AcquiCode diligence

Technical diligence dossier

Meridian Systems (synthetic demo company)

Subject
meridian-systems/meridian-platform @ 5df5415bdef5
Produced by
acquicode-engine 0.1.0, rules 2026.09.1
Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655
Reproduce
The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.

Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.

BLOCKED

4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.

  • Strong copyleft (GPL-family) licenses in production dependencies
  • Network copyleft (AGPL-family) licenses in production dependencies
  • Credentials in the current code (2)

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

4blocking
29material
12minor
1info
5material unknowns
How every claim is graded

Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.

Verified
Observed and independently checked
Observed
Read directly from the repository or a named source
Derived
Computed deterministically from observed facts
Company-asserted
Stated by the company; not proof
Inferred
Heuristic reading; raises questions, never blocks
Conflicting
Sources disagree
Unknown
No evidence either way

History: 19 commits from 2023-02-01 to 2025-04-10. Agreement data comes from the company-supplied register.

ContributorIdentitiesClassCommitsActiveAgreement
Ben Kaplanben@meridian.ioorg domain Company-asserted72023-09-12 – 2025-04-02employee piia (2024-06-01) Company-asserted
Ana Ortizana@meridian.ioorg domain Company-asserted62023-02-01 – 2025-04-10founder assignment (2023-01-15) Company-asserted
Priya Natarajanpriya@quickdev-agency.comexternal domain Derived22024-10-01 – 2025-01-08Unknown
Chris Dalechris.dale@gmail.compersonal email Observed22024-02-03 – 2025-03-01none Company-asserted
Copilot198982749+copilot@users.noreply.github.comai agent Observed12024-09-05 – 2024-09-05Unknown
octodev4412345+octodev@users.noreply.github.comforge noreply Observed12025-02-14 – 2025-02-14Unknown
material AI-012

Model weights or binary model artifacts committed

Observed

1 model artifact(s) are committed (e.g. models/churn.onnx). Their training data, license and origin cannot be established from the repository.

Evidence (1)
  • Observed models/churn.onnx · file.model_artifact · ai.model_artifact@1

Fingerprint fp_5a168622f9f84716 · rule v1

material OWN-001

Contributors without a recorded IP agreement

Company-asserted

3 of 5 human contributors (5 commits) have no IP agreement in the supplied register: Chris Dale <chris.dale@gmail.com> (2), Priya Natarajan <priya@quickdev-agency.com> (2), octodev <4412345+octodev@users.noreply.github.com> (1).

Evidence (1)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1

Fingerprint fp_848bd0d14535075b · rule v1

material OWN-002

Contributions predate the recorded agreement

Company-asserted

1 contributor(s) committed before their recorded agreement date: Ben Kaplan (first commit 2023-09-12, signed 2024-06-01). Confirm the agreements assign prior work.

Evidence (1)
  • Company-asserted meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1

Fingerprint fp_a593eae5ced2d520 · rule v1

material OWN-004

Third-party copyright notices in first-party source

Observed

1 copyright notice(s) in first-party source name 1 other holder(s) (GeoCorp Ltd). Files: src/lib/geo.ts.

Evidence (1)
  • Observed src/lib/geo.ts:2 — Copyright 2014 GeoCorp Ltd · file.copyright_notice · thirdparty.copyright@1

Fingerprint fp_17fc8a987437918f · rule v1

material OWN-005

Stack Overflow references in source

Observed

1 reference(s) to Stack Overflow / Stack Exchange posts in 1 source file(s) (e.g. src/utils/retry.ts). Code copied from those posts is licensed CC BY-SA.

Evidence (1)
  • Observed src/utils/retry.ts:2 — https://stackoverflow.com/questions/38213668/promise-retry-design-patterns · file.stackoverflow_reference · thirdparty.stackoverflow@1

Fingerprint fp_3eed04f51fa86ea1 · rule v1

material OWN-007

File-level license identifiers differing from the project

Observed

1 first-party file(s) declare GPL-2.0-only in SPDX headers, differing from the project license (LicenseRef-Proprietary) (e.g. src/lib/parse.ts).

Evidence (1)
  • Observed src/lib/parse.ts:1 — GPL-2.0-only · file.spdx_identifier · licenses.spdx_header@1

Fingerprint fp_2af3ae93590d474a · rule v1

minor OWN-006

Comments stating code was copied or adapted from a URL

Observed

1 comment(s) say code was copied or adapted from an external URL (e.g. src/lib/parse.ts).

Evidence (1)
  • Observed src/lib/parse.ts:2 — Adapted from https://github.com/example/csv-lite/blob/main/parse.c · file.copied_from · thirdparty.copied_from@1

Fingerprint fp_b8c966ddde259430 · rule v1