
EXOVO_CHANNEL in the stack's .env — new installations
default to stable, and the Updates page shows which channel the system follows. See
release channels.
- This page. Release notes are now published for every stable release, with the current
stable version always shown at the top.
Improved
- The telephony core is now named for what it is: Exovo Core (with its FreeSWITCH
engine noted in the description) on the Services and Updates pages, and System Core
on the dashboard health card.
Fixed
- The operator console no longer shows a stray horizontal scrollbar, and the operator
banner no longer leaves a matching band of empty space at the bottom of the page.
The launch baseline — the first release promoted to the stable channel, recording the product as stable begins.
This is Exovo's first stable release — the baseline every entry after this one builds on.
From here forward, each release on this page is a tested image set promoted to the stable
channel, with notes on what changed. This first entry instead records what the product already
is as stable begins.
In the box
- Calling — extensions, ring groups, call queues with callbacks, digital receptionists
(IVR), parking and pickup, BLF, Find Me / Follow Me, and per-call outbound caller-ID
selection from the softphone.
- Video meetings — meet now or scheduled, with browser guest links, screen share,
recording, virtual backgrounds and phone dial-in.
- Messaging — team chat, business SMS/MMS on your own trunk numbers, and a
live-chat widget that routes website visitors into the same
team inbox.
- Microsoft 365 — Entra ID user sync, "Sign in with Microsoft", and contact sync from
personal and shared mailboxes, all sharing one connection.
- Integrations — 17 CRM templates with caller-ID lookup and journaling, fax, a REST API,
and BI reporting views in your own PostgreSQL.
- Devices & remote work — zero-touch provisioning for desk phones, DECT bases and
gateways, on the LAN or through the Exovo SBC; a backup SIP
server can be provisioned to phones for failover.
- Migrations — import users, trunks, routing and settings straight from a
3CX or
Yeastar P-Series backup.
- Operations & security — encrypted backups, one-click updates, call recording with
on-box transcription, a hypervisor-HA reference architecture,
TLS/SRTP, SIP scanner auto-banning, toll-fraud protection, 2FA and SSO.
- Multi-tenant hosting — isolated tenants on one machine with a cross-tenant operator
console and per-tenant restore.
The full picture is on the features page; what's coming next is on the
roadmap. This release also introduces release channels themselves: systems
follow stable, latest, or an exact version pin,
and new installations default to stable.