AcquiCode diligence

Technical diligence dossier

Meridian Systems (synthetic demo company)

Subject
meridian-systems/meridian-platform @ 5df5415bdef5
Produced by
acquicode-engine 0.1.0, rules 2026.09.1
Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655
Reproduce
The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.

Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.

BLOCKED

4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.

  • Strong copyleft (GPL-family) licenses in production dependencies
  • Network copyleft (AGPL-family) licenses in production dependencies
  • Credentials in the current code (2)

The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.

4blocking
29material
12minor
1info
5material unknowns
How every claim is graded

Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.

Verified
Observed and independently checked
Observed
Read directly from the repository or a named source
Derived
Computed deterministically from observed facts
Company-asserted
Stated by the company; not proof
Inferred
Heuristic reading; raises questions, never blocks
Conflicting
Sources disagree
Unknown
No evidence either way
QuestionStatusEvidenceBasis
Q-OWN-1 Can the company show who wrote the code and that it holds the rights to it?AttentionCompany-asserted5 people committed code. Contributors without a recorded IP agreement; Contributions predate the recorded agreement.
Q-OWN-2 Does the first-party code contain code owned or licensed by someone else?AttentionObserved1 copyright notice(s) in first-party source name 1 other holder(s) (GeoCorp Ltd) 1 reference(s) to Stack Overflow / Stack Exchange posts in 1 source file(s) (e.g 1 first-party file(s) declare GPL-2.0-only in SPDX headers, differing from the project license (LicenseRef-Proprietary) (e.g Vendored code at vendor/tinycrypt (1 file) has no license file or license metadata. 1 comment(s) say code was copied or adapted from an external URL (e.g.
Q-PROV-1 Can the origin of the code be established from the repository?AttentionObservedModel weights or binary model artifacts committed; Executable binaries committed.
Q-AI-1 What evidence exists of AI involvement in the code, and is it consistent?AttentionConflictingEvidence and declarations conflict. 2 file(s) with line-level attribution, 4 changed in AI-attributed commits, 0 with corroborating evidence only (self-declared comments or editor-inserted trailers), 10 flagged by inference only, 10 with no evidence either way (of 26).
Q-AI-2 Were AI-attributed changes reviewed by a person other than the author?AttentionDerived4 of 5 commit(s) carrying AI attribution landed without a pull request or merge (pushed directly to the analysed branch), so there is no record of review.
Q-AI-3 Were the AI tools used under terms that protect the company?AttentionObservedEvidence shows use of aider, cursor, github-copilot but the plan tier, IP indemnity and output-filter settings in force were not declared. Indemnities typically depend on paid commercial tiers and specific settings.
Q-LIC-1 Is the license of the company's own code clear?SatisfiedObservedThe project license is LicenseRef-Proprietary (known, from manifest).
Q-LIC-2 Are the licenses of production dependencies known?AttentionDerived4 of 13 production dependencies have no license information; 0 are likely (inferred).
Q-LIC-3 Do production dependencies carry copyleft or use-restricting licenses?BlockingObserved1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review. 1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.
Q-SEC-1 Are credentials exposed in the code or its history?BlockingObserved2 credentials in a provider format are present in the current code.
Q-SEC-2 Are known vulnerabilities in production dependencies understood?UnknownUnknown2 public dependencies have no exact version (no lockfile pins them), so known vulnerabilities cannot be checked.
Q-SEC-3 Are the build pipeline and supply chain protected against tampering?AttentionObservedCI workflow runs untrusted pull request code with privileges; CI script injection from untrusted input; Dependencies fetched over plain HTTP; Possible dependency confusion; Possible dependency confusion; Dependency names resembling popular packages.
Q-REP-1 Are the inputs needed to rebuild the software fully declared?AttentionObservedDependencies declared without a lockfile; Manifest and lockfile disagree; Container base images not pinned; Executable binaries committed.
Q-MNT-1 Can a new owner maintain the software?SatisfiedDerivedMinor items: Few or no tests.
Q-AID-1 Is the product materially dependent on specific AI providers?AttentionObservedThe product calls external AI services: OpenAI. All direct provider usage found is with OpenAI; its pricing, terms and model deprecations flow straight into the product. 1 model identifier(s) are hard-coded (gpt-4o-2024-08-06). Providers retire model versions on their own schedule.
Q-EVQ-1 Which important claims rest on weak, stale or conflicting evidence?AttentionStale8 findings rest on inferred, company-asserted, stale or conflicting evidence; 5 material unknowns remain.

For management

  1. Origin and license of 1 committed binary file(s) is unknown. Provide the source or vendor/license information for each binary, or remove them. (Q-PROV-1)
  2. Reconcile the AI usage declaration with the recorded evidence and correct the disclosure. (Q-AI-1)
  3. Explain how the large unattributed changes listed were produced. (Q-AI-1)
  4. Confirm the AI coding tools used, the accounts and plans they were used under, and the period of use. (Q-AI-1)
  5. Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters) is unknown. Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it. (Q-AI-1)
  6. Whether pull requests containing AI-attributed changes were approved by another person is unknown. Connect the GitHub App or GitLab token, or supply review exports. (Q-AI-1)
  7. Describe the review process for AI-generated changes and provide review records for the listed commits. (Q-AI-2)
  8. Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters) is unknown. Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it. (Q-AI-2)
  9. Whether pull requests containing AI-attributed changes were approved by another person is unknown. Connect the GitHub App or GitLab token, or supply review exports. (Q-AI-2)
  10. Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters) is unknown. Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it. (Q-AI-3)
  11. Whether pull requests containing AI-attributed changes were approved by another person is unknown. Connect the GitHub App or GitLab token, or supply review exports. (Q-AI-3)
  12. Describe the contract terms, pricing exposure and fallback plan for each AI provider the product calls. (Q-AID-1)
  13. Update the origin declarations to cover the code as it is now. (Q-EVQ-1)

For counsel

Technical findings and escalation prompts; not legal advice.

  1. Obtain executed IP assignment agreements, or confirmatory assignments, from each contributor listed without one. (Q-OWN-1)
  2. Confirm that the agreements of contributors who committed before signing assign work created before the signing date. (Q-OWN-1)
  3. Identify the origin and license of the files carrying third-party copyright notices, and whether their obligations are met. (Q-OWN-2)
  4. Assess CC BY-SA attribution and share-alike obligations for the copied snippets. (Q-OWN-2)
  5. Review the files whose SPDX headers declare a license different from the project license. (Q-OWN-2)
  6. Establish the license of each vendored directory that has no license file. (Q-OWN-2)
  7. Document the source, training data and license of each committed model artifact. (Q-PROV-1)
  8. Assess the copyright position of files whose recorded authorship is predominantly AI, and whether human contribution is documented elsewhere. (Q-AI-1)
  9. Provide the terms (plan tier, IP indemnity, output-filter settings) under which each AI tool was used. (Q-AI-3)
  10. Assess obligations under the listed copyleft licenses given how the software is distributed; plan remediation if required. (Q-LIC-3)
  11. Review the source-available licenses listed for restrictions on the company's use. (Q-LIC-3)

For engineering

  1. Identify code copied from the referenced Stack Overflow posts; attribute it under CC BY-SA or rewrite it. (Q-OWN-2)
  2. Identify the source and license of each piece of code marked as copied or adapted from an external URL. (Q-OWN-2)
  3. Provide the source, version and license of each committed binary, or remove it. (Q-PROV-1)
  4. Explain why the attribution records disagree for the listed files and which record is correct. (Q-AI-1)
  5. Explain the attribution records that reference commits, files or lines that do not exist. (Q-AI-1)
  6. Establish licenses for the listed dependencies (run with registry enrichment or provide an SBOM). (Q-LIC-2)
  7. Rotate the exposed credentials, remove them from the code and confirm rotation dates. (Q-SEC-1)
  8. Confirm that the credentials found in history were rotated, with dates. (Q-SEC-1)
  9. Remove committed environment files and rotate any credentials they contained. (Q-SEC-1)
  10. Known vulnerabilities in 2 dependencies without an exact version is unknown. Commit a lockfile and re-run the analysis. (Q-SEC-1)
  11. Known vulnerabilities in 10 dependency version(s) is unknown. Re-run with vulnerability enrichment enabled. (Q-SEC-1)
  12. Known vulnerabilities in 2 dependencies without an exact version is unknown. Commit a lockfile and re-run the analysis. (Q-SEC-2)
  13. Known vulnerabilities in 10 dependency version(s) is unknown. Re-run with vulnerability enrichment enabled. (Q-SEC-2)
  14. Stop running pull request code under pull_request_target, or isolate it from secrets and write tokens. (Q-SEC-3)
  15. Pass untrusted event fields through environment variables instead of interpolating them into run: scripts. (Q-SEC-3)
  16. Fetch all dependencies over HTTPS. (Q-SEC-3)
  17. Scope private packages and configure registries so internal names cannot resolve publicly. (Q-SEC-3)
  18. Confirm that each near-miss dependency name is the intended package. (Q-SEC-3)
  19. Pin third-party actions to full commit SHAs. (Q-SEC-3)
  20. Replace piped remote scripts with pinned, checksummed downloads. (Q-SEC-3)
  21. Set least-privilege permissions on workflow tokens. (Q-SEC-3)
  22. Review the install scripts of the listed production dependencies. (Q-SEC-3)
  23. Known vulnerabilities in 2 dependencies without an exact version is unknown. Commit a lockfile and re-run the analysis. (Q-SEC-3)
  24. Known vulnerabilities in 10 dependency version(s) is unknown. Re-run with vulnerability enrichment enabled. (Q-SEC-3)
  25. Commit a lockfile for each manifest listed. (Q-REP-1)
  26. Regenerate the lockfiles that no longer match their manifests. (Q-REP-1)
  27. Pin container base images by digest. (Q-REP-1)
  28. Provide the source, version and license of each committed binary, or remove it. (Q-REP-1)
  29. Pin runtime and toolchain versions. (Q-REP-1)
  30. Explain why build outputs are committed and how they are kept in sync with source. (Q-REP-1)
  31. Describe how changes are verified in the absence of automated tests. (Q-MNT-1)
  32. Describe how the product migrates when pinned model versions are retired. (Q-AID-1)
  33. Explain the attribution records that reference commits, files or lines that do not exist. (Q-EVQ-1)