Data and provenance
The repository keeps the research corpus as canonical source data and generates MDX-safe site copies at build time.
Canonical artifacts
INDEX.md— 290-row registry with status and last-investigated metadata.clients/— one Markdown dossier per authoritative client.source/message.txt— supplied authoritative client list.docs/dossier-template.md— canonical dossier structure and writing rules.scripts/validate_registry.py— content integrity checks.data/system-aliases.json— reviewed, conservative identity rules for system consolidation.data/system-analysis.json— canonical per-system hosting environment, kickoff date, and latest production-release research, including direct evidence or explicit unknowns.
Publication model
The build copies dossiers into a generated directory and performs only allowlisted MDX compatibility conversions. Canonical evidence files are not rewritten. Every generated client and system page includes a de-duplicated References index while retaining claim-level evidence links.
The deployed site also exposes byte-identical canonical artifacts under raw/; the SHA256SUMS manifest covers every published artifact.
Generated machine-readable registries are published for both derived views:
systems-registry.json— schema version 2 includes registry IDs, canonical names, aliases, client links, observations, source-file locations, relationship context, contractors, direct evidence, confidence labels, cloud/on-premises findings, kickoff dates, and latest production-release dates.contractors-registry.json— schema version 1 includes derived contractor IDs, normalized names, system/client/observation counts, and every evidenced Client → System → Contractor relationship with role, confidence, and direct source links.
Both registries are generated from canonical client dossiers. Unknown contractors remain explicit in client/system context and are not converted into contractor entities.
Identifier provenance
SYS-* values are internal deterministic registry identifiers. They are generated from the canonical identity key using the first ten hexadecimal characters of its SHA-1 digest.
CTR-* values are internal deterministic contractor identifiers. They are generated from the normalized evidenced contractor name using the first ten hexadecimal characters of its SHA-1 digest. Name normalization is conservative and does not imply that similar legal or trading names are the same entity.
Neither identifier family is discovered in public sources. The identifiers provide stable navigation while the underlying reviewed identity rule remains unchanged.
Interpretation
A generated system record is a navigational and analytical view over canonical client observations. It does not replace the linked evidence or imply ownership, current use, hosting, or supplier responsibility beyond the relationship stated in those observations.