Guide · Private Capital

The Meridian user guide.

Everything a family office, an investor, an issuer or a fund administrator needs to run a deal on Meridian, from the access request to a posted distribution. Written for the people who operate the work rather than the people who buy the software, and it states the limits as clearly as the capabilities.

Meridian private capital guide KXCO Engineering 31 July 2026 Updated 1 August 2026 ~21 min read

Most private capital software covers one half of the work. Deal platforms stop at the commitment and hand you a spreadsheet for everything after it. Fund administration systems start at the commitment and have nothing to say about how the deal was found or diligenced. Meridian covers both halves, and this guide walks the whole path: originate, diligence, commit, settle, then administer the vehicle that holds the position, through capital calls, a distribution waterfall and the bank statement that proves the money moved.

01What Meridian is, and what it is not

Meridian is a private venue for family offices, institutional investors, issuers and their advisers. Two things happen in it. Deals get originated, examined and agreed. Then the vehicles behind those deals get administered: who owns what, who owes what, who is owed what, and what the record says.

What Meridian is not matters just as much, and it is not a disclaimer bolted on at the end. It shapes the product.

  • KXCO is a software company. It is not a party to any transaction on the platform, not a broker-dealer, not an adviser and not a fiduciary.
  • KXCO never holds your assets. Settlement runs between the parties. Meridian records instructions and evidence, it does not take custody.
  • Discretion stays with you. Where the software could plausibly make a judgement for you, it refuses and asks. That principle recurs throughout this guide, and it is the reason several operations require a second person rather than one click.

There is a companion guide inside the product at meridian.kxco.ai/guide. This post is the wider version, and it goes further into the vehicle layer.

02Access and verification

Meridian is closed. There is no self-service route from a landing page to a live data room, by design.

  1. Request access. An organisation applies from the sign-in screen, giving a name, a category and a contact. Nothing is visible yet.
  2. An administrator reviews it. Approval is a human decision. Until it is granted, sign-in is refused rather than granted with an empty account, so a pending applicant cannot browse.
  3. Verification follows separately. Identity and accreditation checks are a second gate, tracked as its own status. You can explore once approved. Sensitive actions, making an offer and paying a capital call, sit behind verification.
  4. Invitations skip the queue. An administrator, or a Founders Club member, can issue a one-time invite link. Invited members enter directly.

On first sign-in two things are created for you. An organisation, which is the unit that actually holds positions and shares a diligence workspace, so your colleagues see the same work rather than each keeping a private copy. And a KXCO ID, a short fingerprint derived from a post-quantum ML-DSA-65 public key, which is the only identifier shown for you across the network.

Membership runs in categories: an observer tier, a member tier and an enterprise tier, set by an administrator against your agreement. The category governs entitlements, not visibility of your own data.

03The deal board, mandates and matching

Live offerings appear on the Deals board. Rather than reading everything, tell Meridian what you actually invest in.

  • Set your mandate: sectors, geographies, instruments, currencies and a ticket range.
  • Live deals are then scored from 0 to 100 against that mandate and collected under Matches. When a new deal goes live and fits, it lands in your alerts.
  • Watch a deal with the star to be told when it changes, whether or not it matches your mandate.

Matching is a filter, not a recommendation. A high score means the deal fits the parameters you typed, and nothing more than that.

04Creating an offering, and the readiness check

Issuers build an offering from Your offerings. The terms are the usual ones: title and description, sector and geography, instrument (equity, debt, a convertible loan, a private placement, a mortgage, a lien, options or a bond), settlement currency, target raise, minimum ticket, and a visibility setting that runs from network-wide to participants-only to fully private.

An offering starts as a draft. You submit it for administrator review to go live, which is the platform's editorial gate.

Before you submit, the Readiness tab scores the offering on structural completeness: core terms filled, documents uploaded and approved, the standard document set for your instrument, an expected diligence list, a reachable data room and settlement configured. It checks that things are present. It does not opine on whether your deal is any good, and it does not block submission. It exists so that you find the gap rather than an investor finding it.

05The data room

Access is tiered. The teaser is open to anyone who can see the deal. The information memorandum and the gated documents unlock when the viewer signs the room's NDA, which covers confidentiality, non-solicitation and non-circumvention, an investor eligibility declaration, and the criminal liability position on inside information. Signing is recorded as a post-quantum signature bound to the hash of the document that was actually shown.

Per document, the issuer chooses how it may be read:

  • Downloadable. The file itself, as uploaded.
  • Locked. The document is rasterised to images and served without a download path, with the viewer's identity burned into the page as a watermark.

Every upload is approved individually before anyone sees it, and a document can be permanently removed later, which deletes the stored bytes and the rasterised pages rather than merely hiding the row.

Uploads are also screened for active content: a PDF carrying embedded JavaScript, a run-on-open action or a launch-external-program action. These are refused outright for every membership tier except enterprise. An enterprise account may upload one, on the understanding that the check never protected the uploader in the first place. It protects whoever later downloads the document from the room, which includes external recipients who arrived on a forwarded NDA link. So the finding is recorded rather than waved through: the uploader sees a warning naming what was found, and a signed audit entry records the markers, the document, its hash and the tier that allowed it.

You get real analytics on the room: who opened what, for how long, on which page, from which device and roughly where, along with a forwarding graph showing how access spread. One shared link can be emailed to many recipients, and each still signs the NDA on arrival, so the roster stays accurate.

Two honest limits

Forwarding is only attributed when the platform sees it. If a recipient mints a personal link or signs again, the graph records it. If they copy the raw URL to somebody who never signs, that hop is invisible. No product can see that, and Meridian does not pretend to.

A watermark deters, it does not prevent. A locked document cannot be downloaded through the product, but a determined viewer with a camera is outside software's reach. Treat locked mode as friction and attribution, not as containment.

06Diligence and the IC memo

This is where most of an investor's time goes, so it is built as a workspace rather than a checklist widget.

For the investor

Open a diligence workspace for your firm on any deal. It belongs to your organisation, so your whole team works the same file, and it is invisible to other investors on the same deal.

  • Work a tracked checklist. Each item moves through not started, requested, received, reviewed, flagged and cleared, carrying your note, a risk flag and a link to the document that evidences it. The list is seeded from a template matched to the instrument, plus whatever the issuer said to expect.
  • Run your own pipeline: screening, in diligence, then commit or pass, with the rationale captured for your investment committee record.
  • Ask for what is missing. A request for information on an item goes to the issuer as a tracked question, not a chat message. Their answer lands against that item and moves it to received.
  • Suggest coverage with AI. Meridian reads the data room and marks each item covered, partial or missing, with citations to the pages it relied on. This runs on a separate axis from your own status and never overwrites it.
  • Generate an IC memo. A first draft covering thesis, terms, financials, key risks and a recommendation, built from the deal's own facts and your own findings, which you then edit, finalise and export as a PDF.

For the issuer

  • Publish an expected diligence list, which seeds every investor's workspace so they start from your checklist rather than inventing one. A single click fills it from a template matched to your instrument.
  • See who is in diligence: each party's stage, progress, risk flags and open requests, and answer every information request from one inbox.
Know this before you type

The issuer and platform administrators can see everything in an investor's workspace, including notes and risk flags. There is no private scratch space on a deal. That was a deliberate choice in favour of a single shared record, taken with the trade-off understood. If a thought should not be visible to the issuer, keep it out of the workspace.

AI suggestions are a drafting aid. They are not advice, not a recommendation, and not a substitute for reading the document. The citations exist so you can check the claim rather than trust it.

07Offers, commitments and settlement

An offer carries an amount, a currency and terms, and requires verification. You can make it personally or through one of your vehicles, which matters later: whatever you name here becomes the holder of the resulting position.

The issuer screens the offer and accepts it, which creates a binding commitment. The commitment records both who acted and which vehicle holds it, and flows into the portfolio.

On the Settlement tab the issuer sets out how to pay:

  • Per-chain deposit addresses across Armature L1, Ethereum, Bitcoin, Arbitrum, Base, Polygon, BNB and Tron, each with a QR code.
  • A members-only payment link that opens the settlement view for signed-in members.
  • A settlement instruction sheet combining the addresses, fiat wire details and a payment reference, on screen, printable or as a branded PDF.
Read this twice

Deposit addresses are entered by the issuer, not verified by KXCO. Always confirm settlement details with the issuer over an independent channel before you transfer anything. Digital asset transfers do not reverse.

08Vehicles and the cap table

Few family offices invest as a single legal person. Meridian therefore models the structure directly, as a tree of any depth: a family office over a manco, over a fund, over an SPV, over a portfolio company, with trusts, holdcos, GP entities and individuals alongside.

A parent must sit in the same organisation as its child, because the tree describes one group's internal containment. An outside party with an interest in your vehicle is not a parent link, it is a line on the cap table.

How the cap table works

One entry is one holder's stake in one vehicle. The holder is exactly one of another vehicle, a person or an organisation. Three properties are worth understanding because they determine what you can ask of it later.

  • Rows are never edited. A change closes the existing row with an end date and opens a new one. The table therefore reads correctly as at any past date, which is what makes a distribution reproducible months later.
  • Stakes are percentages, held to six decimal places. The current stakes may not exceed 100, and if you try, the refusal tells you how much is actually free.
  • Share counts are deliberately not modelled. No customer has asked for them, and guessing how options or convertibles should convert would be inventing requirements. Percentages are exact and honest about what they claim.

Give it an amount and Meridian splits it across the holders so that the parts sum exactly to the whole, with no lost penny and no silent rounding. If a table only totals 95 percent, it still divides the full amount in the holders' ratio rather than quietly keeping 5 percent back, and it refuses to return a split that does not reconcile.

Scoping follows the obvious rule. Whoever runs the vehicle sees the whole table. A holder sees their own row, and the total is withheld from that view, so one investor cannot infer another's position by subtraction.

A deliberate refusal

Deleting a vehicle leaves its positions in place, orphaned. It never cascades into deleting the commitments and distributions attached to it. Money that really moved does not disappear because somebody tidied up a structure diagram.

09Capital calls

A call names an amount and a due date, and splits it across the holders as the cap table stood on the call date. A 500,000 call against a 90 / 5 / 5 table produces obligations of 450,000, 25,000 and 25,000.

Two design decisions shape how this behaves day to day.

  • Overdue is never stored, it is worked out when you look. An obligation is overdue if its due date has passed and it is not paid. There is no scheduled job to fall behind and no stale flag that can lie to you.
  • Every payment carries its own value date, the day the money actually arrived, not the day somebody typed it in. A part payment in March and the balance in June are two dated contributions. This is not administrative neatness: preferred return accrues from the value date, so getting it wrong changes what people are owed.

The obvious mistakes are refused rather than absorbed. You cannot overpay an obligation, and the refusal names the outstanding figure. You cannot pay against a draft call. A payment cannot predate the call it settles. Withdrawing a call keeps its obligations and payments intact, because the money genuinely arrived, and it can still receive payments afterwards.

10Distributions and the waterfall

A vehicle's terms are four numbers: the preferred return rate, whether it is simple or compound, the GP catch-up percentage and the carried interest percentage. Only a manager can set them.

A distribution then runs four tiers in a fixed order: return of capital, preferred return, GP catch-up, then the carry split.

Why the order is not configurable

The sequence lives in code, not in a settings row. A mis-ordered configuration row does not throw an error, it silently pays the wrong people the wrong amounts, and it can do that for years before anybody notices. Holding the order in code means it is tested rather than trusted.

Some specifics that matter if you are checking the arithmetic:

  • Preferred return accrues on capital still outstanding, not on the amount originally contributed. This is the stricter and lower treatment, and it is the correct one. Accruing on contributed capital keeps paying preferred return on money the investor already has back, and it compounds that error for the life of the vehicle.
  • The catch-up is solved, not approximated. It is computed in closed form, because the target moves as the payment closes on it. A catch-up rate at or below the carry rate is refused rather than iterated at, since it can never converge.
  • Capital is split by who held the vehicle when it was drawn, not by who holds it now. A draw date that predates the cap table is refused, and the message tells you when ownership actually starts.
  • Rounding is stated. Each tier's GP share rounds down and the remainder goes to investors.
  • Only settled money counts. Contributions come from paid capital calls, so an unpaid call cannot inflate the return-of-capital tier.
  • Carry with no GP appointed is refused, rather than quietly redistributed to investors.

Preparing, posting and correcting

A preview writes nothing, and refuses to show you a result that does not reconcile. A draft can be prepared by an administrator. Only a manager can post, and once posted it is immutable, with the terms used frozen onto the event so that it can still be explained after the terms change.

A mistake is corrected by reversal, not deletion: a linked contra event carrying negative allocations, with the original marked reversed and the reason recorded. Cumulative totals therefore stay right by simple addition, and the history never rewrites itself. Per-holder notices are generated as PDFs, for posted events only, and a holder sees their own allocations with the gross withheld.

11Bank reconciliation

Import a statement as CSV or OFX and match the money in against the capital call payments it settles. Two details are worth knowing.

First, ambiguous dates are recorded, never assumed. 01/02/2026 is two different days depending on where the file came from, so Meridian stores which reading it used and whether that was inferred from the file or stated by the person importing it.

Second, a line is unmatched, matched or explicitly ignored with a reason. Nothing is silently dropped, so an unexplained line stays visible until somebody explains it.

Automatic matching needs two things, not one. The amount must exactly clear an outstanding obligation, and the line must identify who paid, by carrying the expected reference or the holder's name. Amount alone is never enough, however few candidates are left.

Why matching by elimination was removed

An earlier version would match a line when only one obligation of that size remained. A live check then auto-matched a receipt that carried no reference and no name, purely because the other candidate had just been consumed.

That is matching by elimination, and it is unsafe in exactly the case where it looks safest. If one investor's wire is still in transit and an unrelated receipt of the same amount arrives, a loan drawdown or a transfer between your own accounts, elimination credits it to the investor who has not paid. Their contribution then earns them preferred return on money they never sent, and nothing looks wrong because every total still adds up. Anything the software cannot positively identify is now left for a person.

Meridian imports statements. It holds no banking credentials, has no direct feed into an account and cannot move money.

12Management fees

A vehicle carries one fee schedule: an annual rate in percentage points, a basis, a frequency of monthly, quarterly, semiannual or annual, and a start date with an optional end.

Nothing is accrued into a table. What has accrued is worked out when it is read, from the schedule, the periods elapsed and the base as it stood at the start of each period, in the same way an overdue capital call is derived rather than stored. An accrual table needs a scheduler to keep it true, and a scheduler that misses a quarter leaves a fee that silently never existed.

Two conventions are worth stating, because each changes the number:

  • A complete period charges the annual rate divided by the periods in a year. Two percent a year billed quarterly is 0.5 percent of the base, not two percent scaled by 92 over 365. That is what a schedule means by quarterly, and it makes consecutive quarters equal regardless of how many days they contain.
  • The period in progress is pro-rated by days elapsed, so a fee is never charged for time that has not passed.

The basis is either capital called or capital paid in. Both are chosen because both are knowable for a vehicle. A NAV basis is deliberately absent: Meridian holds no valuation for a vehicle, since valuations attach to a deal position rather than to the vehicle itself, so offering a NAV basis would compute against nothing and quietly return zero.

Performance fees are not here either. Carried interest is the waterfall's fourth tier and is already handled there, and a second mechanism would be a second answer to the same question.

Reading the schedule and the accrual needs the full cap table right, so a manager or a fund administrator can both see it. Changing the schedule needs edit_vehicle, which is the manager alone.

13Currencies and consolidated reporting

Multi-currency used to be nominal: amounts carried a currency label, no rate existed anywhere, and nothing converted, which meant any cross-currency total was quietly adding unlike things together. Consolidation now works properly, on two rules.

  • Money is never stored converted. Amounts stay in the currency they happened in, and conversion happens only at the moment something is shown added up. A stored converted figure is wrong the day after it is written.
  • Every converted figure reports its rate, the rate's date and its source, shown next to the total rather than buried. A consolidated total whose rate you cannot see is a number nobody can check.

Rates are held to twelve decimal places, because FX is quoted far more finely than money is held and rounding the rate before applying it would bias every converted figure the same way.

A missing rate is refused, never treated as parity

If no rate is available for a currency, Meridian does not fall back to 1 and does not drop the currency. It lists that currency with its untouched native amount, leaves it out of the total, and marks the total as incomplete. Both of the alternatives produce a figure that reads as authoritative and is wrong.

One honest note on where rates come from. They are entered records, each carrying its own source and date, and adding them is a platform administrator action rather than something a vehicle manager does. Meridian is not wired to a live market data feed, so a consolidated total is only as current as the most recent rate somebody entered, which is precisely why the date is displayed beside it.

14Who can do what

Owning a vehicle and operating it are separate questions. Ownership is the cap table. Operating rights are granted per vehicle, and a grant can name a person or an outside firm, which is how a third-party fund administrator works on your vehicles without joining your organisation.

One rule governs the whole design: the administrator prepares, the manager approves.

ActionManagerFund administratorHolder
Read the full cap tableyesyesown row
Change ownershipyesnono
Edit vehicle termsyesnono
Issue a capital callyesyesno
Record a payment receivedyesyesno
Model a distributionyesyesno
Post a distributionyesnono
Reconcile the bankyesyesno
Read the fee schedule and accrualyesyesno
Change the fee scheduleyesnono
See consolidated multi-currency totalsyesyesno
Widen its own accessyesnono

Note the asymmetry between the two money operations, which is intentional. An administrator may issue a capital call, because a call asks for money and can be withdrawn and reissued. Only a manager may post a distribution, because a distribution releases money and cannot be unsent.

15Security and the record

  • Post-quantum identity. Every member holds a KXCO ID derived from an ML-DSA-65 key, the signature standard published by NIST as FIPS 204. It is the only identifier shown across the network.
  • Signatures bind to content. An e-signature is an ML-DSA-65 signature over the SHA-256 hash of the exact document presented, so a later edit is detectable rather than arguable.
  • A tamper-evident audit trail. Every state change is signed and recorded, including the administrative ones: an approval, a tier change, a posted distribution. The trail is designed so that alteration is detectable, not so that it is merely discouraged.
  • Access is scoped by default. Endpoints refuse before they read. A holder gets their own row, an administrator gets what it needs to prepare work, and no role can quietly widen itself.

The cryptographic foundation is public and independently scanned. You can read it rather than take our word for it: see the thirteen post-quantum packages we publish on npm and GitHub.

16The limits, stated plainly

A guide that lists only capabilities is a brochure. These are the boundaries of what Meridian does today.

  • The waterfall is deal by deal. Whole-fund (European) waterfalls are not implemented.
  • Preferred return uses actual days over a 365-day year. If your documents specify a different convention, the figures will differ from your own model.
  • Cap tables carry percentages, not share counts. Option pools and convertible instruments are not modelled.
  • Banking is statement import only. No payment initiation, no live account feed, no credentials held.
  • Management fees offer a called or a paid-in basis, and no NAV basis, because Meridian holds no vehicle-level valuation to compute one against.
  • FX rates are entered records, not a live market feed. A consolidated total is only as current as the most recent rate somebody entered, which is why every converted figure shows its rate and date.
  • A deal paying a vehicle does not yet flow automatically into that vehicle's own waterfall. The two layers exist and are correct on their own. The bridge between them is not built, and we would rather say so than imply it works.
  • There is no private scratch space in a diligence workspace, as described in section 6.
  • Forwarding attribution and locked documents have the limits set out in section 5.
  • Nothing in Meridian is advice. Not the match score, not the AI coverage suggestions, not the IC memo draft. Every one of them is a starting point for your own work, and the responsibility for the decision stays with you.

Meridian runs at meridian.kxco.ai, with the in-product guide at meridian.kxco.ai/guide. Access is by approval. To arrange a walkthrough, request a briefing. KXCO Meridian is operated by Knightsbridge Financial Ltd, trading as KXCO. KXCO is a software company and is not a party to any transaction on the platform, nor a broker-dealer, adviser or fiduciary, and it does not take custody of assets. Cryptographic posture reflects NIST FIPS 203/204/205 alignment at Category-3 parameters; KXCO does not claim CNSA 2.0. Nothing here is investment advice.