Global telecommunications network of towers, fiber routes and data centres

Continuous security validation for telecom operators

The Telecommunications Act just got a cybersecurity mandate. Get ahead of it.

Bill C-8 gives regulators binding authority over carrier security. Telecom operators run some of the largest internet-facing customer surfaces on earth. Vana continuously tests the portals, billing systems, and APIs exposed to the internet 24/7 — so you're ready before compliance deadlines hit.

Book a meeting and get a full free pentest of one live application.

95%+ accuracyCanadian data residency availableHuman-in-the-Loop review availableOWASP-aligned reporting

The problem

The layer regulators will ask about is the layer that gets tested least.

Self-serve account portals, billing systems, IoT and device management APIs — often maintained across legacy and modern stacks simultaneously. That surface is exposed around the clock, and it's precisely the layer regulators will expect designated operators to demonstrate active testing against once the CCSPA's designation orders take effect — on top of the Telecommunications Act security powers Ottawa already holds today.

Most operators' security testing budget and attention has historically gone to network and infrastructure security. The customer-facing web/API layer — often the easiest entry point for an attacker — gets tested far less frequently, if at all.

The largest customer-facing surface in any regulated sector

Self-serve account portals, billing systems, IoT and device management APIs — maintained across legacy and modern stacks simultaneously, exposed around the clock.

Point-in-time testing on an always-on edge

Traditional pentesting run 5–10+ weeks per engagement at $15K–$50K. A 2-week development sprint can introduce changes faster than a traditional point-in-time engagement can be scheduled and completed.

Budget concentrated on network, not the web/API layer

Most operators' testing spend has historically gone to network and infrastructure security. The customer-facing layer — often the easiest entry point — gets tested far less frequently, if at all.

A regulatory clock you don't control

Telecommunications Act security directions are already in force. Once designation orders name your operator class under the CCSPA, you have 90 days to stand up a documented cybersecurity program.

Global estates, local expectations

Multi-market operations mean overlapping residency, subcontractor and concentration-risk expectations across every jurisdiction you serve.

Internal teams already stretched

Network and infrastructure security consumes your senior capacity. Repetitive re-testing of authenticated customer flows is the first thing that slips.

Meet Vana

The only fully AI-autonomous pentester on the market — running continuously.

Vana is built and trained in-house, not wrapped around an existing scanner. She is performing a full pentest, not just a vulnerability scanner.

Autonomous, not a scanner

Built and trained in-house — not wrapped around an existing scanner. Vana reasons about your application: enumerates, chains findings, escalates privileges and proves impact the way a real intruder would.

95%+ accuracy, validated impact

Highest of any pentester, human or AI. Every finding ships with evidence, so triage isn't a second job for your team.

Deep authenticated coverage

SSO/SAML/OIDC, MFA and step-up flows, subscriber entitlements, multi-tenant boundaries, REST and GraphQL business logic across self-serve and partner APIs.

Sovereignty matters here

InfiltrateIQ is Canadian-headquartered, in a market where 82% of Canadian buyers weigh vendor country of origin and 56% are actively reconsidering US-based providers. Canada's Cyber Centre joined international partners in publishing guidance for the secure development and adoption of agency AI systems.

Augmentation, not replacement

Vana absorbs the continuous, repetitive testing layer on your customer-facing surface; your internal security and network teams stay focused on infrastructure, core network security and strategic work.

Built for the operator edge

Vana targets the customer-facing web apps and APIs that conventional scanners miss.

Self-serve subscriber and account portals
Billing, payments and top-up systems
Device and IoT management APIs
Partner, MVNO and reseller integrations
Enterprise customer dashboards
Legacy middleware and internal web portals
Acquired-entity estates and shadow applications
Pre-prod, staging and production change windows
Jira / ServiceNow workflow integration

Scope note. Vana tests your internet-facing web applications and APIs. It does not test core network infrastructure, switching, or telecom-specific OT systems.

Regulatory fit

One continuous evidence trail, ahead of the designation clock.

Reporting is OWASP-aligned and can be mapped to relevant control frameworks, with optional review by a qualified human pentester where additional assurance is needed.

Canada

  • Telecommunications Act amendments (Bill C-8, Royal Assent June 2026) — in force now, giving Ottawa authority to issue binding security directions to carriers
  • CCSPA — mandatory cybersecurity programs, incident reporting and supply-chain risk for designated telecom operators once designation orders are issued; 90 days to comply from designation

United States & global

  • FCC and CISA expectations for communications-sector providers, plus PCI DSS 4.0 (11.4) for subscriber payment flows
  • Carrier customer-data protection obligations across the markets you operate in

Europe & UK

  • NIS2 risk-management and incident-reporting duties for electronic communications providers
  • UK Telecommunications (Security) Act code of practice, GDPR safeguards and lawful international data-transfer mechanisms

Pricing

Start with one application. Scale to continuous across the portfolio.

Vana Continuous, with volume-based pricing across your portfolio of customer-facing apps and APIs, fits an operator's scale and always-on exposure better than a point-in-time engagement.

Add Human-in-the-Loop Review for findings that need certified human sign-off ahead of a board update, regulator conversation or insurer requirement.

START FREE

Free Pentest

$0

Book a demo with one of our engineers. We run Vana against one live web application and hand back the full report, findings and evidence. You can validate findings before pursuing further pentesting.

Book a 20-min Demo

CONTINUOUS COVERAGE

Vana Continuous

$2,000/ app / mo
VOLUME PRICING FOR ADDITIONAL APPS

Continuous testing, 24x7x365, for one customer-facing web application. Fixed monthly pricing per app, with volume-based pricing as you add more apps. Optional Human-in-the-Loop review for board and regulatory sign-off.

OPTIONAL ADD-ON

Human-in-the-Loop Review

Custom Add-On

Certified human pentester review of findings, evidence packaging, and sign-off for board updates, regulator conversations, or insurer requirements.

Common questions

Ask the hard ones.

We already have network and infrastructure security tooling.

This operates at a different layer — web applications and APIs, not core network or OT — and is built to complement existing infrastructure security investment, not replace it.

Vendor approval for critical infrastructure is a long process.

Understood. Canadian HQ and existing compliance mappings (SOC 2, ISO 27001, PCI DSS) are built to ease that review, and we're glad to start with a scoped, single-app engagement rather than a full commitment.

We'll deal with this once we're formally designated.

Fair, but the clock works against a wait-and-see approach: once your operator class is named in a designation order, you have 90 days to stand up a documented cybersecurity program. Testing your customer-facing surface now means that clock doesn't start from zero — and the underlying exposure (live, internet-facing portals and APIs) is current regardless of the regulatory timeline.

Can an AI actually test something this complex?

Vana handles SSO and step-up authentication, entitlement-based access boundaries, multi-tenant separation and REST/GraphQL business logic — the surfaces that defeat conventional automation — at 95%+ accuracy with evidence attached to every finding.

How does testing production stay safe?

Scope, rate limits and change windows are agreed up front, and testing can run against pre-prod or staging environments where production windows are constrained.

Continuous coverage for the surface that's exposed to the whole internet, every day.

Book a 20-minute demo and get a free pentest of one live application — the full report, real findings, remediation support; with no obligation.