AcquiCode diligence

Technical diligence dossier

Meridian Systems (synthetic demo company)

Subject
meridian-systems/meridian-platform @ 5df5415bdef5
Produced by
acquicode-engine 0.1.0, rules 2026.09.1
Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655
Reproduce
The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.

Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.

BLOCKED

4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.

  • Strong copyleft (GPL-family) licenses in production dependencies
  • Network copyleft (AGPL-family) licenses in production dependencies
  • Credentials in the current code (2)

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

4blocking
29material
12minor
1info
5material unknowns
How every claim is graded

Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.

Verified
Observed and independently checked
Observed
Read directly from the repository or a named source
Derived
Computed deterministically from observed facts
Company-asserted
Stated by the company; not proof
Inferred
Heuristic reading; raises questions, never blocks
Conflicting
Sources disagree
Unknown
No evidence either way
blocking LIC-010

Strong copyleft (GPL-family) licenses in production dependencies

Observed

1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review.

Evidence (2)
  • Observed package-lock.json — gpl-helpers: GPL-3.0-or-later · lockfile.license · licenses.metadata@1
  • Observed package-lock.json — gpl-helpers@0.4.0 · lockfile.entry · dependencies.parse@1

Fingerprint fp_34cf22e8bc122451 · rule v1

blocking LIC-010

Network copyleft (AGPL-family) licenses in production dependencies

Observed

1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.

Evidence (2)
  • Observed package-lock.json — pdf-render-kit: AGPL-3.0-only · lockfile.license · licenses.metadata@1
  • Observed package-lock.json — pdf-render-kit@2.1.0 · lockfile.entry · dependencies.parse@1

Fingerprint fp_fce4b3f03ecfbedd · rule v1

blocking SEC-001

Credentials in the current code

Observed

Stripe live key in config/.env.production line 1. The value is not reproduced here; fingerprint 792000dea84a3de5.

Evidence (1)
  • Observed config/.env.production:1 — Stripe live key: sk_l… (31 chars) · secret.match · secrets.stripe-live-key@1

Fingerprint fp_7bf5684e91e2c46e · rule v1

blocking SEC-001

Credentials in the current code

Observed

AWS access key ID in src/config.ts line 3. The value is not reproduced here; fingerprint fe916f86aa5d5cca.

Evidence (1)
  • Observed src/config.ts:3 — AWS access key ID: AKIA… (20 chars) · secret.match · secrets.aws-access-key@1

Fingerprint fp_e83b0a535b53e98c · rule v1

material AI-002

Declaration contradicts recorded AI evidence

Conflicting

Declared as written by people (src/billing/**), but 1 matching file(s) carry AI attribution (e.g. src/billing/invoice.ts).

Evidence (2)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_235bc8dcb4afa396 · rule v1

material AI-003

Attribution sources disagree

Conflicting

Attribution records for src/ai/summarize.ts at 58d65e3e4738 disagree on 10 line(s): one source says AI, another says human.

Evidence (2)
  • Observed direct src/ai/summarize.ts @ 58d65e3e4738 — git-ai authorship/3.0.0 · provenance.git_ai_note · ai.git_ai_note@1
  • Company-asserted direct src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1

Fingerprint fp_4427a89bf2492389 · rule v1

material AI-005

AI-attributed changes without review evidence

Derived

4 of 5 commit(s) carrying AI attribution landed without a pull request or merge (pushed directly to the analysed branch), so there is no record of review.

Evidence (4)
  • Observed direct commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_0303827158ddeaf2 · rule v1

material AI-008

AI tool terms not declared

Observed

Evidence shows use of aider, cursor, github-copilot but the plan tier, IP indemnity and output-filter settings in force were not declared. Indemnities typically depend on paid commercial tiers and specific settings.

Evidence (0)

No item-level evidence: this finding is derived from counts or configuration described in its summary.

Fingerprint fp_fc8d772c0a87b8b6 · rule v1

material AI-011

Files predominantly attributed to AI with no recorded human authorship

Derived

1 file(s) have line-level records attributing at least 80% of their current lines to AI tools and none to a named person (e.g. src/search/index.ts). This is a statement about the records, not a legal conclusion on authorship.

Evidence (2)
  • Company-asserted direct src/search/index.ts @ d0bc1462d623 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
  • Observed direct commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_7a90a7c416a2bc5a · rule v1

material AI-012

Model weights or binary model artifacts committed

Observed

1 model artifact(s) are committed (e.g. models/churn.onnx). Their training data, license and origin cannot be established from the repository.

Evidence (1)
  • Observed models/churn.onnx · file.model_artifact · ai.model_artifact@1

Fingerprint fp_5a168622f9f84716 · rule v1

material AID-001

Product depends on external AI providers

Observed

The product calls external AI services: OpenAI. All direct provider usage found is with OpenAI; its pricing, terms and model deprecations flow straight into the product.

Evidence (2)
  • Observed src/ai/summarize.ts — api.openai.com · code.ai_endpoint · ai_dependency.endpoint@1
  • Observed package-lock.json — openai@4.52.7 · lockfile.entry · dependencies.parse@1

Fingerprint fp_3c7b083acc6dda3e · rule v1

material EVQ-002

Declarations older than the code they describe

Stale

The origin declaration for src/billing/** is dated 2024-06-30; 1 matching file(s) changed after that date (e.g. src/billing/invoice.ts).

Evidence (1)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1

Fingerprint fp_8385f0edbc45e3ed · rule v1

material LIC-012

Source-available or restrictive licenses in production dependencies

Observed

1 production dependency is under source-available or use-restricted licenses: graph-weaver@1.3.2 (BUSL-1.1).

Evidence (2)
  • Observed package-lock.json — graph-weaver: BUSL-1.1 · lockfile.license · licenses.metadata@1
  • Observed package-lock.json — graph-weaver@1.3.2 · lockfile.entry · dependencies.parse@1

Fingerprint fp_214aca74a57ed063 · rule v1

material LIC-013

Production dependencies with unknown licenses

Derived

4 of 13 production dependencies have no license information in the analysed sources (e.g. numpy, scikit-learn, loadash, vendor/tinycrypt). Registry lookup was not enabled.

Evidence (4)
  • Observed ml/requirements.txt — scikit-learn@* · manifest.entry · dependencies.parse@1
  • Observed vendor/tinycrypt · vendored.package · dependencies.vendored@1
  • Observed package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1
  • Observed ml/requirements.txt — numpy@>=1.26 · manifest.entry · dependencies.parse@1

Fingerprint fp_52840562c0b3a4d9 · rule v1

material OWN-001

Contributors without a recorded IP agreement

Company-asserted

3 of 5 human contributors (5 commits) have no IP agreement in the supplied register: Chris Dale <chris.dale@gmail.com> (2), Priya Natarajan <priya@quickdev-agency.com> (2), octodev <4412345+octodev@users.noreply.github.com> (1).

Evidence (1)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1

Fingerprint fp_848bd0d14535075b · rule v1

material OWN-002

Contributions predate the recorded agreement

Company-asserted

1 contributor(s) committed before their recorded agreement date: Ben Kaplan (first commit 2023-09-12, signed 2024-06-01). Confirm the agreements assign prior work.

Evidence (1)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1

Fingerprint fp_a593eae5ced2d520 · rule v1

material OWN-004

Third-party copyright notices in first-party source

Observed

1 copyright notice(s) in first-party source name 1 other holder(s) (GeoCorp Ltd). Files: src/lib/geo.ts.

Evidence (1)
  • Observed src/lib/geo.ts:2 — Copyright 2014 GeoCorp Ltd · file.copyright_notice · thirdparty.copyright@1

Fingerprint fp_17fc8a987437918f · rule v1

material OWN-005

Stack Overflow references in source

Observed

1 reference(s) to Stack Overflow / Stack Exchange posts in 1 source file(s) (e.g. src/utils/retry.ts). Code copied from those posts is licensed CC BY-SA.

Evidence (1)
  • Observed src/utils/retry.ts:2 — https://stackoverflow.com/questions/38213668/promise-retry-design-patterns · file.stackoverflow_reference · thirdparty.stackoverflow@1

Fingerprint fp_3eed04f51fa86ea1 · rule v1

material OWN-007

File-level license identifiers differing from the project

Observed

1 first-party file(s) declare GPL-2.0-only in SPDX headers, differing from the project license (LicenseRef-Proprietary) (e.g. src/lib/parse.ts).

Evidence (1)
  • Observed src/lib/parse.ts:1 — GPL-2.0-only · file.spdx_identifier · licenses.spdx_header@1

Fingerprint fp_2af3ae93590d474a · rule v1

material OWN-011

Vendored code without a license file

Observed

Vendored code at vendor/tinycrypt (1 file) has no license file or license metadata.

Evidence (1)
  • Observed vendor/tinycrypt · vendored.no_license · licenses.vendored@1

Fingerprint fp_1b011aee5339e804 · rule v1

material REP-001

Dependencies declared without a lockfile

Observed

ml/requirements.txt declares 3 PyPI dependencies but no lockfile was found, so the exact versions installed are not recorded.

Evidence (1)
  • Observed ml/requirements.txt · manifest.no_lockfile · reproducibility.lockfile@1

Fingerprint fp_5654644c46289aa6 · rule v1 · PyPI:ml/requirements.txt

material REP-002

Manifest and lockfile disagree

Observed

package-lock.json does not match package.json: 1 declared dependency is missing from the lockfile (zod).

Evidence (1)
  • Observed package-lock.json — zod · lockfile.drift · reproducibility.drift@1

Fingerprint fp_06d9df0faaec4243 · rule v1 · npm:meridian-platform

material REP-004

Container base images not pinned

Observed

Dockerfile builds from node:latest, which changes whenever the publisher pushes.

Evidence (1)
  • Observed Dockerfile:1 — node:latest · container.base_image · reproducibility.docker@1

Fingerprint fp_88f9ec93f685af6b · rule v1

material REP-008

Executable binaries committed

Observed

1 executable, library, bytecode or archive file(s) are committed (e.g. bin/legacy-export.exe). Their contents and origin cannot be established from the repository.

Evidence (1)
  • Observed bin/legacy-export.exe — executable · file.binary · inventory.binary@1

Fingerprint fp_f342a06d1f7bfe4b · rule v1

material SEC-001

Credentials in the current code

Inferred

Database URL with password in config/.env.production line 2. The value is not reproduced here; fingerprint 76e6e0674be3dec6.

Evidence (1)
  • Inferred config/.env.production:2 — Database URL with password: Pr0d… (13 chars) · secret.match · secrets.database-url@1

Fingerprint fp_70d6a433b2f745ae · rule v1

material SEC-002

Credentials in git history

Observed

GitHub token existed in an earlier version of scripts/deploy.sh and is no longer in the current code. It remains retrievable from history; confirm it was rotated. Fingerprint 1a1d9910c24f9461.

Evidence (1)
  • Observed scripts/deploy.sh — GitHub token: ghp_… (40 chars) · secret.history_match · secrets.github-token@1

Fingerprint fp_a7b365ab1b120a82 · rule v1

material SEC-003

Environment files committed

Observed

Environment file config/.env.production is committed.

Evidence (1)
  • Observed config/.env.production · file.env · secrets.env_file@1

Fingerprint fp_17c7fe8a363a1614 · rule v1

material SEC-020

CI workflow runs untrusted pull request code with privileges

Observed

.github/workflows/ci.yml is triggered by pull_request_target and checks out pull request code, which then runs with repository secrets and a write token.

Evidence (1)
  • Observed .github/workflows/ci.yml:12 — pull_request_target + checkout of PR head · ci.pr_target_checkout · ci.github_actions@1

Fingerprint fp_07ce8a28034ed08f · rule v1

material SEC-021

CI script injection from untrusted input

Observed

.github/workflows/ci.yml interpolates github.event.pull_request.title into a shell command; an attacker who controls that text can run commands in the pipeline.

Evidence (1)
  • Observed .github/workflows/ci.yml:16 — ${{ github.event.pull_request.title }} · ci.script_injection · ci.github_actions@1

Fingerprint fp_f961f0e04a7182e1 · rule v1

material SEC-031

Dependencies fetched over plain HTTP

Observed

1 dependency is fetched over plain HTTP (meridian-auth).

Evidence (1)
  • Observed package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1

Fingerprint fp_78492bcdb01ea061 · rule v1

material SEC-033

Possible dependency confusion

Inferred

1 unscoped package(s) resolve from a private registry (meridian-auth). If the same names are claimed on the public registry, a misconfigured install can fetch the public package instead.

Evidence (1)
  • Observed package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1

Fingerprint fp_19cf85222bcfbde1 · rule v1

material SEC-033

Possible dependency confusion

Observed

ml/requirements.txt adds a private index with --extra-index-url. pip considers every index and installs the highest version, so a public package with the same name as a private one can be installed instead.

Evidence (1)
  • Observed ml/requirements.txt — --extra-index-url https://pypi.meridian.internal/simple · config.extra_index_url · supplychain.extra_index@1

Fingerprint fp_dcfba87d00eeeb25 · rule v1

material SEC-034

Dependency names resembling popular packages

Inferred

1 direct dependency has a name one character away from a popular package (loadash). Confirm they are the intended packages.

Evidence (1)
  • Observed package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1

Fingerprint fp_9f36f7280727811f · rule v1

minor AI-004

Attribution records that cannot be checked

Unverifiable

2 attribution record(s) could not be checked against the repository (unknown revision, missing file or out-of-range lines) and carry no weight.

Evidence (2)
  • Unverifiable direct src/billing/tax.ts @ deadbeefdead — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
  • Unverifiable direct src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1

Fingerprint fp_2a7f642e89f66a95 · rule v1

minor AI-006

Large unattributed changes after AI tools were adopted

Inferred

Commit 81de5601f559 ("Add reporting module") added 950 lines across 10 files with no AI attribution, after AI tool configuration first appeared (2024-07-01). This is an inference, not evidence of AI origin; ask how it was produced.

Evidence (1)
  • Inferred inference commit 81de5601f559 — Add reporting module · commit.bulk_unattributed · ai.bulk_unattributed@1

Fingerprint fp_26573072b1008fc6 · rule v1

minor AID-002

Hard-coded model identifiers

Observed

1 model identifier(s) are hard-coded (gpt-4o-2024-08-06). Providers retire model versions on their own schedule.

Evidence (1)
  • Observed src/ai/summarize.ts — gpt-4o-2024-08-06 · code.model_id · ai_dependency.model_id@1

Fingerprint fp_0ec97258e4f8bf6b · rule v1

minor MNT-002

Few or no tests

Derived

1 test file(s) for 25 source files (4%).

Evidence (0)

No item-level evidence: this finding is derived from counts or configuration described in its summary.

Fingerprint fp_fe72c0e0b81ff642 · rule v1

minor OWN-006

Comments stating code was copied or adapted from a URL

Observed

1 comment(s) say code was copied or adapted from an external URL (e.g. src/lib/parse.ts).

Evidence (1)
  • Observed src/lib/parse.ts:2 — Adapted from https://github.com/example/csv-lite/blob/main/parse.c · file.copied_from · thirdparty.copied_from@1

Fingerprint fp_b8c966ddde259430 · rule v1

minor REP-004

Container base images not pinned

Observed

Dockerfile builds from python:3.12-slim, pinned by tag but not by digest.

Evidence (1)
  • Observed Dockerfile:5 — python:3.12-slim · container.base_image · reproducibility.docker@1

Fingerprint fp_78d21b97267087c1 · rule v1

minor REP-006

Toolchain versions not pinned

Observed

Toolchain versions are not pinned for: Python (no .python-version or requires-python).

Evidence (0)

No item-level evidence: this finding is derived from counts or configuration described in its summary.

Fingerprint fp_1bb866e7d816d9ad · rule v1

minor REP-007

Build outputs committed to the repository

Observed

Build output directories are committed: dist. Committed artifacts may not correspond to the committed source.

Evidence (1)
  • Observed dist · repo.build_output · inventory.build_output@1

Fingerprint fp_c8eeabe6abdf320f · rule v1

minor SEC-022

Third-party CI actions not pinned to a commit

Observed

1 third-party action reference(s) are pinned to a tag or branch rather than a commit SHA (some-org/deploy-action@v2).

Evidence (1)
  • Observed .github/workflows/ci.yml:13 — some-org/deploy-action@v2 · ci.unpinned_action · ci.github_actions@1

Fingerprint fp_d8daffb1bdf1155b · rule v1

minor SEC-023

Pipelines pipe remote scripts to a shell

Observed

1 pipeline or container file(s) pipe a downloaded script into a shell (.github/workflows/ci.yml).

Evidence (1)
  • Observed .github/workflows/ci.yml:17 — curl -sL https://get.example-cdn.io/setup.sh | bash · ci.pipe_to_shell · ci.pipe_to_shell@1

Fingerprint fp_13a446ca9cf1aa3c · rule v1

minor SEC-024

CI token granted write-all permissions

Observed

.github/workflows/ci.yml grants the workflow token write-all permissions.

Evidence (0)

No item-level evidence: this finding is derived from counts or configuration described in its summary.

Fingerprint fp_0d06f7a88cd76b4a · rule v1

minor SEC-030

Production dependencies run install scripts

Observed

1 production dependency runs install scripts (bcrypt@5.1.1).

Evidence (1)
  • Observed package-lock.json — bcrypt@5.1.1 · lockfile.entry · dependencies.parse@1

Fingerprint fp_6e7faed0bb6fb3dd · rule v1

info AI-001

AI coding tools used in this repository

Observed

Evidence of 5 AI coding tool(s): aider (1 attributed commit); chatgpt (file-comment); claude-code (2 attributed commits); cursor (2 attributed commits); github-copilot (1 attributed commit).

Evidence (5)
  • Observed direct commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1
  • Observed direct commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1

Fingerprint fp_f76e52d6f06c1478 · rule v1

Suppressed by the company

minor SEC-001

Credential-like value in test or example code

Inferredsuppressed by company

Hard-coded credential in test/billing.test.ts line 3 (test, example or placeholder value; confirm it is not live). The value is not reproduced here; fingerprint 1c26c5513f77abea.

Suppression reason (company-asserted): Test-only password used by the billing unit test; not a real credential. — security@meridian.io

Evidence (1)
  • Inferred test/billing.test.ts:3 — Hard-coded credential: test… (17 chars) · secret.match · secrets.generic-secret@1

Fingerprint fp_8a5d3f0986dc1ede · rule v1