AcquiCode diligence

Technical diligence dossier

Meridian Systems (synthetic demo company)

Subject
meridian-systems/meridian-platform @ 5df5415bdef5
Produced by
acquicode-engine 0.1.0, rules 2026.09.1
Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655
Reproduce
The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.

Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.

BLOCKED

4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.

  • Strong copyleft (GPL-family) licenses in production dependencies
  • Network copyleft (AGPL-family) licenses in production dependencies
  • Credentials in the current code (2)

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

4blocking
29material
12minor
1info
5material unknowns
How every claim is graded

Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.

Verified
Observed and independently checked
Observed
Read directly from the repository or a named source
Derived
Computed deterministically from observed facts
Company-asserted
Stated by the company; not proof
Inferred
Heuristic reading; raises questions, never blocks
Conflicting
Sources disagree
Unknown
No evidence either way

These are counts of evidence, not an estimate of how much code was written by AI. A file with no evidence is unknown, not human-written.

Direct, line-level2Machine-readable attribution (git-ai notes, Agent Trace) ties current lines to an AI tool.
Direct, commit-level4Changed in commits whose metadata names an AI tool. Says a tool took part, not which lines.
Corroborating only0A self-declared comment in the file, or an editor-inserted co-author trailer. Consistent with AI use; not attribution.
Inference only10A heuristic signal. A reason to ask, not evidence.
No evidence either way10Unknown.

Of 26 first-party source and test files.

Lines with line-level AI attribution
75
Lines with line-level human attribution
10
Current lines from AI-attributed commits
147 of 1277 blamed lines
AI-attributed commits
5 of 19 (1 via pull request or merge, 4 pushed directly)
Review approvals
unknown (forge API not connected)

Tools

ToolSignalsCommitsModelsDeclared terms
aidercommit-metadata1—Unknown
chatgpt · openaifile-comment0—Unknown
claude-code · anthropiccommit-metadata, config-file, git-ai2claude-sonnet-4-20250514plan: enterprise; indemnity: true; from: 2024-07-01; evidence: Anthropic commercial agreement dated 2024-06-20 Company-asserted
cursor · anysphereagent-trace, commit-metadata, config-file2anthropic/claude-sonnet-4-20250514Unknown
github-copilot · githubagent-authored-commit1—Unknown
material AI-002

Declaration contradicts recorded AI evidence

Conflicting

Declared as written by people (src/billing/**), but 1 matching file(s) carry AI attribution (e.g. src/billing/invoice.ts).

Evidence (2)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_235bc8dcb4afa396 · rule v1

material AI-003

Attribution sources disagree

Conflicting

Attribution records for src/ai/summarize.ts at 58d65e3e4738 disagree on 10 line(s): one source says AI, another says human.

Evidence (2)
  • Observed direct src/ai/summarize.ts @ 58d65e3e4738 — git-ai authorship/3.0.0 · provenance.git_ai_note · ai.git_ai_note@1
  • Company-asserted direct src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1

Fingerprint fp_4427a89bf2492389 · rule v1

material AI-005

AI-attributed changes without review evidence

Derived

4 of 5 commit(s) carrying AI attribution landed without a pull request or merge (pushed directly to the analysed branch), so there is no record of review.

Evidence (4)
  • Observed direct commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_0303827158ddeaf2 · rule v1

material AI-008

AI tool terms not declared

Observed

Evidence shows use of aider, cursor, github-copilot but the plan tier, IP indemnity and output-filter settings in force were not declared. Indemnities typically depend on paid commercial tiers and specific settings.

Evidence (0)

No item-level evidence: this finding is derived from counts or configuration described in its summary.

Fingerprint fp_fc8d772c0a87b8b6 · rule v1

material AI-011

Files predominantly attributed to AI with no recorded human authorship

Derived

1 file(s) have line-level records attributing at least 80% of their current lines to AI tools and none to a named person (e.g. src/search/index.ts). This is a statement about the records, not a legal conclusion on authorship.

Evidence (2)
  • Company-asserted direct src/search/index.ts @ d0bc1462d623 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
  • Observed direct commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_7a90a7c416a2bc5a · rule v1

minor AI-006

Large unattributed changes after AI tools were adopted

Inferred

Commit 81de5601f559 ("Add reporting module") added 950 lines across 10 files with no AI attribution, after AI tool configuration first appeared (2024-07-01). This is an inference, not evidence of AI origin; ask how it was produced.

Evidence (1)
  • Inferred inference commit 81de5601f559 — Add reporting module · commit.bulk_unattributed · ai.bulk_unattributed@1

Fingerprint fp_26573072b1008fc6 · rule v1

info AI-001

AI coding tools used in this repository

Observed

Evidence of 5 AI coding tool(s): aider (1 attributed commit); chatgpt (file-comment); claude-code (2 attributed commits); cursor (2 attributed commits); github-copilot (1 attributed commit).

Evidence (5)
  • Observed direct commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_f76e52d6f06c1478 · rule v1

Files with AI evidence

FileClassAI linesHuman linesToolsState
src/ai/helpers.tsdirect commit——cursorObserved
src/ai/summarize.tsdirect line3010claude-codeConflicting
src/billing/invoice.tsdirect commit——claude-codeConflicting
src/reports/report1.tsinference———Inferred
src/reports/report10.tsinference———Inferred
src/reports/report2.tsinference———Inferred
src/reports/report3.tsinference———Inferred
src/reports/report4.tsinference———Inferred
src/reports/report5.tsinference———Inferred
src/reports/report6.tsinference———Inferred
src/reports/report7.tsinference———Inferred
src/reports/report8.tsinference———Inferred
src/reports/report9.tsinference———Inferred
src/search/index.tsdirect line450cursor, github-copilotCompany-asserted
src/users/avatar.tsdirect commit——cursorObserved
src/users/profile.tsdirect commit——aiderObserved