The largest customer-facing surface in any regulated sector
Self-serve account portals, billing systems, IoT and device management APIs — maintained across legacy and modern stacks simultaneously, exposed around the clock.

Continuous security validation for telecom operators
Bill C-8 gives regulators binding authority over carrier security. Telecom operators run some of the largest internet-facing customer surfaces on earth. Vana continuously tests the portals, billing systems, and APIs exposed to the internet 24/7 — so you're ready before compliance deadlines hit.
Book a meeting and get a full free pentest of one live application.
The problem
Self-serve account portals, billing systems, IoT and device management APIs — often maintained across legacy and modern stacks simultaneously. That surface is exposed around the clock, and it's precisely the layer regulators will expect designated operators to demonstrate active testing against once the CCSPA's designation orders take effect — on top of the Telecommunications Act security powers Ottawa already holds today.
Most operators' security testing budget and attention has historically gone to network and infrastructure security. The customer-facing web/API layer — often the easiest entry point for an attacker — gets tested far less frequently, if at all.
Self-serve account portals, billing systems, IoT and device management APIs — maintained across legacy and modern stacks simultaneously, exposed around the clock.
Traditional pentesting run 5–10+ weeks per engagement at $15K–$50K. A 2-week development sprint can introduce changes faster than a traditional point-in-time engagement can be scheduled and completed.
Most operators' testing spend has historically gone to network and infrastructure security. The customer-facing layer — often the easiest entry point — gets tested far less frequently, if at all.
Telecommunications Act security directions are already in force. Once designation orders name your operator class under the CCSPA, you have 90 days to stand up a documented cybersecurity program.
Multi-market operations mean overlapping residency, subcontractor and concentration-risk expectations across every jurisdiction you serve.
Network and infrastructure security consumes your senior capacity. Repetitive re-testing of authenticated customer flows is the first thing that slips.
Meet Vana
Vana is built and trained in-house, not wrapped around an existing scanner. She is performing a full pentest, not just a vulnerability scanner.
Built and trained in-house — not wrapped around an existing scanner. Vana reasons about your application: enumerates, chains findings, escalates privileges and proves impact the way a real intruder would.
Highest of any pentester, human or AI. Every finding ships with evidence, so triage isn't a second job for your team.
SSO/SAML/OIDC, MFA and step-up flows, subscriber entitlements, multi-tenant boundaries, REST and GraphQL business logic across self-serve and partner APIs.
InfiltrateIQ is Canadian-headquartered, in a market where 82% of Canadian buyers weigh vendor country of origin and 56% are actively reconsidering US-based providers. Canada's Cyber Centre joined international partners in publishing guidance for the secure development and adoption of agency AI systems.
Vana absorbs the continuous, repetitive testing layer on your customer-facing surface; your internal security and network teams stay focused on infrastructure, core network security and strategic work.
Vana targets the customer-facing web apps and APIs that conventional scanners miss.
Scope note. Vana tests your internet-facing web applications and APIs. It does not test core network infrastructure, switching, or telecom-specific OT systems.
Regulatory fit
Reporting is OWASP-aligned and can be mapped to relevant control frameworks, with optional review by a qualified human pentester where additional assurance is needed.
Pricing
Vana Continuous, with volume-based pricing across your portfolio of customer-facing apps and APIs, fits an operator's scale and always-on exposure better than a point-in-time engagement.
Add Human-in-the-Loop Review for findings that need certified human sign-off ahead of a board update, regulator conversation or insurer requirement.
START FREE
Book a demo with one of our engineers. We run Vana against one live web application and hand back the full report, findings and evidence. You can validate findings before pursuing further pentesting.
Book a 20-min DemoCONTINUOUS COVERAGE
Continuous testing, 24x7x365, for one customer-facing web application. Fixed monthly pricing per app, with volume-based pricing as you add more apps. Optional Human-in-the-Loop review for board and regulatory sign-off.
OPTIONAL ADD-ON
Certified human pentester review of findings, evidence packaging, and sign-off for board updates, regulator conversations, or insurer requirements.
Common questions
This operates at a different layer — web applications and APIs, not core network or OT — and is built to complement existing infrastructure security investment, not replace it.
Understood. Canadian HQ and existing compliance mappings (SOC 2, ISO 27001, PCI DSS) are built to ease that review, and we're glad to start with a scoped, single-app engagement rather than a full commitment.
Fair, but the clock works against a wait-and-see approach: once your operator class is named in a designation order, you have 90 days to stand up a documented cybersecurity program. Testing your customer-facing surface now means that clock doesn't start from zero — and the underlying exposure (live, internet-facing portals and APIs) is current regardless of the regulatory timeline.
Vana handles SSO and step-up authentication, entitlement-based access boundaries, multi-tenant separation and REST/GraphQL business logic — the surfaces that defeat conventional automation — at 95%+ accuracy with evidence attached to every finding.
Scope, rate limits and change windows are agreed up front, and testing can run against pre-prod or staging environments where production windows are constrained.
Book a 20-minute demo and get a free pentest of one live application — the full report, real findings, remediation support; with no obligation.