AcquiCode diligence

Technical diligence dossier

Meridian Systems (synthetic demo company)

Subject
meridian-systems/meridian-platform @ 5df5415bdef5
Produced by
acquicode-engine 0.1.0, rules 2026.09.1
Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655
Reproduce
The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.

Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.

BLOCKED

4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.

  • Strong copyleft (GPL-family) licenses in production dependencies
  • Network copyleft (AGPL-family) licenses in production dependencies
  • Credentials in the current code (2)

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

4blocking
29material
12minor
1info
5material unknowns
How every claim is graded

Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.

Verified
Observed and independently checked
Observed
Read directly from the repository or a named source
Derived
Computed deterministically from observed facts
Company-asserted
Stated by the company; not proof
Inferred
Heuristic reading; raises questions, never blocks
Conflicting
Sources disagree
Unknown
No evidence either way

Scope. meridian-systems/meridian-platform at 5df5415bdef5 (main). 44 files inventoried, 42 files read in full, 19 commits of history. Produced by acquicode-engine 0.1.0 with rules 2026.09.1; re-running the same analyzer on the same commits yields the same dossier digest.

AI development evidence. of 26 first-party files, 2 have line-level AI attribution, 4 were changed in AI-attributed commits, 0 carry only corroborating signals (self-declared comments or editor-inserted trailers), 10 are flagged by inference only, and 10 have no evidence either way. 75 surviving lines carry line-level AI attribution and 10 lines carry line-level human attribution; 147 current lines originate in commits that carry AI attribution (commit-level: the commit says a tool took part, not which lines it wrote). Tools evidenced: aider, chatgpt, claude-code, cursor, github-copilot. These are counts of evidence, not an estimate of how much code AI wrote; files with no evidence are unknown, not human-written. 2 contradictions between sources or declarations.

Ownership. 5 people committed code; 3 used personal, external or no-reply addresses. The company-supplied IP register covers 2 of them. History: 19 commits from 2023-02-01 to 2025-04-10.

Dependencies and licenses. 16 dependencies across 2 components; licenses known for 10, likely for 0, unknown for 6. Project license: LicenseRef-Proprietary. Known vulnerabilities were not checked (enrichment disabled); that section is UNKNOWN, not clean.

Limits. the analysis did not build or run the software, did not match snippets against public code, and did not see anything outside the repository. Material unknowns include: Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters); Whether pull requests containing AI-attributed changes were approved by another person; Origin and license of 1 committed binary file(s); Known vulnerabilities in 2 dependencies without an exact version. 1 finding was suppressed by the company (company-asserted reasons are listed in the evidence index).

Why: top material findings

blocking LIC-010

Strong copyleft (GPL-family) licenses in production dependencies

Observed

1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review.

Evidence (2)
  • Observed package-lock.json — gpl-helpers: GPL-3.0-or-later · lockfile.license · licenses.metadata@1
  • Observed package-lock.json — gpl-helpers@0.4.0 · lockfile.entry · dependencies.parse@1

Fingerprint fp_34cf22e8bc122451 · rule v1

blocking LIC-010

Network copyleft (AGPL-family) licenses in production dependencies

Observed

1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.

Evidence (2)
  • Observed package-lock.json — pdf-render-kit: AGPL-3.0-only · lockfile.license · licenses.metadata@1
  • Observed package-lock.json — pdf-render-kit@2.1.0 · lockfile.entry · dependencies.parse@1

Fingerprint fp_fce4b3f03ecfbedd · rule v1

blocking SEC-001

Credentials in the current code

Observed

Stripe live key in config/.env.production line 1. The value is not reproduced here; fingerprint 792000dea84a3de5.

Evidence (1)
  • Observed config/.env.production:1 — Stripe live key: sk_l… (31 chars) · secret.match · secrets.stripe-live-key@1

Fingerprint fp_7bf5684e91e2c46e · rule v1

blocking SEC-001

Credentials in the current code

Observed

AWS access key ID in src/config.ts line 3. The value is not reproduced here; fingerprint fe916f86aa5d5cca.

Evidence (1)
  • Observed src/config.ts:3 — AWS access key ID: AKIA… (20 chars) · secret.match · secrets.aws-access-key@1

Fingerprint fp_e83b0a535b53e98c · rule v1

material AI-002

Declaration contradicts recorded AI evidence

Conflicting

Declared as written by people (src/billing/**), but 1 matching file(s) carry AI attribution (e.g. src/billing/invoice.ts).

Evidence (2)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_235bc8dcb4afa396 · rule v1

material AI-003

Attribution sources disagree

Conflicting

Attribution records for src/ai/summarize.ts at 58d65e3e4738 disagree on 10 line(s): one source says AI, another says human.

Evidence (2)
  • Observed direct src/ai/summarize.ts @ 58d65e3e4738 — git-ai authorship/3.0.0 · provenance.git_ai_note · ai.git_ai_note@1
  • Company-asserted direct src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1

Fingerprint fp_4427a89bf2492389 · rule v1

Unknown: what this analysis could not establish

  • Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters). The repository shows that a tool was used, not which account tier or settings applied. Resolve: Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it.
  • Whether pull requests containing AI-attributed changes were approved by another person. Review approvals live in the forge (GitHub/GitLab), not in git history. Resolve: Connect the GitHub App or GitLab token, or supply review exports.
  • Origin and license of 1 committed binary file(s). Binaries cannot be inspected like source code. Resolve: Provide the source or vendor/license information for each binary, or remove them.
  • Known vulnerabilities in 2 dependencies without an exact version. No lockfile pins them, so the installed versions, and therefore the advisories that apply, cannot be determined. Resolve: Commit a lockfile and re-run the analysis.
  • Known vulnerabilities in 10 dependency version(s). Vulnerability enrichment (OSV) was not enabled for this analysis, so no advisories were checked. This is not the same as "no vulnerabilities". Resolve: Re-run with vulnerability enrichment enabled.