Still Systems, LLC — TreeResolve product site (stillsystems.github.io/treeresolve-community)
CAIQ Lite
Pre-filled lite answers for vendor risk questionnaires. Mapped loosely to common CSA CAIQ / CCM themes. Not a CSA certification. Not SOC 2.
Vendor: Still Systems, LLC (solo operator) Product: TreeResolve VS Code extension + CLI Date: 2026-09-26 Contact: billy.kidd34@gmail.com · private vulnerability reports via SECURITY.md
Legend: Y = yes · N = no · NA = not applicable · P = partial / honest caveat for a solo vendor.
- #: 1 — Control theme (lite): Customer source code processed in vendor cloud? — Ans: N — Notes: Merge parsing/resolution is local-only. See data-flow.md.
- #: 2 — Control theme (lite): Customer source stored at rest by vendor? — Ans: N — Notes: Never collected.
- #: 3 — Control theme (lite): Subprocessors that receive customer source? — Ans: N — Notes: None for merge. Paddle receives buyer billing data only.
- #: 4 — Control theme (lite): Encryption in transit (TLS) for vendor endpoints? — Ans: Y — Notes: Licensing gateway and docs site use HTTPS.
- #: 5 — Control theme (lite): Encryption at rest for customer source in vendor custody? — Ans: NA — Notes: No customer source in vendor custody.
- #: 6 — Control theme (lite): Independent SOC 2 / ISO 27001 attestation? — Ans: N — Notes: Zero-cost constraint; not pursued pre-launch. Trust Pack + local-only design is the substitute.
- #: 7 — Control theme (lite): Documented vulnerability disclosure program? — Ans: Y — Notes: GitHub private advisories + security.txt.
- #: 8 — Control theme (lite): Security contact / response SLA? — Ans: P — Notes: Aim: acknowledge within 48 hours (solo). No 24×7 SOC.
- #: 9 — Control theme (lite): Production access MFA for vendor accounts? — Ans: Y — Notes: GitHub org + Cloudflare + Paddle accounts use MFA (operator practice).
- #: 10 — Control theme (lite): Secrets scanning in CI? — Ans: Y — Notes: gitleaks in release gate; Dependabot on.
- #: 11 — Control theme (lite): Dependency vulnerability scanning? — Ans: Y — Notes:
npm auditin release gate; Dependabot security updates. - #: 12 — Control theme (lite): SBOM available per release? — Ans: Y — Notes: CycloneDX artifact from release workflow.
- #: 13 — Control theme (lite): Signed release artifacts? — Ans: Y — Notes: SHA-256 + Sigstore keyless cosign on VSIX (GitHub OIDC).
- #: 14 — Control theme (lite): Public supply-chain scorecard? — Ans: Y — Notes: OpenSSF Scorecard on
stillsystems/treeresolve-community. - #: 15 — Control theme (lite): Separate prod/non-prod for billing? — Ans: P — Notes: Paddle sandbox vs live; live cutover is an operator step.
- #: 16 — Control theme (lite): Background checks on all staff with prod access? — Ans: P — Notes: Solo founder; no additional employees.
- #: 17 — Control theme (lite): Formal IR playbook with tabletop drills? — Ans: P — Notes: Lightweight VDP process in SECURITY.md; no formal multi-team IR org.
- #: 18 — Control theme (lite): Customer data residency choice? — Ans: NA — Notes: No customer source stored. Licensing KV is Cloudflare (edge).
- #: 19 — Control theme (lite): Right to audit / on-site audit? — Ans: P — Notes: Reasonable questionnaire support; on-site SOC-style audits not offered free.
- #: 20 — Control theme (lite): Pentest within last 12 months? — Ans: N — Notes: Not yet; release gate + Scorecard + advisory channel instead.
- #: 21 — Control theme (lite): Logging / SIEM for customer-code access? — Ans: NA — Notes: Vendor cannot access customer code via the product.
- #: 22 — Control theme (lite): Telemetry opt-out available? — Ans: Y — Notes:
treeresolve.enableTelemetry: falseand/or VS Code telemetry off. - #: 23 — Control theme (lite): Air-gapped deployment supported? — Ans: Y — Notes: Offline VSIX + offline wildcard license; see offline-vsix.md.
- #: 24 — Control theme (lite): Extension allow-list compatible? — Ans: Y — Notes: Documented
extensions.allowed/AllowedExtensionsexamples. - #: 25 — Control theme (lite): Breach notification commitment? — Ans: P — Notes: Will notify affected paying customers promptly if a licensing/account incident occurs; no customer-source breach surface by design.
Free-text summary (paste into portals)
> TreeResolve resolves Git merge conflicts entirely on the developer workstation > or CI runner using local Tree-sitter WASM grammars. Customer source code, ASTs, > and file paths are not transmitted to Still Systems. Optional licensing traffic > may send an anonymized machine fingerprint for trials/floating leases; offline > enterprise wildcard keys require no network validation. Optional anonymous > telemetry (codes only) can be disabled by policy. Still Systems is a solo LLC > without SOC 2; we publish a data-flow diagram, per-release SBOM, SHA-256 + > Sigstore-signed VSIX artifacts, OpenSSF Scorecard on the public tracker, > security.txt / VDP, and offline install guidance instead.