Solutions/By industry/Telecommunications
For telecommunications

CPNI redaction and DORA documentation across

Telecom operators handle some of the most precisely regulated customer data anywhere, where CPNI protection must be certified annually by a corporate officer under penalty of perjury. Igris redacts CPNI at the prompt layer, gates account modifications behind approval, isolates network data by region, and produces GDPR, DPDP Act, and DORA documentation from one governance layer.

USE CASE 01
01
CPNI Redaction

AI Customer Service for Telecom

cpniredactionenforcement
Problem

A telecom chatbot for billing inquiries, plan changes, and technical support receives customer information that falls precisely within FCC Customer Proprietary Network Information rules: phone numbers, account PINs, call records including numbers dialled, call duration and frequency, service package details, and device location during active calls. FCC violations carry penalties of up to $2.5 million per violation per day, and annual compliance must be certified by a corporate officer under penalty of perjury, covering every system and channel that handled CPNI throughout the prior year. When a support bot routes any CPNI to an external LLM provider without a documented redaction control, the operator has created a CPNI unauthorised disclosure event — and the annual certification cannot accurately be signed. GDPR applies for EU subscribers, DPDP Act 2023 for Indian subscribers, and DORA requires EU telecom operators to document the operational resilience controls governing every AI system involved in customer-facing operations.

Igris Solution

Guard applies CPNI-specific redaction policies to every inbound customer message before the prompt reaches the LLM provider — stripping phone numbers, account PINs, call record references, billing details, and service identifiers. Igris Sentinel governs every tool call the support bot makes, blocking account modification actions — plan changes, PIN resets, service additions — until a defined human approval step is completed, enforcing the authorised disclosure and access controls CPNI rules require. Igris Lens tracks cost per support channel — chat, voice, and SMS. The full audit trail creates the documented evidence the annual CPNI certification process requires — that every customer interaction involving CPNI data was governed by a technical control throughout the certification year.

Outcome

The support bot operates with CPNI redaction enforced on every interaction — enforced by the governance layer before the call leaves the network. Account modification actions require human approval by policy. The compliance officer preparing the annual FCC CPNI certification has the audit trail the filing requires without manual log reconstruction.

USE CASE 02
02
Data Isolation

Network Analytics AI

isolationcostdora
Problem

AI systems analysing network performance data to predict outages and optimise routing run as large continuous batch pipelines across multiple network regions and business units simultaneously. Three structural problems emerge at that scale. First: a network anomaly can cause the analytics pipeline to consume far beyond its normal allocation before any human intervenes. Second: without cost anomaly detection, a spike in traffic analysis spend is invisible until the billing cycle closes. Third: without connection isolation between regions and business units, a query on one region's network performance data can expose that data in another region's analytics session — a data sovereignty problem and a DORA ICT risk management gap for EU operators whose documented controls must demonstrate segregation between critical infrastructure components.

Igris Solution

Igris rate limiting holds every network analytics pipeline within its defined allocation regardless of what the network is doing. Igris Lens cost anomaly detection distinguishes between a genuine network incident that legitimately requires intensive analysis and a misconfigured pipeline consuming silently. Tenant isolation on Igris connections keeps each network region's and each business unit's data cleanly separated — satisfying data sovereignty requirements and DORA's ICT risk management requirements for EU infrastructure segregation. The full audit trail records every analytics call, every isolation enforcement event, and every anomaly alert — providing the DORA Article 11 ICT risk management documentation EU operators must maintain.

Outcome

Network analytics pipelines run within defined bounds during normal operations and during incident response events. Regional data stays isolated at the connection layer, satisfying data sovereignty and DORA segregation requirements simultaneously. DORA compliance documentation is generated by the audit trail automatically.

USE CASE 03
03
CPNI Redaction

AI Fraud Detection for Telecom (SIM Swap and Toll Fraud)

cpnicostaudit
Problem

Telecom fraud teams using LLMs to detect SIM swap attacks, toll fraud, and subscription abuse operate pipelines processing the most sensitive CPNI categories available: call records, account modification histories, device identifiers, and service usage patterns. A fraud detection pipeline routing call record data to an external LLM without a documented CPNI redaction control has created the precise unauthorised CPNI disclosure scenario that FCC enforcement action addresses. DORA requires EU telecom operators to document how AI systems in fraud detection pipelines are governed as part of their ICT risk management framework.

Igris Solution

Guard applies CPNI-aware redaction to every fraud analysis prompt, stripping call record identifiers, device references, and account modification data not required for the specific detection inference. Rate limiting prevents the fraud pipeline from consuming beyond its defined allocation during detection spikes. Lens cost anomaly detection distinguishes between a genuine fraud wave and a misconfigured pipeline consuming unexpectedly. The full audit trail provides the CPNI compliance evidence the annual FCC certification requires and the DORA ICT risk management documentation EU operators must maintain.

Outcome

The fraud detection pipeline runs at scale with CPNI redaction enforced on every call. The annual CPNI certification can accurately attest to the controls in place. DORA documentation exists from the audit trail. When a new SIM swap pattern drives a tenfold call volume spike, the rate limit holds the cost and the anomaly alert identifies the cause.

USE CASE 04
04
Agent Governance

AI-Powered Network Operations Centre Assistant

mcpcontentdora
Problem

NOC engineers responding to network incidents increasingly use AI assistants to synthesise alarm data, identify root causes, and coordinate remediation. Network topology details, equipment identifiers, IP address ranges, and infrastructure configuration references are precisely the data that carries the highest sensitivity in a telecom operator's environment. In some jurisdictions, network topology information is classified as critical national infrastructure. CPNI applies when incident context includes subscriber-linked data. DORA Article 11 requires EU telecom operators to document how AI tools used in network operations are governed.

Igris Solution

Guard applies custom content detection patterns to NOC assistant prompts, catching network topology identifiers, IP address blocks, infrastructure configuration references, and CPNI-adjacent subscriber data before any prompt reaches the LLM provider. An allowed model list restricts which LLMs can be used for infrastructure-sensitive queries. Sentinel governs every tool call the NOC assistant makes, enforcing an allowlist of permitted actions so the assistant cannot query or modify network systems beyond its defined operational scope. The DORA-aligned audit trail records every assistant interaction, every policy enforcement action, and every model used.

Outcome

NOC engineers get an AI assistant that genuinely accelerates incident response without routing network topology or subscriber data to external providers. CPNI and infrastructure sensitivity controls are enforced at the prompt layer on every interaction. DORA documentation is generated automatically. When an engineer asks the assistant to query a system outside its permitted scope, Sentinel blocks it before the call executes.

See Igris for Telecommunications

Govern AI across customer service, network, and fraud

See how telecoms redact CPNI on every call, gate risky actions, and generate DORA ICT risk documentation automatically.