The web layer around the grid gets tested least
Customer account portals, billing platforms and smart-meter data APIs receive far less security testing attention than the industrial control systems they're built around.

Continuous security validation for energy & utilities
Bill C-8 is now law with the Critical Cyber Systems Protection Act. Once the government issues designation orders - pipeline, power line, and nuclear operators will have 90 days to stand up a documented cybersecurity program once designated. Vana continuously tests the layer attackers actually hit — customer portals, billing systems, smart-meter platforms — the most common entry point in IT/OT convergence incident documented cybersecurity program.
Book a meeting and get a full free pentest of one live application.
The problem
Energy and utility operators invest heavily in OT security — and rightly so. But the web-facing layer around it — customer portals, billing platforms, smart-meter APIs — is often left under tested, despite sitting exposed on the open internet and being the more common entry point in IT/OT convergence incidents. Under the CCSPA (Bill C-8), designated pipeline, power line, and nuclear operators will soon need to prove they have an active cybersecurity program in place.
Customer account portals, billing platforms and smart-meter data APIs receive far less security testing attention than the industrial control systems they're built around.
Security research has repeatedly documented that IT-facing systems, not OT networks directly, are the initial entry point in the majority of reported IT/OT convergence incidents.
Most operators' security spend and internal expertise sits with control-system security. The customer-facing layer often goes untested by comparison.
The Critical Cyber Systems Protection Act, enacted under Bill C-8, will require designated energy operators to demonstrate active cybersecurity programs once designation orders are issued.
Traditional engagements run 5–10+ weeks at $15K–$50K. A two-week sprint can ship changes faster than a point-in-time engagement can be scheduled and completed.
The customer-facing layer is the one with the most direct exposure to the open internet — live, reachable and current regardless of the regulatory timeline.
WHY ENERGY & UTILITY OPERATORS CHOOSE VANA
Vana is built and trained in-house, not wrapped around an existing scanner.
Built and trained in-house — the only fully AI-autonomous pentester on the market. Vana reasons about your application: enumerates, chains findings, escalates privileges and proves impact the way a real intruder would.
More than any manual or typical AI pentester. Each finding ships with evidence, so triage isn't a second job.
SSO/SAML/OIDC, MFA and step-up flows, customer entitlements, multi-tenant boundaries, and REST and GraphQL business logic across self-serve and partner APIs.
InfiltrateIQ is Canadian-headquartered, in a market where 82% of Canadian buyers weigh vendor country of origin and 56% are actively reconsidering US-based providers. Canada's Cyber Centre (CCCS) co-authored the Five Eyes agentic AI security guidance.
Vana covers the internet-facing IT layer. It's designed to work alongside — not instead of — your existing OT and industrial control system security program.
Vana is designed for the internet-facing surfaces that defeat conventional automation.
Scope note. Vana tests internet-facing web applications and APIs — customer portals, billing systems, data platforms. It does not test industrial control systems, SCADA, or OT networks. It's built to secure the IT-facing layer that's commonly the entry point attackers use to work toward OT — not to replace an OT-specific security program.
Regulatory fit
Reporting is OWASP-aligned and can be mapped to relevant control frameworks, with optional review by a qualified human pentester where additional assurance is needed.
Pricing
Vana Continuous, with volume-based pricing across your customer-facing applications and APIs, fits an operator's scale and ongoing exposure better than a point-in-time engagement. Add Human-in-the-Loop Review for findings that need certified human sign-off ahead of a board update, regulator conversation, or insurer requirement.
20-min Demo
$0
Book a 20-minute demo with our CTO. We run Vana against one live customer-facing application and hand back the full report, findings and evidence. A low-commitment first look at output quality.
Book a 20-min DemoContinuous coverage
$2,000
/ app / mo
Volume pricing for additional appsFixed monthly pricing per customer-facing web application, with volume-based pricing across your portfolio. Fits an operator's scale and ongoing exposure better than a point-in-time engagement.
Optional add-on
Custom Pricing
Certified human pentester review of findings, evidence packaging and sign-off for board updates, regulator conversations, or insurer requirements.
Common questions
Agreed — and that's exactly why this is scoped the way it is. Vana secures the internet-facing layer that's commonly the actual entry point in reported IT/OT incidents, as a complement to your OT-specific security program, not a substitute for it.
Canadian HQ and existing compliance mappings (SOC 2, ISO 27001, PCI DSS) are built to ease that review, and we're glad to start with a scoped, single-app engagement.
Fair, but the clock works against a wait-and-see approach: once your operator class is named in a designation order, you have 90 days to stand up a documented cybersecurity program. Testing your customer-facing surface now means that clock doesn't start from zero — and the underlying exposure (live, internet-facing portals and APIs) is current regardless of the regulatory timeline.
Vana handles SSO and step-up authentication, entitlement-based access boundaries, multi-tenant separation and REST/GraphQL business logic — the surfaces that defeat conventional automation — at 95%+ accuracy with evidence attached to every finding.
Scope, rate limits and change windows are agreed up front, and testing can run against pre-prod or staging environments where production windows are constrained.
Book a 20-minute demo and get a free scan of one live customer-facing application — the full report, real findings, remediation support; with no obligation.