Inside KXCO Meridian: A Complete Guide for Family Offices and Private Investors
Access, data rooms, diligence and IC memos, then the vehicle layer most deal platforms leave to a spreadsheet: cap table, capital calls, the distribution waterfall, management fees and consolidated multi-currency reporting.
Part of theStocks Center
Most private capital software covers one half of the work. Deal platforms stop at the commitment and hand you a spreadsheet for everything that follows. Fund administration systems start at the commitment and have nothing to say about how the deal was found or diligenced. The gap between the two is where errors live, because it is bridged by hand.
KXCO Meridian covers both halves. This guide walks the whole path: originate a deal, diligence it, commit, settle, then administer the vehicle that holds the position through capital calls, a distribution waterfall, management fee accrual, consolidated multi-currency reporting and the bank statement that proves the money actually moved.
What Meridian is, and what it is not
Meridian is a private venue for family offices, institutional investors, issuers and their advisers. Two kinds of work happen inside it. Deals get originated, examined and agreed. Then the vehicles behind those deals get administered: who owns what, who owes what, who is owed what, and what the record says.
What it is not matters just as much, because it shapes the product rather than sitting in a footnote.
KXCO is a software company. It is not a party to any transaction on the platform, not a broker-dealer, not an adviser and not a fiduciary.
KXCO never holds your assets. Settlement runs between the parties. Meridian records instructions and evidence, it does not take custody.
Discretion stays with the user. Wherever the software could plausibly make a judgement on your behalf, it refuses and asks instead. That principle explains why several operations below need a second person rather than one click.
Getting in: two gates, not one
Meridian is closed. There is no self-service route from a landing page into a live data room, and that is deliberate.
An organisation requests access from the sign-in screen, giving a name, a category and a contact. Nothing is visible yet.
An administrator reviews it. Approval is a human decision. Until it is granted, sign-in is refused outright rather than granted into an empty account, so a pending applicant cannot browse.
Verification is a separate gate, tracked as its own status. Once approved you can explore. Sensitive actions, making an offer and paying a capital call, sit behind verification.
Invitations skip the queue. An administrator, or a Founders Club member, can issue a one-time invite link, and an invited member enters directly.
Two things are created on first sign-in. An organisation, which is the unit that actually holds positions and shares a diligence workspace, so colleagues see the same work rather than each keeping a private copy. And a KXCO ID, a short fingerprint derived from a post-quantum ML-DSA-65 key, which is the only identifier shown for you across the network.
The deal board and your mandate
Live offerings appear on the deal board. Rather than reading everything, you tell Meridian what you actually invest in.
Set a mandate: sectors, geographies, instruments, currencies and a ticket range.
Live deals are then scored from 0 to 100 against that mandate and gathered under Matches. When a new deal goes live and fits, it lands in your alerts.
Watch any deal to be told when it changes, whether or not it matches.
Matching is a filter, not a recommendation. A high score means the deal fits the parameters you typed, and nothing beyond that.
For issuers: building an offering
Issuers build an offering from their own offerings screen. The terms are the familiar ones: title and description, sector and geography, instrument (equity, debt, a convertible loan, a private placement, a mortgage, a lien, options or a bond), settlement currency, target raise, minimum ticket, and a visibility setting running from network-wide to participants-only to fully private.
An offering starts as a draft and is submitted for administrator review to go live, which is the platform's editorial gate.
Before submitting, a readiness check scores the offering on structural completeness: core terms filled, documents uploaded and approved, the standard document set for that instrument, an expected diligence list, a reachable data room, settlement configured. It checks that things are present. It does not opine on whether the deal is any good, and it does not block submission. It exists so that the issuer finds the gap before an investor does.
The data room
Access is tiered, and a signature is not a key. The teaser is open to anyone who can see the deal. Signing the room's confidentiality undertaking, which covers confidentiality, non-solicitation and non-circumvention, an investor eligibility declaration, and the criminal liability position on inside information, records the signature and puts the signer in a queue. It does not admit them. The signer stays at teaser level, the issuer is told that somebody has signed and has not been let in, and the issuer then approves and chooses the level that reader gets. Signing is recorded as a post-quantum signature bound to the hash of the document actually shown. Approving cannot demote either: a reader who already holds a wider level keeps it, and the same request cannot be decided twice.
Per document, the issuer chooses how it may be read. Downloadable serves the file through the notice described below. View-only rasterises the document to images, serves it with no download path, and refuses the bytes even if the URL is guessed; Word and Excel files are converted and rasterised on the same path, where the converter is deployed. Restricted is a rung no access level reaches, not even full access. It is visible to the issuer, because it is their room, and to the people named on the document itself, so one file can go to one investor without widening their access to every confidential document on the deal. Those grants are keyed to an email address, so one issued before somebody registers still finds them afterwards.
Where a document may be taken, the download runs through a notice enforced on the server. Acknowledging it records a row, and the file route refuses to serve an attachment without a recent acknowledgement bound to that document and that caller, so a copied or scripted URL does not walk around it. Reading the notice records nothing, so a reader who cancels has no acknowledgement against their name. Documents themselves are filed in folders that nest to any depth, and a folder is presentation rather than permission: the document's own tier decides who may see it, and because a folder name is itself information, a recipient is shown a folder only where a document they may see sits beneath it.
Every upload is approved individually before anyone sees it, and a document can later be permanently removed, which deletes the stored bytes and the rasterised pages rather than merely hiding a row.
Uploads are also screened for active content, meaning a PDF carrying embedded JavaScript, a run-on-open action or a launch-external-program action. These are refused outright for every membership tier except enterprise. An enterprise account may upload one, on the understanding that the check never protected the uploader in the first place. It protects whoever later downloads the document from the room, including external recipients who arrived on a forwarded NDA link. So the finding is recorded rather than waved through: the uploader sees a warning naming what was found, and a signed audit entry records the markers, the document, its hash and the tier that allowed it. The room reports who opened what, for how long, on which page, from which device and roughly where, plus a forwarding graph showing how access spread.
Three limits are worth stating. A shared link is either open to whoever holds it or locked to the people it was sent to, and a locked link mints one invitation per recipient, signed against the name and email the issuer entered rather than whatever the form posts. What it cannot do is survive a forwarded email: if a recipient passes the whole message on, the holder is indistinguishable from the recipient and reads under that recipient's signature. Forwarding is attributed only when the platform sees it: if a recipient mints a personal link or signs again, the graph records it, but if they copy the raw URL to somebody who never signs, that hop is invisible. And a watermark deters rather than prevents. Every reader's copy is watermarked on the server rather than in the browser, so two recipients receive files that differ byte for byte and a leaked copy is attributable, and gated surfaces refuse to print, but a viewer with a camera is outside software's reach.
Diligence and the IC memo
This is where most of an investor's time goes, so it is built as a workspace rather than a checklist widget.
An investor opens a diligence workspace on a deal. It belongs to the organisation, so the whole team works one file, and it is invisible to other investors on the same deal.
Work a tracked checklist. Each item moves through not started, requested, received, reviewed, flagged and cleared, carrying a note, a risk flag and a link to the document that evidences it. The list is seeded from a template matched to the instrument, plus whatever the issuer said to expect.
Run your own pipeline: screening, in diligence, then commit or pass, with the rationale captured for the investment committee record.
Ask for what is missing. A request for information on an item reaches the issuer as a tracked question rather than a chat message, and their answer lands against that item.
Suggest coverage with AI. Meridian reads the data room and marks each item covered, partial or missing, with citations to the pages it relied on. This runs on a separate axis from your own status and never overwrites it.
Generate an IC memo: a first draft covering thesis, terms, financials, key risks and a recommendation, built from the deal's facts and your own findings, which you then edit, finalise and export as a PDF.
Issuers get the other side of the same surface. They publish an expected diligence list, which seeds every investor's workspace so investors start from the issuer's checklist rather than inventing one. They can see who is in diligence, with each party's stage, progress, risk flags and open requests, and answer every information request from one inbox.
Know two things before typing into a workspace. The issuer and platform administrators can see everything in it, including notes and risk flags, because Meridian has no private scratch space on a deal. That was a deliberate choice in favour of a single shared record. If a thought should not be visible to the issuer, keep it out. And the AI suggestions are a drafting aid, not advice and not a recommendation. The citations exist so you can check a claim rather than trust it.
Offers, commitments and settlement
An offer carries an amount, a currency and terms, and requires verification. It can be made personally or through one of your vehicles, which matters later, because whatever is named here becomes the holder of the resulting position.
The issuer screens the offer and accepts it, creating a binding commitment that records both who acted and which vehicle holds it.
The issuer then sets out how to pay: per-chain deposit addresses across Armature L1, Ethereum, Bitcoin, Arbitrum, Base, Polygon, BNB and Tron, each with a QR code; a payment link, which a signed-in member can open and so can a counterparty who signed on a room link carrying more than the teaser, using the access token issued at the moment they signed, with every reveal recorded against the name on that signature; and a settlement instruction sheet combining addresses, fiat wire details and a payment reference, on screen, printable or as a PDF. Bank account numbers are held encrypted at rest with the key kept outside the database, which is what makes that sheet payable, since no rail settles from a masked number.
Read this part twice. Deposit addresses are entered by the issuer and are not verified by KXCO. Confirm settlement details with the issuer over an independent channel before transferring anything. Digital asset transfers do not reverse.
Vehicles and the cap table
Few family offices invest as a single legal person, so Meridian models the structure directly, as a tree of any depth: a family office over a management company, over a fund, over an SPV, over a portfolio company, with trusts, holding companies, GP entities and individuals alongside.
A parent must sit in the same organisation as its child, because the tree describes one group's internal containment. An outside party holding an interest in your vehicle is not a parent link, it is a line on the cap table.
One cap table entry is one holder's stake in one vehicle, and the holder is exactly one of another vehicle, a person or an organisation. Three properties determine what you can ask of it later.
Rows are never edited. A change closes the existing row with an end date and opens a new one. The table therefore reads correctly as at any past date, which is what makes a distribution reproducible months afterwards.
Stakes are percentages, held to six decimal places. Current stakes may not exceed 100, and an attempt to exceed it is refused with the amount actually free.
Share counts are deliberately not modelled. No customer asked for them, and guessing how options or convertibles should convert would be inventing requirements.
Give it an amount and Meridian splits it across holders so the parts sum exactly to the whole, with no lost penny and no silent rounding. A table totalling only 95 percent still divides the full amount in the holders' ratio rather than quietly retaining 5 percent, and a split that does not reconcile is refused rather than returned.
Scoping follows the obvious rule. Whoever runs the vehicle sees the whole table. A holder sees their own row, and the total is withheld from that view, so one investor cannot infer another's position by subtraction.
Deleting a vehicle leaves its positions in place, orphaned. It never cascades into deleting the commitments and distributions attached to it, because money that really moved should not disappear when somebody tidies a structure diagram.
Capital calls
A call names an amount and a due date, and splits it across holders as the cap table stood on the call date. A 500,000 call against a 90 / 5 / 5 table produces obligations of 450,000, 25,000 and 25,000.
Two decisions shape how this behaves day to day.
Overdue is never stored, it is worked out when you look. An obligation is overdue if its due date has passed and it is unpaid. There is no scheduled job to fall behind and no stale flag that can lie to you.
Every payment carries its own value date, the day the money arrived rather than the day somebody typed it in. A part payment in March and the balance in June are two dated contributions. This is not administrative neatness. Preferred return accrues from the value date, so getting it wrong changes what people are owed.
The obvious mistakes are refused rather than absorbed. You cannot overpay an obligation, and the refusal names the outstanding figure. You cannot pay against a draft call. A payment cannot predate the call it settles. Withdrawing a call keeps its obligations and payments intact, because the money genuinely arrived, and it can still receive payments afterwards.
Distributions and the waterfall
A vehicle's terms are four numbers: the preferred return rate, whether it is simple or compound, the GP catch-up percentage and the carried interest percentage. Only a manager can set them.
A distribution then runs four tiers in a fixed order: return of capital, preferred return, GP catch-up, then the carry split. The sequence lives in code rather than in a settings row, and that is a deliberate safety decision. A mis-ordered configuration row does not throw an error, it silently pays the wrong people the wrong amounts, and it can do that for years before anyone notices.
Specifics that matter if you are checking the arithmetic:
Preferred return accrues on capital still outstanding, not on the amount originally contributed. This is the stricter and lower treatment and it is the correct one. Accruing on contributed capital keeps paying preferred return on money the investor already has back, and compounds that error for the life of the vehicle.
The catch-up is solved, not approximated. It is computed in closed form, because the target moves as the payment closes on it. A catch-up rate at or below the carry rate is refused rather than iterated at, since it can never converge.
Capital is split by who held the vehicle when it was drawn, not by who holds it now. A draw date preceding the cap table is refused, and the message says when ownership actually starts.
Rounding is stated. Each tier's GP share rounds down and the remainder goes to investors.
Only settled money counts. Contributions come from paid capital calls, so an unpaid call cannot inflate the return-of-capital tier.
Carry with no GP appointed is refused, rather than quietly redistributed to investors.
A preview writes nothing and refuses to show a result that does not reconcile. A draft can be prepared by an administrator, but only a manager can post, and once posted it is immutable, with the terms used frozen onto the event so it can still be explained after the terms change.
A mistake is corrected by reversal rather than deletion: a linked contra event carrying negative allocations, with the original marked reversed and the reason recorded. Cumulative totals therefore stay right by simple addition, and the history never rewrites itself. Per-holder notices are generated as PDFs for posted events only, and a holder sees their own allocations with the gross withheld.
Bank reconciliation
A statement is imported as CSV or OFX and the money in is matched to the capital call payments it settles.
Ambiguous dates are recorded, never assumed. 01/02/2026 is two different days depending on where the file came from, so Meridian stores which reading was used and whether that was inferred from the file or stated by the person importing it. Each line is unmatched, matched, or explicitly ignored with a reason, so nothing is silently dropped and an unexplained line stays visible until somebody explains it.
Automatic matching needs two things rather than one. The amount must exactly clear an outstanding obligation, and the line must identify who paid, by carrying the expected reference or the holder's name. Amount alone is never enough, however few candidates remain.
That rule was tightened after a live check. An earlier version matched a line when only one obligation of that size was left, and it auto-matched a receipt carrying no reference and no name purely because the other candidate had just been consumed. That is matching by elimination, and it is unsafe in exactly the case where it looks safest. If one investor's wire is still in transit and an unrelated receipt of the same size arrives, a loan drawdown or a transfer between your own accounts, elimination credits it to the investor who has not paid. Their contribution then earns them preferred return on money they never sent, and nothing looks wrong because every total still adds up. Anything the software cannot positively identify is now left for a person.
Meridian imports statements. It holds no banking credentials, has no direct feed into an account, and cannot move money.
Management fees
A vehicle carries one fee schedule: an annual rate in percentage points, a basis, a frequency of monthly, quarterly, semiannual or annual, and a start date with an optional end.
Nothing is accrued into a table. What has accrued is worked out when it is read, from the schedule, the periods elapsed and the base as it stood at the start of each period, in the same way an overdue capital call is derived rather than stored. An accrual table needs a scheduler to keep it true, and a scheduler that misses a quarter leaves a fee that silently never existed.
Two conventions are worth stating, because each changes the number.
A complete period charges the annual rate divided by the periods in a year. Two percent a year billed quarterly is 0.5 percent of the base, not two percent scaled by 92 over 365. That is what a schedule means by quarterly, and it makes consecutive quarters equal regardless of how many days they contain.
The period in progress is pro-rated by days elapsed, so a fee is never charged for time that has not passed.
The basis is either capital called or capital paid in, because both are knowable for a vehicle. A NAV basis is deliberately absent: Meridian holds no valuation for a vehicle, since valuations attach to a deal position rather than to the vehicle itself, so offering a NAV basis would compute against nothing and quietly return zero.
Performance fees are not here either. Carried interest is the waterfall's fourth tier and is handled there, and a second mechanism would be a second answer to the same question.
Currencies and consolidated reporting
Multi-currency used to be nominal. Amounts carried a currency label, no rate existed anywhere, and nothing converted, which meant any cross-currency total was quietly adding unlike things together. Consolidation now works properly, on two rules.
Money is never stored converted. Amounts stay in the currency they happened in, and conversion happens only at the moment something is shown added up. A stored converted figure is wrong the day after it is written.
Every converted figure reports its rate, the rate's date and its source, shown next to the total rather than buried. A consolidated total whose rate you cannot see is a number nobody can check.
Rates are held to twelve decimal places, because FX is quoted far more finely than money is held, and rounding the rate before applying it would bias every converted figure the same way.
A missing rate is refused, never treated as parity. Meridian does not fall back to 1 and does not drop the currency. It lists that currency with its untouched native amount, leaves it out of the total, and marks the total as incomplete. Both alternatives produce a figure that reads as authoritative and is wrong.
One honest note on where rates come from. They are entered records, each carrying its own source and date, and adding them is a platform administrator action rather than something a vehicle manager does. Meridian is not wired to a live market data feed, so a consolidated total is only as current as the most recent rate somebody entered, which is precisely why the date is shown beside it.
Who can do what
Owning a vehicle and operating it are separate questions. Ownership is the cap table. Operating rights are granted per vehicle, and a grant can name a person or an outside firm, which is how a third-party fund administrator works on your vehicles without joining your organisation.
One rule governs the design: the administrator prepares, the manager approves.
A manager can do everything: change ownership, edit vehicle terms, issue calls, record payments, model and post distributions, reconcile the bank, and grant access.
A deputy manager, which is what an organisation's admin holds on its own vehicles, can do everything a manager can except post a distribution and change ownership. Those two are withheld because no later overruling reaches them: a posted distribution has already paid out, and a cap table an outside counterparty has relied on cannot be quietly rewritten.
A fund administrator can read the full cap table, issue capital calls, record payments received, model a distribution, reconcile the bank, read the fee schedule and accrual, and see consolidated multi-currency totals. It cannot change ownership, edit vehicle terms, change the fee schedule, post a distribution, or widen its own access.
A holder sees their own cap table row and their own distribution allocations, and nothing else.
Note the asymmetry between the two money operations, which is intentional. An administrator may issue a capital call, because a call asks for money and can be withdrawn and reissued. Only a manager may post a distribution, because a distribution releases money and cannot be unsent.
Security and the record
Every member holds a KXCO ID derived from an ML-DSA-65 key, the signature standard published by NIST as FIPS 204. It is the only identifier shown across the network.
An e-signature is an ML-DSA-65 signature over the SHA-256 hash of the exact document presented, so a later edit is detectable rather than arguable.
Every state change is signed and recorded, including administrative ones such as an approval, a tier change or a posted distribution. The trail is built so alteration is detectable, not merely discouraged.
Access is scoped by default. Endpoints refuse before they read, and no role can quietly widen itself.
The cryptographic foundation is public and independently scanned, so it can be read rather than taken on trust. KXCO publishes thirteen post-quantum packages on npm and GitHub.
The limits, stated plainly
A guide listing only capabilities is a brochure. These are the current boundaries.
The waterfall is deal by deal. Whole-fund, or European, waterfalls are not implemented.
Preferred return uses actual days over a 365-day year. Documents specifying another convention will produce different figures from your own model.
Cap tables carry percentages, not share counts. Option pools and convertible instruments are not modelled.
Banking is statement import only. There is no payment initiation, no live account feed and no credentials held.
Management fees offer a called or a paid-in basis, and no NAV basis, because Meridian holds no vehicle-level valuation to compute one against.
FX rates are entered records rather than a live market feed. A consolidated total is only as current as the most recent rate somebody entered, which is why every converted figure shows its rate and date.
A deal paying a vehicle does not yet flow automatically into that vehicle's own waterfall. Both layers exist and are correct on their own, but the bridge between them is not built.
There is no private scratch space in a diligence workspace.
Word and Excel files can be made view-only only where the document converter is deployed. Where it is not, the offer is refused rather than accepted and quietly delivered as something a counterparty can keep.
The wording on a deal's action button is not reviewed. Length and hidden-character rules apply, but the claim a custom label makes reaches a public investment page without passing the review the listing itself passed.
Nothing in Meridian is advice. Not the match score, not the AI coverage suggestions, not the IC memo draft. Each is a starting point for your own work, and the decision remains yours.
How to request access
Meridian is at meridian.kxco.ai. Access is by approval, so the route in is the request form on the sign-in screen: choose Request access, give your organisation name, category and contact, and an administrator reviews it. If somebody at KXCO has already sent you an invitation link, use that instead and you will enter directly.
The in-product guide sits at meridian.kxco.ai/guide, and a longer technical version of this walkthrough is published at kxco.ai/developers/blog/meridian-user-guide.
Disclosure: Live Trading News and KXCO Meridian are both operated by KXCO. This is a product guide rather than independent coverage, and nothing in it is investment advice. Meridian is operated by Knightsbridge Financial Ltd, trading as KXCO, which is a software company and is not a party to any transaction on the platform, nor a broker-dealer, adviser or fiduciary, and does not take custody of assets.

What KXCO Is, and Why the Hard Problem Was Never Intelligence
The prevailing enthusiasm assumes the hard problem is intelligence. It is not. It is that banks, hospitals, courts and governments are being asked to let software act on their behalf with no way to establish who decided, on what basis, or whether the record will still read in a decade. KXCO founder Shayne Heffernan sets out the architecture that answers those questions, drawn as a graph, and argues that properly constructed AI is an amplifier of human judgement rather than a replacement for it.

AI Intelligence Scales. Accountability Does Not. Why KXCO Is Built for It.
Capability is becoming abundant and everything abundant gets cheap. What does not get cheap is the person who has to sign, and they can only carry what they can see. Four conditions follow from that, and four independent authorities reached the first of them last month without knowing it.

KXCO Meridian Big Ticket Deals
Most deal software is built for one shape of transaction and stretched over the rest. You can tell, because it asks a property vendor for a cap table. What changes when the venue knows the difference between a standing asset, a development scheme and an equity raise.

The Truth in All Its Ugliness Must Survive
A majority vote does not determine the truth. Consensus is a mood, gossip is a sport, and a model will write the pretty version for free. Why the ugly number has to survive, why a record beats a dashboard, and what KXCO was built to keep standing when the room changes its mind.
Every story, signed and delivered.
Subscribe to the kxco channel and get the headline, the AI-written key takeaways, and the chain-anchor link the moment we publish. Audio versions and per-ticker subscriptions arrive in the next iteration.