High-voltage transmission towers and a lit substation at night beneath a network of glowing grid connections

Continuous security validation for energy & utilities

Your Grid Is Protected. Is Your Front Door?Bill C-8 is now law.

Bill C-8 is now law with the Critical Cyber Systems Protection Act. Once the government issues designation orders - pipeline, power line, and nuclear operators will have 90 days to stand up a documented cybersecurity program once designated. Vana continuously tests the layer attackers actually hit — customer portals, billing systems, smart-meter platforms — the most common entry point in IT/OT convergence incident documented cybersecurity program.

Book a meeting and get a full free pentest of one live application.

  • 95%+ accuracy
  • Canadian data residency available
  • Human-in-the-Loop review available
  • OWASP-aligned reporting

The problem

The layer regulators will ask about is the layer that gets tested least.

Energy and utility operators invest heavily in OT security — and rightly so. But the web-facing layer around it — customer portals, billing platforms, smart-meter APIs — is often left under tested, despite sitting exposed on the open internet and being the more common entry point in IT/OT convergence incidents. Under the CCSPA (Bill C-8), designated pipeline, power line, and nuclear operators will soon need to prove they have an active cybersecurity program in place.

The web layer around the grid gets tested least

Customer account portals, billing platforms and smart-meter data APIs receive far less security testing attention than the industrial control systems they're built around.

IT is the documented entry point

Security research has repeatedly documented that IT-facing systems, not OT networks directly, are the initial entry point in the majority of reported IT/OT convergence incidents.

Budget concentrated on OT, for good reason

Most operators' security spend and internal expertise sits with control-system security. The customer-facing layer often goes untested by comparison.

A regulatory clock you don't control

The Critical Cyber Systems Protection Act, enacted under Bill C-8, will require designated energy operators to demonstrate active cybersecurity programs once designation orders are issued.

Point-in-time testing on an always-on surface

Traditional engagements run 5–10+ weeks at $15K–$50K. A two-week sprint can ship changes faster than a point-in-time engagement can be scheduled and completed.

Direct exposure to the open internet

The customer-facing layer is the one with the most direct exposure to the open internet — live, reachable and current regardless of the regulatory timeline.

WHY ENERGY & UTILITY OPERATORS CHOOSE VANA

The only fully AI-autonomous pentester on the market — running continuously.

Vana is built and trained in-house, not wrapped around an existing scanner.

Autonomous, not a scanner

Built and trained in-house — the only fully AI-autonomous pentester on the market. Vana reasons about your application: enumerates, chains findings, escalates privileges and proves impact the way a real intruder would.

95%+ accuracy, validated impact

More than any manual or typical AI pentester. Each finding ships with evidence, so triage isn't a second job.

Deep authenticated coverage

SSO/SAML/OIDC, MFA and step-up flows, customer entitlements, multi-tenant boundaries, and REST and GraphQL business logic across self-serve and partner APIs.

Sovereignty matters here

InfiltrateIQ is Canadian-headquartered, in a market where 82% of Canadian buyers weigh vendor country of origin and 56% are actively reconsidering US-based providers. Canada's Cyber Centre (CCCS) co-authored the Five Eyes agentic AI security guidance.

Complementary, not a replacement

Vana covers the internet-facing IT layer. It's designed to work alongside — not instead of — your existing OT and industrial control system security program.

Built for the customer-facing edge

Vana is designed for the internet-facing surfaces that defeat conventional automation.

  • Customer account and self-serve portals
  • Billing, payments and pre-authorized debit systems
  • Smart-meter data platforms and APIs
  • Outage reporting and notification services
  • Commercial and industrial customer dashboards
  • Partner, retailer and aggregator integrations
  • Legacy middleware and internal web portals
  • Acquired-entity estates and shadow applications
  • Pre-prod, staging and production change windows

Scope note. Vana tests internet-facing web applications and APIs — customer portals, billing systems, data platforms. It does not test industrial control systems, SCADA, or OT networks. It's built to secure the IT-facing layer that's commonly the entry point attackers use to work toward OT — not to replace an OT-specific security program.

Regulatory fit

One continuous evidence trail, ahead of the designation clock.

Reporting is OWASP-aligned and can be mapped to relevant control frameworks, with optional review by a qualified human pentester where additional assurance is needed.

Canada

  • Bill C-8 received Royal Assent June 2026, creating the Critical Cyber Systems Protection Act — enacted, but not yet operative
  • Designation orders are expected on a phased, sector-by-sector timeline; covered sub-sectors are interprovincial/international pipelines and power lines, and nuclear
  • Once designated, operators have 90 days to stand up a documented cybersecurity program

Sector & payment frameworks

  • NERC CIP and provincial regulator expectations for the IT systems adjacent to your operating environment
  • PCI DSS 4.0 (11.4) for customer billing and payment flows
  • SOC 2 and ISO 27001 mappings to ease critical-infrastructure vendor review

Evidence & assurance

  • OWASP-aligned reporting that can be mapped to relevant control frameworks
  • Optional review by a certified human pentester for board, regulator and insurer conversations
  • One continuous evidence trail rather than an annual snapshot

Pricing

Start with one application. Scale to continuous across the portfolio.

Vana Continuous, with volume-based pricing across your customer-facing applications and APIs, fits an operator's scale and ongoing exposure better than a point-in-time engagement. Add Human-in-the-Loop Review for findings that need certified human sign-off ahead of a board update, regulator conversation, or insurer requirement.

20-min Demo

Free Pentest

$0

Book a 20-minute demo with our CTO. We run Vana against one live customer-facing application and hand back the full report, findings and evidence. A low-commitment first look at output quality.

Book a 20-min Demo

Continuous coverage

Vana Continuous

$2,000

/ app / mo

Volume pricing for additional apps

Fixed monthly pricing per customer-facing web application, with volume-based pricing across your portfolio. Fits an operator's scale and ongoing exposure better than a point-in-time engagement.

Optional add-on

Human-in-the-Loop Review

Custom Pricing

Certified human pentester review of findings, evidence packaging and sign-off for board updates, regulator conversations, or insurer requirements.

Common questions

Ask the hard ones.

Our real risk is in OT and SCADA, not the website.+

Agreed — and that's exactly why this is scoped the way it is. Vana secures the internet-facing layer that's commonly the actual entry point in reported IT/OT incidents, as a complement to your OT-specific security program, not a substitute for it.

Vendor approval for critical infrastructure takes a long time.+

Canadian HQ and existing compliance mappings (SOC 2, ISO 27001, PCI DSS) are built to ease that review, and we're glad to start with a scoped, single-app engagement.

We'll deal with this once we're formally designated.+

Fair, but the clock works against a wait-and-see approach: once your operator class is named in a designation order, you have 90 days to stand up a documented cybersecurity program. Testing your customer-facing surface now means that clock doesn't start from zero — and the underlying exposure (live, internet-facing portals and APIs) is current regardless of the regulatory timeline.

Can an AI actually test something this complex?+

Vana handles SSO and step-up authentication, entitlement-based access boundaries, multi-tenant separation and REST/GraphQL business logic — the surfaces that defeat conventional automation — at 95%+ accuracy with evidence attached to every finding.

How does testing production stay safe?+

Scope, rate limits and change windows are agreed up front, and testing can run against pre-prod or staging environments where production windows are constrained.

Continuous coverage for the layer most exposed to the open internet.

Book a 20-minute demo and get a free scan of one live customer-facing application — the full report, real findings, remediation support; with no obligation.