Summary

  • The identity bridge is unusually strong: the RIPE record for AS202842 names SC HIGH-TECH SYSTEM&SOFTWARE SRL and carries registration number 30126940, the same number used on HTSS software and legal pages. The slight differences in spacing and pluralisation across public records do not describe different Romanian companies.
  • AS202842 substantiates a narrow historic network surface: one observed IPv4 prefix, 95.128.174.0/24, a registered routing policy naming GTS Telecom and Vodafone Romania, and public visibility that ended on December 17, 2025. It does not substantiate which HTSS applications ran there, where their data were stored, or whether either declared connection was a live failover path.
  • The commercial perimeter changed before the route vanished. Setrio announced the purchase of the retail-pharmacy software division in February 2025; Smart ID announced the purchase of the Business Solutions team, Mindclass and Shiftin in July; the sole shareholder then chose voluntary dissolution in September. A current Romanian company record now marks the original company as radiated.
  • For a buyer, the decisive evidence is therefore product-specific and contractual: successor ownership, data flow and residency, current security assurance, named support staff, recovery tests, export formats and an executable transition plan. Routing data can verify a small part of the transport history, but procurement must stop well before turning that history into an application, security or continuity claim.

The route’s final morning

At 08:00 UTC on December 17, 2025, a small piece of the public internet’s map changed. RIPE’s historical view says that 95.128.174.0/24, a block of 256 IPv4 addresses, was last seen with AS202842 as its origin at that time. The same RIPE routing-status record dates the first observation to July 27, 2016. A windowed RIPE query shows the prefix continuously visible from the beginning of December until that final timestamp.

The temptation is to turn that timestamp into a corporate narrative: the network shut because the company shut. The dates make the story look plausible, but they do not prove it. According to Economica’s report on the shareholder resolution, Kaseke Limited decided on September 18, 2025 to dissolve High Tech Systems & Software voluntarily, appoint a liquidator and end the administrators’ mandates. The route remained publicly visible for roughly three more months. Its withdrawal could have followed decommissioning, a provider change, an asset transfer, an administrative choice or another cause. BGP carries no liquidation note.

The distinction matters because the corporate and network clocks did not stop together. In February 2025, Setrio announced that it had acquired HTSS’s retail-pharmacy software division. In July, Smart ID announced the acquisition of the Business Solutions division, its custom-software team, Mindclass and Shiftin. In September came the dissolution decision. In December the last globally visible prefix disappeared. By this research date, Termene’s record for CUI 30126940 marks the company as radiated, while the RIPE registration still exists and shows a May 2026 modification to the organisation entry.

That asynchronous sequence is the opening lesson. A registry entry can persist after a legal company is removed. A product website can remain readable after its named provider ceases to be a viable counterparty. A route can continue after an asset sale and disappear before every public record catches up. Each surface has its own maintenance cycle. None should be asked to answer a question it was not designed to answer.

As of July 18, 2026, the network evidence is clear but narrow. The current RIPE AS overview says AS202842 is not announcing a prefix. The current announced-prefix query returns none for July 4–18. IPinfo independently labels the ASN inactive, with no currently known address space, hosted domains, peers or upstreams in its view. Those observations justify saying that the public network surface is no longer visible at normal thresholds. They do not justify saying that every historical application stopped, that customer deployments vanished, or that no private connectivity survives.

One number resolves the identity problem

The assigned name is awkwardly specific: SC HIGH-TECH SYSTEM&SOFTWARE SRL. Elsewhere, the company appears as High-Tech Systems & Software S.R.L., HIGH TECH SYSTEMS & SOFTWARE SRL, or simply HTSS. “System” becomes “Systems”; spaces appear around the ampersand; the Romanian corporate prefix comes and goes. Names alone would leave room for a false match.

Registration number 30126940 closes that gap. The RIPE organisation record pairs SC HIGH-TECH SYSTEM&SOFTWARE SRL with reg-nr: 30126940. The surviving HTSS solutions catalogue places High-Tech Systems & Software S.R.L., tax number RO 30126940 and Trade Register number J40/4847/2012 in its legal footer. Telemedica’s terms name High-Tech Systems & Software SRL, the same trade-register number and the same tax number as the company that provides and manages the service described on that page. Termene’s company record uses another typographic variant but the same CUI.

This is more than brand association. It is a chain from a public network registration to a Romanian legal identifier and from that identifier to software terms and product marketing. It supports the conclusion that AS202842 belonged to the same legal company behind the HTSS pages. It also prevents a common research error: treating a similarly named overseas technology company, an unrelated “HTSS” domain, a parent investor or a product brand as the assigned company.

The bridge is historical as well as technical. When Romania’s Competition Council approved Kaseke Limited’s takeover in 2021, AGERPRES described the target as a developer and implementer of custom and proprietary software, a supplier of hardware infrastructure, and a provider of maintenance and support for the IT&C services it developed. That independent account connects the legal company to both application work and infrastructure delivery. It is stronger evidence of the operating bridge than an ASN alone.

But the same identifier that proves the past also disciplines claims about the present. The current company record for 30126940 says radiated. The public Telemedica terms still designate that number as the service company. Both facts can be true as statements about different update cycles; they cannot together tell a buyer who could validly sign a new service agreement today. The correct response is not to choose the more convenient page. It is to require a current corporate certificate and a documented chain transferring the relevant contract, intellectual property, data-processing duties and support obligations to a live legal party.

What the operating company demonstrably did

At its widest public perimeter, HTSS looked less like a pure cloud subscription business than a combined software house, systems integrator and support operator. The 2021 AGERPRES account supplies the broad categories: custom applications, proprietary applications, hardware infrastructure, and maintenance and support. The company’s own solutions catalogue adds the product and workflow names: pharmacy management, omnimedica for doctors and clinics, Telemedica, Mindclass, Shiftin, custom development, and IT infrastructure services including security, application development, migration and information storage.

First-party catalogues describe ambition, not delivery. Two procurement records make the software-and-support activity more concrete. The Romanian Court of Accounts’ 2024 register lists HIGH-TECH SYSTEMS & SOFTWARE SRL on a RON 58,459 contract to maintain the authority’s own e-learning platform and marks it completed. A separate 2024 public-procurement result identifies the same company by RO30126940 as winner of a RON 374,900 learning-management service contract. The second record is an aggregator rather than the authority’s original award notice, so it is corroboration, not a basis for expansive conclusions. Neither record should be relabelled Mindclass without contract text saying so.

The healthcare side is also tied to the legal entity rather than merely to a brand. Telemedica’s terms call the product a paid B2B Software as a Service offering and identify company number 30126940. The terms describe browser and mobile access, customer administrators and users, paid access governed by a separate agreement, and account information such as name, email and organisational role. Telemedica’s public site presents video and chat consultation, appointment and patient-history workflows. These are claims made by the product site, but the legal page makes the company-to-product attribution real.

Mindclass has a similarly direct, product-specific bridge. A Microsoft-hosted publisher-attestation page identifies High-Tech Systems & Software SRL as the partner company for Mindclass and dates the developer’s answers to August 30, 2024. It describes a Teams-connected learning application running on Azure infrastructure. Again, the evidence is bounded: it tells us about the developer’s assertions for one application at one date. It does not make Azure the architecture of the pharmacy suite, Telemedica or the company’s custom deployments.

The pharmacy portfolio had the deepest operational footprint described in public. The HTSS catalogue presented software for pharmacy management, while a 2025 transaction announcement named DataKlas Pharmaceutical and Pharma Original as the products in the retail-pharmacy division acquired by Setrio. An incumbent’s regulatory document offers useful independent market context: Cegedim’s 2024 Universal Registration Document identified HTSS, Setrio and Softeh as its main Romanian pharmacy-software competitors, while making clear that this was its own market assessment.

This evidence supports a substantial historical operator: application development, regulated-industry workflows, infrastructure supply, support, and public-sector learning services. It does not support a single uniform architecture. A custom application deployed on customer premises, a pharmacy system linked to fiscal devices, a Teams learning service reported as running on Azure, a telemedicine web service and a routed /24 can coexist in one supplier portfolio without sharing a hosting stack. Procurement goes wrong when the company-level list is mistaken for a product-level dependency diagram.

What AS202842 actually substantiates

An autonomous system is an administrative unit of internet routing, not a catalogue of servers. RFC 4271 defines BGP as the protocol that exchanges network reachability information between autonomous systems. Its AS_PATH tells other routers which autonomous systems an announcement has traversed. It can reveal that a network originated a prefix and which external networks carried the route. It was never designed to identify a software licence holder, a database engine, a patient-record store or a support desk.

The RIPE documentation for an aut-num record is equally precise. Such a record represents an autonomous system and its external routing policy; its inbound and outbound policy attributes say what routes an operator intends to accept or announce. In AS202842’s registered record, the company declared that it would accept routes from AS5606 and AS12302 and announce AS202842 to each. The status is assigned, and the record dates from May 2016.

The observed surface was small. RIPE’s routing-status history identifies only 95.128.174.0/24 as the first and last observed origin prefix. There is no observed IPv6 space in the current status. A /24 is the smallest IPv4 prefix generally carried without widespread filtering on the public internet, although that operational convention itself does not say how the addresses were used. The important company-specific point is simply scale: the public origin evidence covers 256 addresses, not an unknowable global estate.

What can a buyer reasonably infer from that? First, HTSS once had enough control over network policy to originate a public prefix through its own ASN. That suggests a deliberately managed edge rather than relying exclusively on addresses originated by a hosting vendor. Second, two named external providers in the registered policy indicate an intention to have more than one path. Third, the persistence of the prefix through December 2025 gives a timestamped signal that some network configuration remained visible after the asset transfers and dissolution decision.

Each inference needs a brake. Originating a prefix does not prove ownership of the underlying address block; route origin, address registration and physical equipment can involve different parties. Two policy lines do not prove two simultaneous working sessions, diverse fibre paths or automatic failover. A public /24 does not show whether it carried production, disaster recovery, office internet, VPN endpoints, monitoring, email or nothing customer-facing at all. The last-seen time does not identify a service interruption. The record offers a view of control at the routing boundary and almost nothing above it.

The present observation is even narrower. The RIPE overview reports no qualifying announcement on July 18, 2026, and the two-week prefix query returns an empty list. That means procurement cannot use AS202842 as evidence of a currently reachable production edge. It also means a buyer should not use its absence as proof that transferred products are offline: those products may have been moved, may always have lived elsewhere, may run in customer environments or may use a cloud provider’s address space.

Two declared providers, only one observed neighbour

The two policy counterparts are not obscure. The RIPE overview for AS5606 identifies GTS Telecom SRL’s backbone. The overview for AS12302 identifies Vodafone Romania. On paper, that is a plausible dual-provider edge for a Romanian enterprise supplier: two large external networks and a customer ASN announcing the same identity toward both.

But registration and observation diverge. A RIPE historical neighbour query returns AS5606 as the only left-side neighbour in its snapshot. It does not return AS12302. Collector coverage is incomplete, so this is not proof that Vodafone was disconnected; it is proof that the frozen public observation corroborates GTS and does not independently corroborate Vodafone for that moment.

Even GTS’s presence needs disciplined wording. GTS says it operates data centres in Bucharest and Cluj-Napoca and sells colocation and cloud services. It would be easy to place HTSS equipment in one of those facilities by association. There is no source here that does so. A transit path through the GTS backbone might terminate at customer premises, a leased rack, another carrier hotel or a managed service. The provider’s portfolio cannot fill the missing HTSS architecture diagram.

Nor does dual-provider intent equal physical resilience. Two BGP sessions can share the same building entrance, power supply, router, firewall, cross-connect tray or configuration error. One may be a cold standby. One policy may be stale. The providers may themselves share downstream infrastructure. The only safe network conclusion is that the registered policy named two external systems and that RIPE observed one of them in the selected historical view.

For procurement, this distinction translates into a document request. If a service successor claims carrier diversity, it should provide the service-specific topology under confidentiality: demarcation points, facilities, last-mile paths, edge hardware, failover method, monitoring ownership, route-filtering practice and recent failover-test evidence. The AS record is a useful index against which to check that diagram. It cannot replace the diagram.

The application estate was larger than the routed edge

The mismatch between one /24 and a broad software catalogue is not suspicious; it is normal for an integrator. What matters is that the catalogue spans very different customer workflows and therefore very different failure consequences.

In pharmacy retail, the transferred products sat close to inventory, sales, fiscal and regulatory processes. Setrio’s acquisition announcement promised that customers would retain their existing DataKlas Pharmaceutical or Pharma Original application while Setrio combined expertise and support. That promise reveals the switching problem even without publishing an architecture: pharmacy customers were sufficiently embedded that continuity meant keeping the current application, not forcing an immediate migration.

In learning, the workflows were identity, enrolment, content, assessment and organisational reporting. The Microsoft publisher attestation for Mindclass says the application processed names, surnames, email addresses and company roles, integrated with Microsoft identity, and used a delegated User.Read permission. HTSS’s catalogue description presented Mindclass alongside employee training and Shiftin alongside workforce scheduling. Those are enterprise-control surfaces: access rules, staff data, course history, shift constraints and managerial reporting, not merely web pages.

In telemedicine, the stakes change again. Telemedica’s public terms describe a B2B application in which customer administrators create users and manage access. Its privacy policy contemplates account, device, location and usage information, and distinguishes situations in which the company is a controller from support work in which it acts as processor for the customer. Its marketing describes medical history, appointments, video and chat. A route announcement cannot tell a clinic whether consultation records are encrypted at rest, whether video is relayed or peer-to-peer, whether backups contain health data, or which party can restore them.

Custom software makes company-level inference weakest of all. A development team can deliver applications into a customer’s tenant or data centre, operate a hosted service, maintain a third-party platform or hand over code at acceptance. AGERPRES’s 2021 description confirms that HTSS combined custom development, proprietary software, hardware infrastructure and maintenance. It does not say that all of those activities depended on AS202842.

The rational architecture hypothesis is therefore heterogeneous: some services may have used the company edge, some used a public cloud, some ran in customer environments, and some combined these arrangements. That is explicitly an inference from the variety of delivery types, not a verified topology. A buyer must obtain the answer per service instance. Any diligence report that labels the entire estate “self-hosted in Romania” because of AS202842, or “hosted in Azure Ireland” because of Mindclass, crosses the evidence boundary.

The portfolio split changed the continuity question

Before 2025, a customer could plausibly ask one company about software, infrastructure and support. After the disclosed transfers, “Is HTSS still operating?” became the wrong question. The useful question is “Which live party owns and supports this exact deployment, under which transferred obligations?”

The first split was sector-specific. On February 13, 2025, Setrio’s announcement said it acquired the HTSS retail-pharmacy software division that held DataKlas Pharmaceutical and Pharma Original. Setrio said each customer would keep its existing software, that operational continuity was an objective, and that the combined teams would improve technical support. Those are meaningful commitments from the buyer, but they remain commitments. A pharmacy should still verify contract novation, support contacts, release ownership, source-code custody, data-processing roles and the maintenance roadmap for its installed version.

The second split was capability-specific. On July 11, Smart ID’s announcement said it acquired the Business Solutions division, a team experienced in architecture, custom development and delivery, plus Mindclass and Shiftin. The acquiring company said the team would join its Logistics and Business Solutions operation. HTSS’s finance chief framed the transaction as continuity for the transferred products and people. For users of those named products, this is the strongest public successor signal in the frozen record.

The announced sets do not cover everything. Neither the Setrio release nor the Smart ID release names Telemedica, omnimedica, AS202842 or every infrastructure and support obligation. The absence of a name in a press release does not prove that an asset remained behind, moved elsewhere, was discontinued or was bundled under a broader term. It means only that the public chain is incomplete. Assigning those residual services to Setrio, Smart ID, Kaseke, Penta or another affiliate without transaction documents would be invention; the dissolution report does not supply that missing asset chain.

The dissolution decision then made the missing chain commercially urgent. Economica reported that the sole shareholder chose voluntary dissolution on September 18. The same report, cross-checked against Targetare’s 2024 figures, gives a company that had still been large in accounting terms: roughly RON 118 million revenue, a RON 67.7 million loss, RON 74.6 million debt and average employment of 337. Scale did not remove continuity risk.

The current Termene record marks CUI 30126940 as radiated. That status changes the burden of proof. A buyer should not accept a legacy website, invoice template or familiar support mailbox as evidence of the counterparty. The successor must identify itself, show the legal basis on which it controls the software and customer data, and reconcile the old contract with the new operating arrangement.

Telemedica is the unresolved counterparty test

Telemedica exposes the problem more clearly than the transferred products because its public commercial surface still appears open. The pricing page offers one month free, then EUR 40 per doctor per month with a five-doctor minimum. The terms page calls the service paid, B2B and available by browser and mobile application. It names High-Tech Systems & Software SRL, J40/4847/2012 and tax number 30126940 as the company managing the service.

Yet the current company record for that number says radiated. A working marketing page and a removed legal company are not two equal indicators to average together. The marketing page may be an unattended remnant, the service may be operated during a transition, or an unpublicised successor may exist. The public record here does not resolve which.

The standard terms would have been weak continuity evidence even before that conflict. They permit the company to terminate on 30 days’ notice. They allow assignment or subcontracting of services without customer consent. They offer the service as available, disclaim continuous operation, and say access may cease or change. Pricing is delegated in part to a separate agreement. For a low-impact collaboration tool, a buyer might negotiate around such provisions. For a clinical workflow involving patient history, consultation scheduling and communications, they demand a stronger negotiated service schedule.

The privacy policy raises more questions. It says a third-party cloud provider acts as sub-processor, but the provider link is left unfilled. It says data may sit on company or sub-processor servers, yet another server reference is unfilled. The duration for retaining login and access history is also left unspecified. The policy lists possible support, hosting, analytics, email and SMS providers without publishing a current named list or locations. These are observations about the public document, not a finding that the running service lacks controls.

A prospective clinic therefore needs a fresh evidence room before even testing the software. The first document is not a security certificate; it is a current contracting-party certificate. Next come a signed data-processing agreement, named sub-processors and countries, a current service description, support and escalation contacts, availability and recovery commitments, evidence of professional liability coverage, and a transition statement explaining what happened to the old company’s customer contracts and data.

For an existing customer, the order is slightly different. Preserve access and exports, identify who is currently receiving fees and support requests, and obtain written confirmation of the party controlling the environment. Do not interpret the public-page contradiction as permission to stop care workflows abruptly. The goal is controlled continuity: establish legal and technical custody while maintaining safe patient operations.

Product-specific hosting evidence beats ASN inference

Mindclass demonstrates what better-scoped evidence looks like, even though the evidence is historical and self-reported. On the Microsoft page, HTSS said Mindclass used Azure Infrastructure as a Service and stored the covered Microsoft customer data in Ireland. It identified the data as name, surname, email and company role. Those answers were last updated by the developer on August 30, 2024.

That statement is useful because it names a product, cloud layer, provider and country. It also carries a prominent limitation: Microsoft says the page is based on the developer’s self-assessment and gives no guarantee of accuracy. The statement predates Smart ID’s acquisition of Mindclass. A 2026 buyer should ask Smart ID for the current architecture and assurance rather than treating the old attestation as inherited truth.

Telemedica’s privacy policy gives the opposite example. It acknowledges a third-party cloud sub-processor but does not name it in the relevant line or identify a country. AS202842 cannot fill that gap. Even if Telemedica once used an address in 95.128.174.0/24—and there is no evidence here that it did—the route would identify an origin ASN, not the jurisdiction of every primary database, backup, content store, analytics service, email gateway or video component.

The same restraint applies to GTS. AS5606 was a declared provider and the only neighbour visible in the selected historic RIPE snapshot. GTS advertises facilities in Bucharest and Cluj-Napoca. No public source here places HTSS equipment in either facility. “Connected to a provider that owns Romanian data centres” is not “hosted in Romania,” and neither phrase answers where a cloud backup or subcontracted service processes data.

A usable product architecture should separate at least six planes: user access, application compute, primary data, backups, identity, and outbound integrations. For Telemedica, video, chat, notifications and medical records may have different paths. For Mindclass, Teams identity, learning content and reporting may differ. For pharmacy software, a local store server, central database, fiscal equipment and vendor support channel may all sit in different places. These are procurement questions, not assertions about the actual deployments.

The practical output is a data-flow diagram with legal names attached to each service. It should state data categories, processor role, country, encryption ownership, recovery source, deletion path and exit format. The diagram should be current after the 2025 transfers. Neither the old ASN nor an old cloud attestation can substitute for it.

Security assurance must follow the product and owner

The Mindclass publisher attestation contains the richest public control list in this research. HTSS reported annual penetration testing, quarterly vulnerability scanning, a documented disaster-recovery plan, perimeter controls, event logging, alerting, formal incident response, change approval and multifactor authentication for code repositories, DNS management and credentials. It also reported ISO 27001 certification.

The same page records limits: no SOC 2 or SOC 3, no ISO 27017, and no FedRAMP compliance; some other standards were marked not applicable. More importantly, all answers were supplied by the developer. There is no certificate number, current scope statement, penetration-test executive summary, recovery-test result or audit period on the public page. It is a good diligence index and a poor final assurance package.

Ownership change creates a scope problem. A management-system certificate can cover a legal entity, locations, people and processes. Moving a product and team to Smart ID does not automatically demonstrate that the buyer’s current environment is covered by the old entity’s certificate or that every control continued unchanged. The right evidence is a current certificate and scope, a statement of applicability where available, and product-specific testing under the successor’s ownership.

Telemedica needs a separate assessment. Its public privacy policy describes personal data and third-party support categories but omits a named cloud provider and precise login-history retention period. Its terms disclaim uninterrupted availability. Neither document supplies technical evidence for encryption, tenant isolation, backup immutability, recovery time, recovery point, vulnerability disclosure or security monitoring. That is an evidence gap, not proof that the controls do not exist.

European requirements explain why a buyer cannot stop at an ISO logo. GDPR Article 32 calls for risk-appropriate confidentiality, integrity, availability, resilience, restoration and regular testing; Article 28 governs processor and sub-processor terms. For organisations in scope, NIS2 Article 21 puts incident handling, business continuity, backup and disaster recovery, supply-chain security, secure maintenance and effectiveness testing in the same risk programme. Neither source establishes that every HTSS product or customer is within every provision. Together, they show the categories of evidence a regulated buyer is expected to manage.

ENISA’s procurement baseline is useful operationally: set lifecycle-wide minimum requirements, connect certification to the relevant scope, require support for an agreed lifetime, and address vulnerability handling and service continuity. Applied here, that means assurance travels with the named product, environment and successor. It cannot be inherited from the mere persistence of the HTSS brand.

Incidents, outages and the danger of an empty record

The frozen public record does not establish a security incident attributable to HTSS, AS202842 or any named HTSS product. It also contains no product-specific public postmortem. Those are deliberately bounded statements. They do not mean that no incident occurred; they mean a buyer cannot derive incident performance from the materials reviewed.

There is one visible network change: the route stopped appearing on December 17, 2025. The RIPE history records reachability, not cause or application impact. Calling the withdrawal an outage would be speculation. If no customer workload used the prefix, there may have been no customer effect. If a migration preceded it, disappearance may have been planned. If services depended on it without alternative paths, the consequence could have been material. The route data cannot select among these cases.

The Telemedica terms explicitly contemplate maintenance, internet-related unavailability and cessation or change of access, while declining to promise continuous function. That contract language is not an incident history. It tells a buyer that any availability commitment must live in a negotiated schedule, with measurement source, maintenance windows, exclusions, service credits and termination rights.

Romanian healthcare supplies a sobering sector benchmark that is not an HTSS allegation. In February 2024, the Romanian Ministry of Health reported that ransomware encrypted production files and databases of a hospital information system and made systems unavailable across multiple hospitals. The ministry notice does not connect that event to HTSS. It demonstrates why a clinic buying any digital-care system needs tested restoration, offline procedures and clarity about shared dependencies.

The diligence response to an empty public incident record is neither trust nor accusation. Ask the current operator for a three-year incident schedule, including severity, duration, affected services, notification timing, root cause and corrective actions. Ask for recent recovery-test evidence and the exact status of open remediation. Reconcile those answers with monitoring reports and customer references. If confidentiality limits disclosure, use redacted summaries or an independent assessor. Silence is an unknown, not a clean bill of health.

Support evidence survived in contracts, then moved with teams

HTSS did more than sell licences. The Romanian Court of Accounts register records a completed 2024 maintenance engagement for an e-learning platform. AGERPRES described maintenance and support as part of the operating company’s activity. These are credible historical signals of a support organisation.

The 2025 transactions show that people, not just code, were part of continuity. Setrio said it would combine expertise and strengthen support for the pharmacy products. Smart ID said it took over an experienced custom-software team along with Mindclass and Shiftin. Those statements improve the successor story for the named assets because knowledge transfer is explicit.

They still leave buyer-level questions. Which support tickets, knowledge articles, source repositories, deployment tools and customer-specific configurations transferred? Did response-time obligations move unchanged? Are the same engineers retained? Who holds privileged access to old environments? Which party patches versions that were heavily customised? Does a pharmacy contact Setrio for every DataKlas module, or only the acquired retail-pharmacy set? The announcements do not say.

For small and mid-sized customers, concentration of knowledge is a particular continuity risk. A deployment may depend on a few people who understand fiscal integrations, inventory rules, identity mappings or data conversions. A large supplier headcount can conceal that narrow dependency. The 2024 average of 337 employees reported by Economica says nothing about how many people understood a given customer.

A successor support schedule should therefore be named and testable. It needs service hours, severity definitions, response and restoration targets, escalation contacts, Romanian and other required language coverage, on-call arrangements, maintenance ownership, vulnerability timelines, spare-hardware responsibility where relevant, and a knowledge-transfer plan if staff leave. A live exercise—opening a priority ticket and tracing escalation—is more informative than a support brochure.

Pricing is visible; total cost is not

Telemedica is the rare part of the historical portfolio with a public figure. Its pricing page advertises a one-month trial and then EUR 40 per physician per month, with a minimum of five physicians and therefore EUR 200 per month. The terms say the final access type, rate, invoicing and payment conditions are set in a separate agreement.

That price is useful as a commercial clue and unsafe as a budget. It does not identify implementation, data migration, identity integration, training, messaging or video usage, storage, support tier, security assessment, custom reporting, taxes or exit work. It also sits on a page whose named legal provider is now marked radiated. A buyer must obtain a current quote from a verified successor before treating the figure as available.

The other products appear more naturally tied to configuration and integration. Pharmacy systems touch inventory, sales, fiscal and reporting workflows. Mindclass can integrate identity and organisational learning records. Shift scheduling depends on labour constraints and workforce data. Custom software is, by definition, scoped around a customer. In each case, the subscription or licence is only one layer of cost.

The largest hidden cost is often change. Pharmacy data must remain accurate and auditable while transactions continue. Learning history may be needed for compliance or employment records. Shift rules embed local practice. Clinical records and communications require safe continuity. Interfaces to accounting, identity, devices, messaging and reporting must be rebuilt or preserved. The buyer should price data extraction, mapping, parallel run, reconciliation, user retraining, old-system read access and secure deletion from the beginning.

The European Commission’s Data Act explainer says the regulation has applied since September 12, 2025 and establishes minimum switching and contractual-transparency requirements for data-processing services within scope. It discusses open interfaces and machine-readable export for relevant platform and software services, with switching charges due to be removed from January 12, 2027. The exact application can depend on the service and exceptions, especially for highly customised deployments. Procurement should use the regulation as a floor to examine, not a reason to skip an exit schedule.

For a successor product, the quote should split recurring service, implementation, third-party services, support, security options and exit assistance. It should also say which legacy customisations the successor accepts responsibility for. A low monthly price paired with undocumented data export and an uncertain legal chain is not cheap; it is deferred migration expense.

Competition is now successor-specific

Before the breakup, HTSS could be compared as a broad Romanian technology supplier. In pharmacy software, Cegedim’s 2024 filing placed HTSS beside Setrio and Softeh as principal competitors in its own assessment. After Setrio acquired the HTSS retail-pharmacy division, using that old league table without adjustment would count part of the same product lineage on both sides.

For Mindclass and Shiftin, the relevant vendor is now the acquiring operation described by Smart ID, not a radiated HTSS company. For DataKlas Pharmaceutical and Pharma Original, it is the Setrio continuity proposition. For Telemedica, omnimedica and residual infrastructure services, this research cannot name a successor. They should not enter a competitive shortlist until a current owner and contracting party are proven.

The comparison criteria should follow the workflow. A pharmacy buyer should test statutory updates, inventory and fiscal integrations, offline operation, store rollout, support coverage, data conversion and roadmap. A learning buyer should test identity, content standards, reporting, accessibility, tenant separation and export. A clinic should test consent and access controls, consultation continuity, clinical-data handling, sub-processors, recovery and safe downtime procedures. A custom-development buyer should test code ownership, deployment reproducibility, documentation, staffing and handover.

Network autonomy is a secondary differentiator at best. A current ASN and dual transit may be valuable for a self-operated platform, but a cloud-native service can be resilient without its own ASN, and an ASN can exist without a resilient application. Compare measured service outcomes and dependency design. Use routing evidence to verify specific architecture claims, not to rank vendors by the appearance of infrastructure ownership.

A procurement test built around the broken chain

The most useful diligence process for this company’s legacy is not a generic questionnaire. It is a sequence designed to close the exact gaps exposed by the 2025 transfers, the radiated legal company, the surviving product pages and the withdrawn route.

1. Establish the current legal and asset chain

Start with the exact product and installed version. Obtain a current registry certificate for the proposed contracting party. Require the asset-purchase or transfer evidence necessary to show ownership or licensing rights, without demanding commercially irrelevant transaction details. Map the old HTSS contract to any novation, assignment or new agreement. Confirm who owns customer-specific code, generic product code, trademarks, documentation and deployment tooling.

For DataKlas Pharmaceutical and Pharma Original, the Setrio announcement is a strong lead, not the contract. For Mindclass and Shiftin, the Smart ID announcement performs the same role. For Telemedica, the old terms and the radiated company record conflict, so a new buyer should pause commercial commitment until the chain is supplied.

2. Draw the instance-specific architecture

Ask for a diagram of the actual customer instance, not a reference architecture. Mark application components, identities, databases, object storage, backups, monitoring, support access, interfaces and message providers. Name the legal operator and country for each. Separate customer premises, successor-controlled infrastructure and public cloud.

Use AS202842 only as a reconciliation item. If the diagram claims no dependence on the old network, ask when any migration occurred and whether customer allow-lists, VPNs, certificates or monitoring still reference 95.128.174.0/24. If it claims a replacement network, record the new origin and providers. Do not assume that the old prefix’s withdrawal caused a migration or proves its completion.

3. Test continuity as an operation

Require recent backup-restore results with recovery point and recovery time, not merely a policy. Walk through loss of the primary site, cloud region, identity provider, key support person and one external integration. Define manual procedures for pharmacy, workforce, learning or clinical operations during downtime. Establish who declares an incident, who communicates with customers and who can authorise restoration.

For healthcare, the Romanian Ministry of Health’s 2024 incident notice shows the operational consequence of inaccessible production data, without implicating HTSS. A restoration claim should therefore be exercised against a realistic encrypted or unavailable primary environment.

4. Replace historic assurance with current evidence

Use the Mindclass Microsoft attestation as a question list: Azure location, testing cadence, recovery plan, logging, MFA, vulnerability handling and certificate scope. Then ask the successor for current evidence. Confirm what changed in hosting, personnel and control ownership after acquisition.

For Telemedica, resolve every missing item in the privacy policy: cloud provider, server locations, sub-processors, transfer basis, retention periods, support access and deletion. Align the data-processing agreement with GDPR. Where the customer is covered, map evidence to NIS2 supply-chain, incident and continuity duties. Do not treat a certificate badge as the mapping.

5. Prove support capacity

List named roles rather than relying on total headcount: product owner, release engineer, database specialist, integration specialist, security lead and escalation executive. Show coverage and backups for each. Review ticket statistics by severity, age and recurrence. Test a ticket. Verify that the team acquired by the successor actually supports the customer’s branch and custom version.

For pharmacy and learning customers, compare the promised continuity in the Setrio and Smart ID announcements with staffing, release notes and response data. The announcements say knowledge moved; operations must show how much.

6. Make exit executable before entry

Inventory every export: master data, transactions, documents, audit trails, attachments, learning history, schedules, clinical records, configuration and identity mappings. Define format, frequency, cost, encryption and validation. Include documentation and assistance for custom interfaces. Preserve a legally appropriate read-only archive where records must remain accessible.

The Data Act guidance sharpens expectations for switching in covered data-processing services, but it cannot write the customer’s migration plan. Schedule an export test during the contract, measure completeness, and require remediation. Define secure deletion and evidence after transition.

7. Verify network claims at their proper level

If the service uses its own network, collect current prefix, origin, provider, facility and route-security evidence. Test failover and compare observations from more than one vantage point. Ask whether the two providers are physically diverse. If the service is in public cloud, focus instead on region design, private connectivity, egress control and cloud dependency.

The old record offers a cautionary control: two registered providers, one neighbour observed in the selected snapshot, and no current public announcement. A procurement statement should say which of those is policy, which is measurement and which is no longer current.

Where procurement must stop inferring

The qualification question has a firm answer. Historically, the exact Romanian entity behind registration number 30126940 developed and supported enterprise software, supplied infrastructure, operated named healthcare and learning products, and controlled AS202842. Public customer and platform records corroborate parts of that activity beyond the company’s own marketing.

As of July 18, 2026, no current service can safely be assigned to that exact legal entity for new procurement. The company is marked radiated. Named assets moved: DataKlas Pharmaceutical and Pharma Original to Setrio’s disclosed pharmacy transaction, and Mindclass, Shiftin and a custom-software team to Smart ID’s disclosed Business Solutions transaction. The public chain for Telemedica, omnimedica, residual infrastructure work and AS202842 remains incomplete.

AS202842 substantiates one historical public prefix, an autonomous routing identity and a declared two-provider policy. Public observation corroborates GTS as a neighbour in the selected historical view; it does not corroborate Vodafone there. The route was last seen on December 17, 2025 and is not currently visible at RIPE’s normal threshold. That is the full defensible network conclusion.

Procurement must stop before inferring an application from the prefix, a data centre from an upstream, redundancy from two policy lines, security from network control, or business continuity from a surviving website. It must also stop before assigning an unmentioned product to a transaction buyer. Each of those leaps replaces a missing document with a plausible story.

The route’s disappearance is still valuable. It gives buyers a precise question: what depended on 95.128.174.0/24, where did it move, and who accepted responsibility? A credible successor should be able to answer with an asset chain, an architecture, current assurance, support ownership and a tested exit. Until then, the old ASN is not a certificate of resilience. It is a boundary marker showing exactly where open-source network evidence ends.