AcquiCode diligence
Technical diligence, with the evidence attached

Know what a buyer will find in your code before they look.

Trace ownership, AI involvement, licenses and exposure to the records behind them. See what can be proved, and what a buyer will still need to ask.

Hosted sign-in is being set up. The sample works now; the local CLI can scan your own repository without uploading source.

AcquiCode / dossier excerptMeridian Systems · synthetic
BLOCKED
4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.
4blocking
29material
5unknowns
10files with no AI evidence either way
blockingLIC-010Strong copyleft (GPL-family) licenses in production dependenciesObserved

1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distributi…

blockingLIC-010Network copyleft (AGPL-family) licenses in production dependenciesObserved

1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft c…

Open the full sample dossier →

Buyers now ask two questions about AI-built code

How much of this was produced with AI tools? And, more importantly, what share was reviewed by a person who understood it?

Most founders cannot answer either. Tools that “detect” AI-written code give you a percentage that is a guess, and a wrong number in a transaction document is a liability. Even attribution written by tools can be wrong: some editors have stamped AI co-authors on commits with no AI involvement.

AcquiCode does not guess. It collects the evidence that exists (coding-agent trailers, agent-authored commits, git-ai line attribution, Agent Trace records, review approvals) and grades it.

The evidence ladder

Direct, line-levelMachine-readable records tie specific lines to a tool.Direct, commit-levelA commit written by, or naming, the agent that made it.CorroboratingSelf-declared comments, tool configuration, editor-inserted trailers.InferenceA reason to ask. Never counted as evidence, never blocks a deal.No evidenceUnknown. Not “human”.

How it works

  1. Connect, or run the CLI

    Install the GitHub App on the repositories you choose, connect GitLab, upload an archive, or run the CLI in CI so the code never leaves your machine.

  2. Fix what you can, declare what you can't

    Rotate the exposed key, pin the action, record your AI tools and their terms, upload the IP register. Re-scan until what is left is what you intend to disclose.

  3. Share a dossier the buyer can verify

    Send a read-only link to the buyer and their counsel. The dossier is signed, and anyone with access to the same commits can reproduce it byte for byte.

What the dossier answers

Ownership

Everyone who committed code, under which addresses, matched against your IP-assignment register. Contractors on personal emails and work that predates a signature are called out for counsel.

Licenses & third-party code

Dependency licenses with their certainty, copyleft given your distribution model, copied snippets (Stack Overflow is CC BY-SA), foreign copyright notices, unlicensed vendored code.

Exposure

Credentials in code and history (values never reproduced), material vulnerabilities, CI pipelines that run untrusted code, dependency confusion.

Reproducibility

Are the inputs needed to rebuild the software declared and pinned: lockfiles, drift, container digests, committed binaries.

AI development

Which tools, on which code, reviewed by whom, under which terms (indemnities depend on the plan tier), and where the records contradict what the company says.

What is still unknown

A separate list of what could not be established, why, and how to resolve it, with questions routed to management, counsel and engineering.

For acquirers and investors

Ask your target for a dossier, not their code

Targets rarely hand source code to a buyer directly. With AcquiCode you send a request instead:

  • Create a request for each target; it comes with a token that can only deliver one dossier to you, and cannot read anything.
  • The target runs the analysis in their own CI or on a laptop and pushes the signed result.
  • You see what arrived, whether the signature checks out, and every question the dossier raises, routed to your deal team, counsel and engineers.

See the dossier a buyer receives

What a buyer gets that a questionnaire cannot give

  • Evidence, graded. Each answer states whether it was observed, derived, asserted by the company, inferred or unknown.
  • Contradictions surfaced. Where the company's declarations disagree with the repository, the dossier says so.
  • A verifiable artifact. A signature binds the dossier to the commits it describes; reproduction proves it matches the code.
  • A history. Snapshots over time show what changed between signing and close.

Deterministic, so it can be verified

There is no language model in the analysis. The same commits and the same analyzer always produce the same dossier digest, so a buyer, their counsel or an independent reviewer can re-run it and check.

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

# The Meridian demo repository
$ node acquicode.mjs scan . --sign-key keys/acquicode-signing.key.pem
BLOCKED  4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.
  findings: 4 blocking, 29 material, 12 minor · unknowns: 5 material
  AI evidence (files): 2 line-level, 4 commit-level, 10 inference-only, 10 no evidence
  digest c9f52a1b6dbe7ac7474f…

$ node acquicode.mjs verify dossier.json --reproduce .
dossier digest c9f52a1b6dbe7ac7474f…
reproduced digest c9f52a1b6dbe7ac7474f…: MATCHES

Pricing

A sell-side technical review costs $5,000–$30,000 and takes weeks. AcquiCode is the first pass you run before anyone else does.

Local

$0 forever

Engineers and CI

  • CLI and CI analysis where the code lives
  • Full dossier, JSON, CycloneDX SBOM
  • Self-signed attestations
  • One hosted repository to try the workflow
Run the free CLI

Custody

$490 per month

Companies within two years of a raise or exit; post-close integration

  • Up to 25 repositories
  • Continuous monitoring on every push
  • Signed snapshot history (chain of custody)
  • Material-change timeline, with Slack or webhook alerts
  • Share links
Request early access

Acquirer

$2,500 per month

Aggregators, search funds and PE running several deals

  • Up to 60 repositories across targets
  • Targets push signed dossiers to your workspace with a write-only token; no code changes hands
  • Signature and digest verification for every dossier received
  • Share links for your deal team and counsel
  • Change reports between a target's snapshots
Request early access

Enterprise: Run the whole stack in your own environment (container image) · Custom repository limits and retention · Dossier upload API for CI · Direct support during a transaction. Request it here

Questions

Do you detect AI-written code?

No. Detection of AI-written code is an open research problem, and a percentage based on it would be a guess presented as a fact. We report the evidence that exists and label everything else unknown.

What if my repository records no AI attribution at all?

Then the dossier says so, and the AI section is mostly “unknown”. That is still useful: it tells you what a buyer will ask, and how to start recording attribution (git-ai or Agent Trace) so the next snapshot can answer.

Is this legal advice?

No. The dossier states technical facts and their certainty, and turns them into questions for your counsel.

What happens to my code?

With the CLI, nothing leaves your machine. With hosted analysis, the repository is cloned into an isolated working directory with a short-lived read-only token, analysed, and deleted; only the dossier is kept, encrypted, for your retention period. No model is trained on it and no language model reads it. Details.

What does READY mean?

Every diligence question is answered and nothing material is unknown. It is deliberately hard to reach: you need history, declarations, a contributor register and a vulnerability check, not just clean code. It is never a statement that the software is secure or free of legal risk.

Find out before your buyer does

Your first repository is free. The sample dossier shows exactly what you will get.