MERIDIAN
FORENSIC · INTELLIGENCE · DISCLOSURE

Every crime leaves a data trail. Meridian turns seized devices into evidence a court can trust — and follows the trail from the first text message to the final verdict.

SCROLL TO BEGIN
01 — The offer

A deal struck
in the dark

Two phones. A procurement tender worth millions. A price agreed in a handful of messages nobody was ever meant to read.

02 — The award

They won
the contract

The tender is awarded. On paper, a clean procurement. Underneath, a kickback already moving through a relative's account.

03 — The investigation opens

The devices
come in

A whistle-blower. A warrant. The suspects' phones are seized and forensically imaged. Two drives land on the analyst's bench — millions of artefacts, and a chain of custody that must hold.

04 — Meridian at work

From evidence
to exhibit

Scroll through the pipeline. The analyst never leaves one workspace.

STEP 01
Forensic ingest
Mount UFDR & E01 images. Every artefact hashed and verified on the way in.
STEP 02
E-discovery review
Chats, calls, email and files — one searchable, taggable review surface.
STEP 03
Timeline
Every dated artefact snaps onto a single reconstructable spine.
STEP 04
Link analysis
People, accounts and companies resolve into a network you can read.
STEP 05
Red-flag detectors
Typologies surface patterns for the investigator — never a verdict.
STEP 06
Court-ready output
Exhibit packs, GraphML, goAML XML and a s212 affidavit — reproducible.
Deterministic. Non-predictive. Meridian narrates and suggests — the investigator decides. Every step re-runs to the same result, so it holds up under cross-examination.
MERIDIAN — MATTER 0447LIVE

Forensic ingest — verifying images

Extract UFDR
Extract E01
SHA-256 verify
DEVICE_A · sha256 9f2a…c471 MATCH
DEVICE_B · sha256 1c88…a0e3 MATCH
1,284,905 artefacts indexed · chain of custody intact

E-discovery review — 4 of 1.2M flagged

SMS · Device A → Device BKickback
"15% once the award letter is signed. Cousin's account."
SMS · Device B → Device AConcealment
"Done. Delete this."
EMAIL · procurement@…Award letter
Re: Tender 0447 — Notice of Award (PDF attached)
DOC · bank_transfer.pdfFinancial
EFT — R 2,400,000 → acc. ****8831

Timeline — reconstructed sequence

SMS: offer
Mar 3
Panel scores
Mar 6
Award letter
Mar 11
EFT R2.4m
Mar 14

Offer → award → payment, in eleven days. The sequence is the story.

Link analysis — the network draws itself

Red-flag detectors — patterns surfaced

Kickback / bribery languageHIGH
Undisclosed conflict of interestHIGH
Shell-company layeringMED
Payment timed to awardMED
Evidence-destruction intentHIGH

Court-ready output — one click

Forensic Report — Matter 0447
Exhibit Pack PNG · SVG GraphML → i2 / yEd goAML XML s212 Affidavit Rule Ledger
05 — The exhibit

Entered
into evidence

The Meridian report goes before the court — reproducible, hash-verified, cross-examination-proof. The sequence speaks for itself. The gavel comes down.

Keep scrolling — the ruling lands.
06 — The verdict
Guilty

Evidence became an exhibit. The exhibit became a conviction. That is the whole point of Meridian.

MERIDIAN — FROM EVIDENCE TO EXHIBIT
Meridian
Forensic Investigator
Case FileFinancial Crime / Africa
DeploymentOn-device · Air-gapped
StatusBy demonstration · v2.3
Financial Crime Investigation Software — Built for Africa

Map the Money.
Expose the Network.

MERIDIAN turns months of investigation into a court-ready case file — without sending a single document to the cloud.

Cash-flow network — illustrative
The Gap
Investigators draw link diagrams in PowerPoint, manually transcribe bank statements into Excel, and spend weeks producing reports a prosecutor struggles to use.
The Fix
MERIDIAN does all of it — from raw bank statement to prosecution narrative — entirely on your device, with no data leaving your machine.
22
Investigation panels
22
Demo case files
8
Jurisdictions covered
0
Data leaves your device
The Situation

The first hour
decides the rest.

Every investigator has heard it: show me the evidence. Proof beyond reasonable doubt is what a court demands.

But evidence on its own rarely carries a case. Whoever you hand it to — a prosecutor weighing whether to run with it, a magistrate, an arbitrator, a disciplinary panel — forms their first, strongest impression early. First impressions are hard to undo. A case that lands clearly and convincingly from the outset builds momentum; one that opens in confusion spends the rest of its life fighting uphill.

So the real task of a white-collar investigation isn't only gathering the evidence. It's making the scheme land — clearly and persuasively — from the very first read. Complexity is the fraudster's best defence: the layers, the shells, the cross-border hops exist to make a scheme too tangled to follow. Your job is to cut through that fog before it costs you the room.

MERIDIAN was built to help you win that first hour — to turn what you've uncovered into a case that's clear, credible, and easy to follow from the moment someone opens it.

01
The bank statement problem
You receive 14 months of FNB statements for 3 accounts. Manually transcribing every transaction to identify counterparties takes 2–3 days. You haven't even started the analysis yet.
02
The diagram problem
Your network diagram lives in PowerPoint. It can't show cash flow amounts. It can't be filtered. It doesn't know which entities are PEPs. It has no legal significance.
03
The report problem
You need a court-admissible report with entity registers, cash flow tables, evidentiary sources, and a prosecution narrative. Writing that from scratch takes a week. Every time.
04
The cloud problem
Your case data cannot leave your device. Client privilege. POPIA. Professional obligation. Every cloud-based tool you've looked at asks you to upload your evidence to their servers.
05
The software problem
The link-analysis and case tools that do exist are built for Western agencies, priced for banks, and blind to African legislation, banks, and schemes. You end up bending your investigation to fit the software, instead of the other way around.
The Workflow

From raw data
to court file.

Five steps. One tool. Everything stays on your machine.

01
Import
Upload your bank statements
Drop in a CSV bank-statement export. MERIDIAN is built to detect the format and build the cash-flow network automatically. Tuned first for major South African banks, with more being added — part of what hands-on testing will refine. Or start from a seized disk image: the Discovery workspace ingests an E01 forensic image and promotes its evidence straight into the case.
02
Map
Build your entity network
Add people, companies, shell co's, bank accounts, properties, SOEs. Classify PEPs per FICA. Mark risk levels. Link everything. The canvas is built to handle dozens of entities — test it with the scale of your real cases.
03
Enrich
Run OSINT intelligence
Integrated lookups via OpenCorporates, Maigret, and Holehe, run from the OSINT tab. Every query is logged in the audit trail and staged for your approval before it touches the canvas. These integrations are new — testing how they hold up on real cases is exactly what hands-on testing is for.
04
Analyse
Automated detection
Pattern detection is built to surface structuring, round-tripping, and layering, with a library of typologies and a rule-based red-flag scanner mapped to FICA, POCA, and FATF. Designed to help identify the organiser — tell us where it misses on your cases.
05
Export
Generate the court file
Judge-ready report, court exhibit bundle, prosecution narrative, and register exports — generated from the case file. The goal: a document your prosecutor can read cold and understand. Some export formats are more mature than others; practitioner feedback tells us which need work.
What Changes

What you produce
at the end of a case.

Not features. Outputs that matter to prosecutors, regulators, and courts.

RPT
A report a judge can read without training

The Judge-Ready Report is built to present plain language, portrait entity cards, and a narrative structure — not a technical network diagram — so a magistrate or arbitrator can follow the scheme. Tell us how it reads on your matters.

NAR
A prosecution brief written by AI, reviewed by you

MERIDIAN's AI is designed to read your full case graph and draft a structured prosecution narrative — scheme overview, key actors, money trail, legislation, red flags, investigative priorities. Runs locally via Ollama on your own machine; no cloud. (Requires a local Ollama install.)

GAP
A clear picture of what you're still missing

Evidence Gap Analysis is built to flag the weakest links in your prosecution chain before you hand the file over, with a prosecution-readiness rating. A newer feature — we want your view on whether its judgement matches yours.

OSI
A digital footprint built in minutes

The OSINT tab integrates company-record, username, and email-registration lookups, with every result reviewed and approved before it appears on the canvas. These integrations are new and depend on third-party services — real-world testing is what hands-on testing is for.

NET
A network built from bank statements in minutes

Drop in a CSV bank-statement export and MERIDIAN is built to parse the transactions, identify counterparties, and build the cash-flow network — turning days of manual transcription into minutes. Bank-format coverage is still expanding; bring your own and tell us what parses.

SEC
A case file that never left your machine

AES-256-GCM encryption on save files. No cloud. No telemetry. OSINT queries are investigator-initiated and logged; AI inference runs locally via Ollama. The architecture is built so your evidence stays under legal professional privilege — and we welcome scrutiny of it.

Capabilities

Every tool an investigator needs.
Nothing they don't.

Built specifically for financial crime investigation in Africa. Not adapted. Built.

E01
New in v2.3
Discovery — investigate straight off a seized disk image

Open a forensic disk image (E01/EWF) read-only, verify its integrity against the acquisition hash, and catalogue what's inside — the documents, spreadsheets, and messages a case actually turns on. Full-text search reads inside PDF, Word, and Excel; the source is never written to, and restricted material is screened and sealed rather than opened. Promote the artefacts that matter into your case with provenance and chain of custody intact — an unbroken line from the seized disk to the charge sheet, all on your own machine.

01
Ingest & Verify
Read-only ingestion of E01/EWF forensic images, with integrity verification against the stored acquisition hash. The source disk is never written to — evidentiary soundness by design.
02
Catalogue & Search
An encrypted catalogue of every file, with full-text search that reads inside PDF, Word, and Excel. Documents and media are reviewed as text and metadata — never auto-rendered — with restricted content screened and sealed.
03
Review & Promote
Promote the artefacts that matter into the case as evidence, carrying provenance, source, and chain of custody. Discovery feeds the same graph, red-flag engine, and court file as the rest of MERIDIAN.
OSI
Investigator-controlled enrichment
OSINT Intelligence — investigator-controlled enrichment

Three integrated intelligence tools accessible directly from the OSINT sidebar tab. All queries are investigator-initiated, explicitly logged in the case audit trail, and route through the Electron main process — never the renderer. Investigation data never leaves your device. Results land in a staging area for your review and approval before anything touches the canvas.

OC
OpenCorporates
Search 200M+ company records across 140+ jurisdictions. Returns directors, registration status, and related entities. You must supply your own OpenCorporates API key. MERIDIAN does not provide, resell, or proxy OpenCorporates access — you connect your personal API token, and your key and your queries never pass through MERIDIAN servers.
MG
Maigret
Search a username across 3,000+ platforms simultaneously. Recursive — follows linked usernames automatically. Requires local Python installation.
HL
Holehe
Check if an email address is registered on 120+ platforms. Uses public registration flows — no passwords. Requires local Python installation.
E01
Forensic Image Discovery (E01)

Ingest a seized disk image (E01/EWF) read-only, verify it against the acquisition hash, and catalogue what's inside. Full-text search reads inside PDF, Word, and Excel; documents and media are reviewed as text and metadata only, never auto-rendered, with restricted content screened and sealed. Promote the artefacts that matter into the case with provenance and chain of custody intact. The newest workspace — real cases are where we prove it against real images.

New
CHN
Crypto Transaction Analysis

Import on-chain and exchange transactions and model wallets and exchanges as first-class entities on the canvas. Screen addresses against operator-supplied flagged lists (sanctions, mixers, known scams) and cluster wallets with an explainable common-input heuristic. Deterministic and offline — operator-supplied data, not a proprietary cloud dataset, and not attribution. Tell us which chains and exports matter in your work.

New
CSV
Bank Statement Parser

Built to import CSV bank-statement exports and auto-detect the format, extract and deduplicate counterparties, and render the cash-flow network on the canvas. Tuned first for major South African banks (ABSA, FNB, Standard Bank, Nedbank, Capitec); other African banks are being added. Bring your own statements and tell us what parses and what doesn't — this is exactly the kind of thing practitioner feedback shapes.

Core
NET
Financial Network Canvas

A range of node and relationship types with full metadata (amounts, dates, confidence, reference numbers). PEP/PIP classification per FICA Schedule 3A, 3B, 3C. AES-256-GCM encrypted save files. Undo/redo. PNG and SVG export. Built and ready to test against the demands of a real case.

Core
NAR
Prosecution Narrative Generator

Designed to read the full case graph and draft a multi-section prosecution brief — scheme overview, key actors, money trail, legislative framework, red flags, investigative priorities — using your entity names, amounts, and jurisdictions. You edit and approve before use. Runs locally via Ollama on your own machine; no cloud. (Requires a local Ollama install.)

AI
OSI
OSINT Intelligence Tab

OpenCorporates company lookup, Maigret username search, and Holehe email-registration check, accessible from the OSINT sidebar panel. Staged approval workflow: nothing touches the canvas without investigator review, and every query is logged in the case audit trail — designed to be defensible in court or disciplinary proceedings. These integrations are new; real cases are where we confirm they hold up.

OSINT
RPT
Judge-Ready Report + Executive Summary

Two distinct outputs from the same investigation data: a full technical report for prosecutors and regulators (entity cards, relationship narrative, cash-flow tables, red flags, source register, exhibit register, certification) and a short executive summary for clients and boards — generated from the EXPORT menu. Export formats vary in maturity; practitioner feedback tells us which need polish.

New
CoC
Evidence Chain Tracker

Built to track full chain of custody per exhibit — collection, transfer, storage, court — across exhibit types including original documents, certified copies, digital extracts, photographs, devices, affidavits, and witness statements. Admissibility flags, gap detection, and an exhibit register in court reports. A newer module we want stress-tested on real evidence trails.

New
TYP
Typology Intelligence Library

A built-in library of financial-crime typologies — structuring, layering, mule and funnel accounts, circular transactions, shell-company activity, TBML, crypto layering, real-estate laundering, PEP misuse, beneficial-ownership concealment, invoice and procurement fraud, SOE corruption, hawala, loan-back schemes, casino ML, NPO misuse, and more — each with red-flag indicators and relevant legislation. Tell us which typologies matter most in your work.

New
FLG
Automated Red Flag Scanner

A deterministic, rule-based scanner — explainable, no black-box AI — with checks mapped to FICA, POCA, PRECCA, PFMA, and FATF recommendations: PEP cash flows, SOE leakage, cross-border structuring, round-trip flows, beneficial-ownership concealment. Each flag is built to carry the specific section reference for STR submission. Help us test the rules against real matters.

Core
PRO
Source & Witness Concealment

Node-level concealment flag — one click in the Properties panel. Concealed nodes display as [PROTECTED A], [PROTECTED B] in all report outputs. Deterministic identifier: same node always gets the same letter across every report section. Every concealment change is logged in the case audit trail.

New
CEN
Network Centrality — Find the Organiser

Degree, betweenness (Brandes algorithm), and eigenvector centrality. The node with the highest betweenness score is your broker — the organiser who controls information and money flow. This is the entity investigations typically need to prioritise for asset preservation and arrest sequencing.

Core
MRG
Multi-Investigator File Merge

Two investigators work separate parts of the same case. Merge their .meridian files: entities with similar names are automatically matched, edges are rewired, conflicts are flagged. New cross-investigation connections — the ones neither investigator knew about — are highlighted immediately.

New
Built-In Case Library

22 real cases.
Ready to load.

Pre-built investigation files drawn from public record — so you can learn the tool on real schemes, demonstrate to clients, and use them as teaching material. Loaded in the app for you to explore.

R1.9bn
VBS Mutual Bank
Municipal deposit fraud. Matodzi, Mukhodobwane, and the looting of ordinary depositors. Reference: Terry Motau SC report.
USD 600M+
Goldenberg — Kenya
Fictitious gold and diamond export-compensation fraud. Kamlesh Pattni and senior officials. Estimated 10% of GDP. Reference: Bosire Commission of Inquiry.
USD 4.5bn
1MDB — Malaysia
Largest sovereign fund fraud in history. Najib Razak, Jho Low, Goldman Sachs. 10 jurisdictions. Reference: US DOJ.
R200bn+
Steinhoff International
Accounting fraud. Fictitious €6.5bn income. Markus Jooste. Offshore shell structures. Reference: PwC forensic report.
SOEs
State Capture
Eskom, Transnet, Trillian, McKinsey. Illustrative map based on Zondo Commission public record.
USD 1.7bn
Sanjay Shah — Cum-Ex
Largest Danish financial crime. Danish dividend tax fraud from Dubai. 12-year sentence December 2024.
USD 10m+
Fishrot Scandal
Namibia. Samherji fishing quota bribes. Two Cabinet ministers. WikiLeaks disclosure. 26 charged.
+15 more
Africa & Global
Zimbabwe Gold Mafia, Equity Bank insider fraud, Botswana NPF, and more across 8 African jurisdictions.
Data Security

Your client's evidence
stays with you.

POPIA requires that personal information is processed lawfully and with appropriate security measures. Legal professional privilege requires that your case data is not disclosed to third parties. Every cloud-based investigation tool creates a problem for both.

MERIDIAN was designed from the ground up to run entirely on your device. AI features use Ollama — a locally-deployed language model with no API calls. OSINT queries are investigator-initiated and route through the Electron main process, never the renderer. Investigation data never leaves your machine.

The question isn't whether AI can help forensic investigators. It can, demonstrably. The question is whether you can use it without compromising your evidence and your client's privilege. MERIDIAN resolves that tension — entirely local inference, complete data sovereignty.

Design principle — MERIDIAN v2
Investigation data never leaves your device

Case data makes zero outbound network calls. No analytics, no telemetry, no update checks, no CDN dependencies. The application works fully air-gapped. OSINT queries are explicitly investigator-initiated, logged in the audit trail, and handled by the Electron main process — never the renderer.

AES-256-GCM encryption on every save file

Investigation files are encrypted using AES-256-GCM with PBKDF2 key derivation (310,000 iterations, SHA-256). The passphrase never leaves your device. Even if someone steals the file, it is unreadable without your passphrase.

AI inference runs on your machine via Ollama

The prosecution narrative generator, evidence gap analysis, and investigative question generator all use a locally-deployed language model. No API keys, no subscription, no data transmission. Your case context never reaches an external server.

POPIA and legal privilege compliant by design

Data processed entirely within your device's jurisdiction. Legal professional privilege is not compromised because no information is transmitted. POPIA's data minimisation and purpose limitation requirements are satisfied because no personal information ever leaves the controller's device.

Legislation Library

8 jurisdictions.
Built in and searchable.

Full legislation text, key sections, and plain-language descriptions — all searchable from within your investigation without leaving the tool. South Africa carries the deepest coverage (14 statutes). More jurisdictions are on the roadmap — tell us which you need next.

ZA
South Africa
KE
Kenya
ZW
Zimbabwe
ZM
Zambia
BW
Botswana
NA
Namibia
AE
UAE
INT
FATF International
About MERIDIAN

Built local
to sort out local.

MERIDIAN was designed to address a specific gap: South African forensic practitioners — advocates, forensic accountants, boutique investigation firms — lack access to professional-grade investigation tooling at a price that makes commercial sense.

MERIDIAN was built from scratch around the workflows, legislation, and investigation contexts that African practitioners actually encounter — state capture, municipal looting, VBS-style bank fraud, procurement corruption, and cross-border organised crime.

Every feature was built because a real investigator needed it. The prosecution narrative generator exists because investigators were spending weeks writing briefs the NPA struggled to act on. The OSINT tab exists because digital footprint research was being done manually in browser tabs, unlogged, outside the case file.

By the Numbers
Automated tests545+
Typologies built in22
Jurisdictions covered14
Bank formats supported9
Demo case files22
OSINT sources200M+
Get In Touch

Book a walkthrough
or a demo.

We'll walk you through MERIDIAN on real published case data — VBS, 1MDB, Steinhoff — in under 20 minutes. Book a walkthrough or a full demo, and we'll show you exactly how a case moves from raw data to court file. We want your honest feedback on what works and what doesn't.

Investigations journalists, NGOs, and civil society organisations investigating corruption or organised crime are encouraged to apply for the NGO programme.

Based inSouth Africa
ResponseWithin 48 hours on business days
✓ Request received — we'll be in touch within 48 hours.