§Déjà · evidence custody between systems
Sealed at the moment, not reconstructed later.
Déjà keeps a record of what your systems reported and what changed — across vendors that don't talk to each other, sealed when a signal is scored, and verifiable offline by an examiner who trusts neither you nor us.
Without visibility across systems there's no seam to be custodian of · and independence has nothing to be independent about
This weekQuarterAll
vaultnorthbridge-prodchain41/41 continuousReceipts sealed41
Attributed · R16
Low confidence · R1-L2
No attribution · R1-N33
Verified offline41/41
Coverage · period to dateSignals from a source that can name a changed field15Signals that cannot26Governance receipts7Chain breaks0
26 of 33 no-attribution receipts came from threshold alerts that carried no affected field. Their receipts record that they were received and that the attribution gate was not entered.
Review signal sourcesIllustrative ledger. Every receipt here — including the ones where nothing was found — is sealed. No resolution receipt (R2) is issued today.
vverifyeexport bundlej/kmove↵open receipt §What Déjà isThe facts nobody owns are the ones between two systems.
Every vendor already proves what happened inside itself. Sentry proves the exception. GitHub proves the merge. The relationship between the two is owned by nobody — which is exactly the relationship an examiner asks about.
OneObserve
Reads the tools you already run, and approves nothing, blocks nothing, remediates nothing. Besides delivering receipts where you point them, it writes back in two places: an event into Honeycomb when an incident is resolved, and ServiceNow incidents if you turn on incident sync.
TwoSeal
Signals from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana are sealed when Déjà scores them: each one that reaches scoring ends in a signed receipt, whether or not a cause is found. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, so they get no receipt, and whether PagerDuty, AWS CloudWatch, Azure Monitor, Google Cloud Monitoring, incident.io, Rootly and FireHydrant incidents reach scoring is still being checked. The ledger is append-only, not assembled the next morning from Slack and recollection.
ThreeExamine
When a signal carries the required attribution inputs, changes in the lookback window are enumerated and scored against the affected field. Otherwise the failed eligibility condition is recorded without scoring.
FourAttribute
One narrow failure mode: a producer removed, renamed or retyped a field and a consumer broke on it. Scored, thresholded, and sealed with the score.
FiveVerify
Open tooling on your auditor's machine. No Déjà account, no API call, no source access. Signed receipts stay signature-verifiable offline, and exported bundles stay independently integrity-checkable, whether or not we are still here.
NotWhat it isn't
Not a GRC platform, not a control, not an opinion. Déjà supplies the record. It doesn't discharge an obligation, and it doesn't tell you what to conclude.
Layer oneGovernance — connector grants, key rotations, zone locks, auditor invitations. Independent of any incident.RG · always on
Layer twoOccurrence — a signal from a scored source (Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana today) is sealed when it is scored, as proof it arrived and was examined, even when nothing is attributed. Alerts from the other connected sources get no receipt yet, and R0 is issued only for incidents posted to Déjà's own endpoint.R0 · R1-N
Layer threeCausation — a producer-side field change linked to the downstream error it broke. Narrow by design, and the only layer that names a cause.R1 · R1-L · R2
Layers one and two run continuously and don't depend on any incident attributing. Layer three is the narrowest of the three and the only one people usually hear about, which is why it's stated last here rather than first.
§How it worksFour connections. Then the record keeps itself.
Nothing to install, and no change to how anyone works. Your observability and paging stay exactly where they are — they're Déjà's inputs, not its replacement.
- youConnect your sources
- youSign the genesis receipt
- Déjà · unattendedSignals sealed, changes examined, receipts chained
- exceptionsGaps and failures sealed too
- your auditorVerifies offline, without an account
- 01
Connect your sources
An error tracker for the signal, a source-control provider for the change. Déjà writes nothing back to Sentry or GitHub; it reads events and each pull request's metadata and diff as it's opened, updated and merged, secrets scrubbed, never a file outside that diff.
- 02
Seal the genesis receipt
Sequence zero, the root of your governance chain. Every later governance receipt chains behind it, and the ledger is append-only — enforced in the database, not by convention.
- 03
Signals are queued for scoring
Each new signal from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana is queued for scoring as it arrives, and whatever scoring finds — a cause, low confidence or nothing — ends in a sealed receipt. That is what makes the ledger a record of the period rather than a record of the interesting parts of it. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, and get no receipt.
- 04
Changes are examined and scored
Producer-side changes in the lookback window are enumerated and scored against the affected field the signal carried — eight weighted signals, published thresholds. Above the threshold the receipt carries the score and the candidate. Below it, the receipt says so.
- 05
The exceptions are sealed as well
Nothing matched, confidence below threshold, the fix didn't hold, the same field broke again — each has its own receipt type. A ledger that only records the cases that worked is a brochure.
- 06
Your auditor verifies without us
Export the bundle; they run the open CLI on their own machine against a published key. No account, no call to our API, no request we could refuse or fail to answer.
No-attribution receipt · unscorable signal
R1N-0e51b7R1-Nledger-sync
Connection pool exhausted · 03:11:02
- SIGNAL
- No affected field present in the payload. error_class: other
- GATE
- Not entered — attribution requires an affected field to score against.
- WINDOW
- 30 days, 9 changes recorded across 2 producers.
- CANDIDATES
- #318 #319 #322 #327 #331 #334 #340 #341 #344
- REASON
- Outside attribution scope. Recorded and listed, not scored.
sha 4d1e…90bcchain +103:11:06
§The receipt nobody else writes
The ledger records the outcome, not only the finding.
Whole classes of incident will never produce an attribution — timeouts, capacity, infrastructure, logic bugs — and pretending otherwise would be the fastest way to lose an auditor's confidence in the cases that do attribute. Déjà doesn't claim those, and their receipts are not less useful for it.
A no-attribution receipt comes in two kinds, and it says which. When scoring runs, the receipt records what was examined and why nothing cleared the threshold. When the signal isn't scorable — no affected field to score against — it records the eligibility condition that failed and why scoring was never entered, and still lists the changes in the window.
Either way the receipt is built to be worth reading: what came in, how far back the window reached, which changes were in it, and the reason the outcome was what it was. That is a result — here is what the system did and did not do — rather than a shrug.
A tool that records only its successes has told you nothing about the period it covers. This is the part an examiner is actually testing for.
§Scope · attributionThree patterns. And everything else.
The narrow part of Déjà is stated plainly here rather than discovered in month two. Layers one and two cover far more; layer three covers this.
Pattern oneA field was removed
A producer stops emitting total_cents. A consumer reading it raises KeyError. The signal names the field; the change removed it.
Pattern twoA field was renamed
currency_code becomes currency. Same shape as removal from the consumer's side, and the same evidence on the producer's.
Pattern threeA field changed type
A string becomes an object. The consumer raises TypeError or AttributeError on a field the change touched.
- else
Everything else gets a receipt, not an attribution
Timeouts, memory, capacity, auth failures, rate limits, logic bugs, performance regressions, infrastructure. These are sealed as no-attribution receipts carrying the processing outcome and, when scoring ran, what was examined. They are evidence of the period; they are not a claim about cause.
- gate
Four conditions have to hold at once
The signal arrives from a connected source; the signal carries the affected field; the language has a real parser; and a matching change exists in the lookback window on a change with a resolved edge. Fail any one and the result is a no-attribution receipt.
- yours
The proportion is yours to establish
What share of your incidents are cross-team field breaks is a number about your architecture, not about Déjà, and we won't invent it for you. It's also the wrong number on its own: the cross-team schema break is the case where nobody knows the cause, because it lives in another team's repository.
§The argument
A postmortem is a memory of an outage, written by tired people.
The outage ends at 3:07. The reconstruction starts at nine. Somebody scrolls back through five tools and assembles a story that is broadly true, mostly in order, and entirely dependent on what people remembered and what hadn't yet rotated out of a log.
Nobody thinks this is good. Everybody does it, because the alternative — writing the record while the thing is happening — competes with fixing the thing that is happening. So it loses, every time, correctly. The record was never too hard to keep. It was only ever kept afterwards.
Change what it costs to keep the record, and the argument about discipline disappears.
That is the whole of it. Déjà doesn't ask anyone to be more rigorous during an incident. It watches the systems that were already going to fire and writes what they said, at the moment they said it, into a record that gets checked rather than remembered.
The second-order effect is the one people underestimate. When the record is contemporaneous, the interesting question stops being what happened and becomes what does the record show — which is a question with an answer, and the only kind an examiner can test.
§VerificationYou don't have to trust Déjà to trust Déjà.
A vendor's own attestation is not independently verifiable evidence by itself, and that constraint applies to us as hard as to anyone. So every attribution receipt is signed — with Déjà's Ed25519 key, or on Enterprise and Sovereign with your vault's own KMS key — and verifies against a published public key with open tooling on a machine we don't control, with no account and no call to our API.
The ledger is append-only, and that constraint is enforced in the database rather than by application policy — an issued receipt cannot be updated through the product, and your auditor can read the constraint definition themselves. What each signature independently establishes is narrower and more durable: that this receipt's content is the content that was signed by the holder of the published key.
The bundle states, per receipt, whether it is signed or content-hashed, rather than letting the stronger word cover both.
Offline verification · your auditor's machine
- Signature · ed25519 against published key
- valid
- Hash chain · 41 receipts, sequence continuous
- intact
- Canonical form · recomputes to the signed bytes
- match
- Governance receipts · ed25519 signed
- 7
- Déjà API calls required
- 0
$ dsr-verifier-cli verify-bundle bundle.zip --key deja-managed-v1.pub
§CompareEverything here keeps a record. None of them keeps this one.
These systems each preserve what happened inside themselves, and they do it well. What none of them produces is a single artefact spanning several of them, carrying its own examination outcome, that a third party can check without asking any of us anything.
How Déjà compares with observability and paging, probabilistic RCA, and GRC platforms| Capability | Observability & paging | Probabilistic RCA | GRC platform | Déjà |
|---|
| Primary artefact | Telemetry and events, inside its own environment | A ranked inference over that telemetry | An entry in a control register | A cross-system receipt linking what several systems reported |
|---|
| Captured as it happens | Yes, within the system | Yes, over the same data | No — entered afterwards by a person | Yes for scored sources — sealed into an append-only chain when scored |
|---|
| Explicit no-attribution outcome | Not generally what it is for | Usually surfaces as a lower-ranked candidate | A blank field | A receipt stating what was examined, or which eligibility condition failed |
|---|
| Deterministic attribution | Correlation and change tracking, not a deterministic claim | Probabilistic and ranked by design | Whatever was typed | Three field-change patterns, scored against published thresholds |
|---|
| Independent verification | Generally not its evidence model | Generally not its evidence model | Self-asserted by the customer | Offline signature check against a published key, for signed receipt types |
|---|
| Evidence format | Vendor-specific | Vendor-specific | Platform-specific | DSR/1.0 receipts and bundles — open spec |
|---|
| If the vendor disappears | Export, typically unattested | The inference goes with it | Export, still self-asserted | Signed receipts still verify against the published key |
|---|
Keep all of them. Observability and paging are Déjà's inputs; a GRC platform is where the evidence lands. Déjà is the substrate underneath, not a replacement for any of the three.
§Our own statusWhat we can show you today — and what we can't yet.
Déjà is early. Pretending otherwise would waste the first hour of your security review, so here is the position in writing. If a connector matters to you and it's in the second list, say so before the trial rather than after.
- Sentry
Signal-to-receipt path demonstrated end to end
A real exception in a production organisation produced a sealed receipt through the full signal path. That is a narrower statement than cross-system attribution demonstrated in production, which we are not yet making. It is currently the one qualifying source we can say even this much about.
- GitHub
Change side demonstrated
Merge events write producer-side edges. Consumer-side resolution across services is built and being validated; until it lands, cross-service attribution isn't something we'll claim.
- Datadog
Connected · cannot name a field
Its alerts are scored, but Déjà's intake keeps no title, message or stack trace — Error Tracking included — so a Datadog alert cannot name the field, and its receipt records that none was extracted. Our endpoint accepts a delivery that carries the connection's secret in a header, which a Datadog webhook can be set to send, and we have not yet shown a real Datadog delivery end to end.
- Slack · PagerDuty
Connected, not yet demonstrated
They deliver and they page. A PagerDuty incident that reaches scoring is scored on its title, from which a field can be read, but whether PagerDuty's current webhook format reaches scoring is still being checked, so no PagerDuty receipt is claimed.
- ServiceNow · Jira
Beta, untested by us
In the codebase, not yet validated end to end. Listed here rather than on an integrations grid with a checkmark next to it.
- GitLab
Connects, not read yet
Déjà registers its own webhooks on the projects you choose, but merged merge requests are not read yet, so nothing the GitLab connection receives becomes a candidate for attribution.
- Languages
Python demonstrated
The Python parser is demonstrated. JavaScript and TypeScript are supported but not yet demonstrated by us. Other languages produce signal receipts without field-level classification.
- Certifications
In progress, not complete
Charter and trial customers get the control narrative and the gap list as it stands. We'd rather lose a deal than imply an attestation we don't hold.
Everything in the second list either becomes a demonstration or comes off this page. Ask for the current version of it before the demo — it's the fastest way to find out whether this is worth either of our time.
§PricingPriced by scope. Never metered.
A bad quarter costing more than a quiet one is an incentive pointed the wrong way. Tiers are priced on vaults, retention, isolation and support — never on how many receipts your systems produced.
Charter$30Kper year · locked for life- For design partners shaping the roadmap
- Direct line to the team, DSR working-group seat
- Up to 15 seats · one vault · single framework
- Two-year receipt retention
- Limited seats
Standard · recommended$10Kper month · billed annually- One vault, full receipt lifecycle, framework mapping
- 30 admin seats · unlimited auditor invitations
- Five-year retention · SSO/SAML · governance log
- Offline verification and exportable evidence bundles
- 14-day trial, fully featured, no card
Enterprise$300K+per year · custom contract- Multi-vault, isolated tenant, custom retention
- Uptime, support and incident-response commitments written into the agreement
- Procurement-grade review
- Sovereign deployments from $1M a year
No receipt quota and no overage on any tier — a quarter with four hundred incidents costs what a quarter with four costs. The trial runs fourteen days from signup, and it needs a work email address: a vault is identified by an organisation, so personal domains are declined at signup.
§Reasonable objectionsQuestions we would ask too.
- We already have Datadog and PagerDuty.
- Keep them — they're inputs. They observe and they page; neither produces a sealed, offline-verifiable record of what arrived and what changed. Different layer, not a replacement, and Déjà is worth nothing without them.
- Why should we trust your attribution?
- You shouldn't have to. Scoring is deterministic and published, the score travels on the receipt, and where confidence is below threshold or nothing matched the receipt states that instead. A system that records its uncertainty explicitly is the only kind worth checking.
- What if it attributes the wrong change?
- Then the receipt carries the score and the margin, and an engineer can see the second candidate was 0.004 behind. That's why the number is on the artifact rather than behind it. Where two candidates sit inside the tie band, the receipt is sealed as low confidence rather than as a finding.
- What happens to our evidence if you shut down?
- Signed receipts remain signature-verifiable offline against a published key, and an audit engagement's period report remains independently integrity-checkable. None of that depends on us being reachable — or existing. The ledger export does not hold everything: it takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE.
- Our auditors won't accept this.
- They don't have to accept it — they verify it, on their own machine, without an account. Bring your audit firm into the trial; that's what the trial is for, and their objections are more useful to us than our answers are to them.
- Does this satisfy DORA or Part 500?
- No, and be wary of anyone who says it does. Déjà supplies the record. Filing, determination, classification and certification remain with your named accountable individuals, and no vendor can take that on for you.
Has an examiner ever asked for a record you couldn't produce?
Fourteen days to decide. Bring your auditor.