7.9 KiB
7.9 KiB
Lithuanian source-route notes
Use these routes as discovery and verification aids; they do not lower the claim/source standard in the main skill.
Official institution sites
- On LRV-hosted and similar official sites, inspect
/sitemap.xmlto enumerate deep pages that menus and search engines miss. Prioritize paths forasmens-duomenu-apsauga,informacines-sistemos,registrai,projektai,viesieji-pirkimai,nuostatai, andatviri-duomenys. - Open the discovered page and cite the canonical page URL. A sitemap entry proves that a page exists, not the claim inside it.
- Pages headed
... asmens duomenų valdytojaor... asmens duomenų tvarkytojacan directly establish a controller/processor role for listed systems. Do not translatevaldytojaon a personal-data page into system ownership unless system regulations or another source explicitly assign ownership.
Official-site internal search fallback
- When external engines do not expose an older institution or article, try the official municipality/institution search route directly. A recurring Lithuanian pattern is
/search?q=<URL-encoded exact institution name>. - Treat the search page only as discovery. Open and cite the resulting official article; verify that the article body, not merely a search snippet, names the institution and supports the claimed purpose or relationship.
- This route is particularly useful for schools with retired domains, renamed institutions, and municipality-hosted news archives.
data.gov.lt fallback for blocked institution sites
- When an institution's official site remains blocked after one browser-equivalent retry, search
https://data.gov.lt/datasets/?q=<URL-encoded exact institution name>. Inspect the organization/creator facets and result cards, then open the direct organization page (/orgs/<id>/) and each relevant dataset record (/datasets/<id>/). - The organization page can corroborate the exact publisher identity, supervising jurisdiction, and sector. A direct dataset record can establish that the institution publishes or maintains data from a named register or system when its metadata says so.
- Treat the query page and facets as discovery, not final evidence. Cite the opened organization or dataset record. Dataset publication does not by itself prove software ownership, development, maintenance, hosting, or cloud provider; preserve those as unknown unless another source assigns the role.
CPVA search form
- CPVA's
https://cpva.lt/paieskauses Search & Filter Pro. The live, validated result URL ishttps://cpva.lt/paieska?_sf_s=<URL-encoded phrase>. The browser rewrites the form state to this URL and the server-rendered.search-filter-results-3173container contains the result cards. An ordinaryPOSTwith_sf_search[]can return an apparently successful but unfiltered/empty page; do not use that as evidence that a query ran. - Validate automation against a positive control such as the generic term
sistemaand a negative/random control. Confirm the result container changes, extract result-card titles and links, and recognize the explicitRezultatų nėra – įveskite / pakoreguokite paieškos frazęempty state. - CPVA search behaves as broad token matching rather than reliable exact-phrase matching. Long system labels can return unrelated pages sharing generic words, and even every queried system may appear to have a raw hit. Treat candidate counts as noisy discovery output; rank pages by exact acronym/name occurrence and open the source body before mapping anything.
- Search pages remain discovery evidence only. Open the resulting CPVA article, project, or attachment and require its body to prove the exact client/system relationship, project, date, funding, supplier, or delivery role before citing it.
Official policy PDFs as SaaS evidence
- Inspect sitemap URLs for direct PDFs as well as HTML pages. School and care-institution sitemaps often expose electronic-diary usage rules, data-processing policies, or director-approved procedures that navigation menus omit.
- Extract and inspect the full PDF text. A dated official procedure can directly name the institution, product, provider, system purpose, administrative roles, and login URL; embedded PDF link annotations may also reveal a product URL not obvious in extracted prose.
- Bound the date carefully: a policy proves use or an assigned provider role at the policy date, not an unchanged current subscription, current maintenance allocation, contract term, or production hosting. Keep those fields unresolved unless a current contract or equivalent source establishes them.
- When the official policy names both the SaaS product and company, it can support the client-product relationship and provider attribution in one primary source. Open the provider's current legal/product page separately to corroborate the company's identity and product role, but do not inflate that corroboration into implementation, hosting, or contract claims.
Lithuanian public-procurement documents
- Search results may expose direct documents at URLs shaped like
https://viesiejipirkimai.lt/epps/cft/downloadContractDocument.do?resourceId=...&documentId=.... - Official institution sites may also place a child
/sutartys/page under a named system or service page. Inspect its raw anchors: these catalogues can separately link a preliminary agreement, amendment, main contract, and supplier offer even when the visible page contains almost no supplier detail. Resolve relative attachment URLs against the page URL, download each relevant body, and classify each document independently. - Open and inspect the document body. Endpoint names and link labels such as
downloadContractDocument,Pagrindinė sutartis, orTiekėjo pateiktas pasiūlymasdescribe the expected document class but are not proof of supplier identity, signature, dates, or delivery until the body confirms them. - If an HTML catalogue opens but an attachment rejects a generic downloader, retry once with the same browser-equivalent
User-Agent,Accept, and language headers used for bot-sensitive public pages. If the body still cannot be opened, cite the catalogue only for the existence of procurement documents and leave supplier attribution unresolved. - Classify evidence by its contents:
- technical specification or tender conditions → intended procurement and required scope;
- supplier offer → bidder and proposed scope, not award by itself;
- preliminary/framework agreement → framework parties and scope, not necessarily a call-off;
- main/signed contract → contracted role and dates;
- award notice → selected supplier, subject to identity/date alignment;
- acceptance/completion record → delivered or accepted work.
- Technical specifications are especially useful for current-system inventories, acronyms, integrations, migration scope, and planned functionality, but they do not identify the winning supplier unless the body explicitly does so.
Pre-delivery link verification
- Extract every URL from changed dossiers and open each one before commit. Correct path truncation, stale slugs, and redirects before assigning confidence.
- Inspect redirect chains, not only the initial URL's status. An official institution page may redirect to a retired or unreachable product domain: the redirect can still prove that the institution links or historically linked the named service, but it does not prove that the service is currently operational. State the availability gap explicitly and avoid an unqualified current-use claim.
- For a multi-file batch, check unique evidence URLs concurrently with bounded timeouts, then retry flagged links once with a different network strategy (for example IPv4-only
curl -4) before classifying them. Preserve genuine HTTP failures and unreachable final destinations as review items rather than silently accepting the source URL. - Re-run the dossier table/schema check after any textual patch; a targeted replacement can accidentally remove a Markdown table cell while leaving the prose readable.