Check Romanian companies by CUI in bulk and get notified when their status changes: VAT registration, inactive status, split VAT, e-Factura registry. Uses ANAF's public web service; source and retrieval time on every record. Pay per CUI checked and per change detected.
Rate limiter moved to the product host (one host per product, Petre's hosting rule 2026-10-07; ADR-001 amendment): PDA_LIMITER_URL is now https://clearsource.ppftec.com/limiter (the site Worker forwards /limiter/* to the anaf-limiter Worker over a Service Binding; the old https://anaf-limiter.petrepopa33.workers.dev is switched off). The pin is now host and path: https, exactly clearsource.ppftec.com, path exactly /limiter, no credentials, query or fragment; the request URL is built from the constant, never from the input. Redirects stay refused. The run log now names the limiter endpoint in use (never the secret).
Host move (Petre's hosting rule, 2026-10-07): privacy_notice_url is now https://clearsource.ppftec.com/privacy (the old https://ppftec.com/public-data-api/privacy answers 301 to it); README updated.
0.1.3 — 2026-10-04 (private build, not listed)
D-LIM-T1: a limiter slot whose round trip took longer than 400 ms is not used (the slot-time estimate would be too uncertain); a new slot is requested. At most 3 slow slots per ANAF request, then the run fails closed ("rate-limit service too slow to time the request safely"), with no ANAF call. Each discarded slot still counts against the shared daily budget (20,000/day).
0.1.2 — 2026-10-04 (private build, not listed)
Release conditions R1–R8 of the legal memo (docs/compliance/legal-research-memo-d6-2026-10-04.md §5.1), code parts:
R1: the central limiter enforces a global daily budget (default 60,000 ANAF slots per UTC day, var DAILY_SLOT_LIMIT, persisted); when it is used up the actor stops before any ANAF call with "the shared daily ANAF request budget is used up; try again after 00:00 UTC". Tests confirm: no proxy in the code, the descriptive User-Agent goes out with every ANAF request, back-off 5/10/20/40 s.
R2: CNP-like redaction now walks every string value taken from the ANAF response, at any depth (not a fixed field list); a property test injects a CNP into each source field in turn.
R4: every record carries privacy_notice_url (https://ppftec.com/public-data-api/privacy, one constant in src/sources.ts, pending hosting); README links it. Output schema 1.3.0 (additive, optional field).
R5: test that an accepted objection removes the CUI from the watch store on the next run, with no ANAF request, output or charge for it.
R6: README keeps "Sursa: ANAF" and makes no official / certified / OGL claim (one explicit disclaimer sentence; test).
Spacing raised from 1,200 ms to 1,500 ms (limiter + per-run guard; README throughput now about 4,000 CUIs per minute shared): the deployed contract test had measured client-side gaps of 891–969 ms. The limiter client now aims at the slot time (midpoint of the round trip + wait_ms) instead of sleeping wait_ms from receipt. Production daily budget 20,000 slots.
Fix rounds after QA (docs/qa/report-ro-company-status-2026-10-04.md) and security review (docs/security/anaf-limiter-and-company-status-review-2026-10-04.md).
DEF-1: without pay-per-event pricing a run is no longer truncated (only a real budget limit stops it); on Apify an unpriced build fails loud before any call unless PDA_ALLOW_NO_PPE=1 (private builds only). Watch state is persisted when events are unpriced.
DEF-2 / NEW-C2: new-format trade-register numbers (J/F/C + year 1990–current + 6 digits + county 01–52 + 1 digit, e.g. J2004000552406) are no longer nulled as CNP-like; J/F/C followed by a CNP still is.
DEF-3 / CS-SEC-06: INVALID_INPUTS echoes a value only if it holds at most 10 digits (after NFKC); 12-digit variants, CNPs split by any separator and full-width digits are stored as null.
DEF-4: a dry run with zero valid CUIs exits 1.
DEF-6: cap messages read "5,000" / "10,000".
DEF-7: the replay transport skips fixture files without a found[] list.
DEF-8: README states that the once-a-day floor applies to companies; sole traders are re-queried, never charged or reported.
DEF-9: resetWatch works under the kill switch, PDA_DISABLED_MODES=watch and the pending gates (it only deletes the customer's own store; no limiter or ANAF call, no charge).
DEF-10: live and deployed tests run only with an explicit opt-in set in the shell (PDA_LIVE_ANAF_APPROVED=P1-02; Worker LIMITER_CONTRACT=1).
CS-SEC-03: health mode needs PDA_HEALTH_ENABLED=1, a secret input healthToken matching the secret PDA_HEALTH_TOKEN (≥ 32 chars) and, if set, PDA_MAINTAINER_USER_ID.
CS-SEC-07: .actor/actor.json references secrets as @pdaLimiterSecret, @pdaSuppressionPepper, @pdaHealthToken; no maintainer switch is declared there.
LIM-SEC-10 (limiter): local tests use explicit bindings only and refuse to run if .dev.vars exists; contract values live in .contract.env; the limiter secret was rotated.
Output schema 1.2.0 (provenance envelope 1.1.0, additive; emitted records unchanged). Shared core updated (spacing never fires early).
0.1.0 — 2026-10-04 (private build, not listed)
Provenance envelope 1.1.0 vendored (additive: personal_data adds minimised, envelope_version accepts 1.1.0); output schema ro-company-status/record 1.2.0 references it; shared src/core/provenance.ts updated (identical in all actors). Emitted records unchanged (envelope_version1.0.0; personal_datanone or public-register-natural-person).
Lookup and watch modes per docs/spec/ro-company-status-v1.md (T1–T8): CUI check digit, CNP rejection, caps (10,000 / 5,000 / 20,000 raw), chunks of ≤ 100 CUIs, de-duplication.
Central rate limiter client (workers/anaf-limiter, ADR-001): a slot before every ANAF attempt, fail closed (no ANAF request without a slot), pinned limiter host.
Mapping with minimisation (sole traders: no street-level address; phone, fax, IBAN never output), CNP-like redaction, provenance envelope 1.0.0, output schema v1.1.0.
Source shape pinned against the first approved live sample (2026-10-04): no top-level cod/message, perioade_TVA is an array, empty values are "", extra key date_generale.data_inreg_Reg_RO_e_Factura (accepted, not output).
Watch mode (C1–C12): fixed store name, daily floor, pruning, no history, sole traders excluded, confirmation of disappearances, lock; gated off on Apify until D6.
Suppression list (HMAC with secret pepper), kill switches (PDA_KILL_SWITCH, PDA_DISABLED_ADAPTERS, PDA_DISABLED_MODES, limiter-side ANAF_DISABLED), dry run, health mode.
Pay-per-event charging: company-check, watch-check, status-change, chunks sized to the remaining budget.