BLOCKED
4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.
- Strong copyleft (GPL-family) licenses in production dependencies
- Network copyleft (AGPL-family) licenses in production dependencies
- Credentials in the current code (2)
The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.
How every claim is graded
Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.
- Verified
- Observed and independently checked
- Observed
- Read directly from the repository or a named source
- Derived
- Computed deterministically from observed facts
- Company-asserted
- Stated by the company; not proof
- Inferred
- Heuristic reading; raises questions, never blocks
- Conflicting
- Sources disagree
- Unknown
- No evidence either way
Scope. meridian-systems/meridian-platform at 5df5415bdef5 (main). 44 files inventoried, 42 files read in full, 19 commits of history. Produced by acquicode-engine 0.1.0 with rules 2026.09.1; re-running the same analyzer on the same commits yields the same dossier digest.
AI development evidence. of 26 first-party files, 2 have line-level AI attribution, 4 were changed in AI-attributed commits, 0 carry only corroborating signals (self-declared comments or editor-inserted trailers), 10 are flagged by inference only, and 10 have no evidence either way. 75 surviving lines carry line-level AI attribution and 10 lines carry line-level human attribution; 147 current lines originate in commits that carry AI attribution (commit-level: the commit says a tool took part, not which lines it wrote). Tools evidenced: aider, chatgpt, claude-code, cursor, github-copilot. These are counts of evidence, not an estimate of how much code AI wrote; files with no evidence are unknown, not human-written. 2 contradictions between sources or declarations.
Ownership. 5 people committed code; 3 used personal, external or no-reply addresses. The company-supplied IP register covers 2 of them. History: 19 commits from 2023-02-01 to 2025-04-10.
Dependencies and licenses. 16 dependencies across 2 components; licenses known for 10, likely for 0, unknown for 6. Project license: LicenseRef-Proprietary. Known vulnerabilities were not checked (enrichment disabled); that section is UNKNOWN, not clean.
Limits. the analysis did not build or run the software, did not match snippets against public code, and did not see anything outside the repository. Material unknowns include: Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters); Whether pull requests containing AI-attributed changes were approved by another person; Origin and license of 1 committed binary file(s); Known vulnerabilities in 2 dependencies without an exact version. 1 finding was suppressed by the company (company-asserted reasons are listed in the evidence index).
Why: top material findings
blocking LIC-010 Strong copyleft (GPL-family) licenses in production dependencies
Observed1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review.
Evidence (2)
- Observed
package-lock.json — gpl-helpers: GPL-3.0-or-later · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — gpl-helpers@0.4.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_34cf22e8bc122451 · rule v1
blocking LIC-010 Network copyleft (AGPL-family) licenses in production dependencies
Observed1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.
Evidence (2)
- Observed
package-lock.json — pdf-render-kit: AGPL-3.0-only · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — pdf-render-kit@2.1.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_fce4b3f03ecfbedd · rule v1
blocking SEC-001 Credentials in the current code
ObservedStripe live key in config/.env.production line 1. The value is not reproduced here; fingerprint 792000dea84a3de5.
Evidence (1)
- Observed
config/.env.production:1 — Stripe live key: sk_l… (31 chars) · secret.match · secrets.stripe-live-key@1
Fingerprint fp_7bf5684e91e2c46e · rule v1
blocking SEC-001 Credentials in the current code
ObservedAWS access key ID in src/config.ts line 3. The value is not reproduced here; fingerprint fe916f86aa5d5cca.
Evidence (1)
- Observed
src/config.ts:3 — AWS access key ID: AKIA… (20 chars) · secret.match · secrets.aws-access-key@1
Fingerprint fp_e83b0a535b53e98c · rule v1
material AI-002 Declaration contradicts recorded AI evidence
ConflictingDeclared as written by people (src/billing/**), but 1 matching file(s) carry AI attribution (e.g. src/billing/invoice.ts).
Evidence (2)
- Company-asserted
meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1 - Observed direct
commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
Fingerprint fp_235bc8dcb4afa396 · rule v1
material AI-003 Attribution sources disagree
ConflictingAttribution records for src/ai/summarize.ts at 58d65e3e4738 disagree on 10 line(s): one source says AI, another says human.
Evidence (2)
- Observed direct
src/ai/summarize.ts @ 58d65e3e4738 — git-ai authorship/3.0.0 · provenance.git_ai_note · ai.git_ai_note@1 - Company-asserted direct
src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
Fingerprint fp_4427a89bf2492389 · rule v1
Unknown: what this analysis could not establish
- Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters). The repository shows that a tool was used, not which account tier or settings applied. Resolve: Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it.
- Whether pull requests containing AI-attributed changes were approved by another person. Review approvals live in the forge (GitHub/GitLab), not in git history. Resolve: Connect the GitHub App or GitLab token, or supply review exports.
- Origin and license of 1 committed binary file(s). Binaries cannot be inspected like source code. Resolve: Provide the source or vendor/license information for each binary, or remove them.
- Known vulnerabilities in 2 dependencies without an exact version. No lockfile pins them, so the installed versions, and therefore the advisories that apply, cannot be determined. Resolve: Commit a lockfile and re-run the analysis.
- Known vulnerabilities in 10 dependency version(s). Vulnerability enrichment (OSV) was not enabled for this analysis, so no advisories were checked. This is not the same as "no vulnerabilities". Resolve: Re-run with vulnerability enrichment enabled.