Skip to content
Déjà · evidence custody between systems

Sealed at the moment, not reconstructed later.

Déjà keeps a record of what your systems reported and what changed — across vendors that don't talk to each other, sealed when a signal is scored, and verifiable offline by an examiner who trusts neither you nor us.

Without visibility across systems there's no seam to be custodian of · and independence has nothing to be independent about

This weekQuarterAll
vaultnorthbridge-prodchain41/41 continuous
Receipts sealed41
Attributed · R16
Low confidence · R1-L2
No attribution · R1-N33
Verified offline41/41
Coverage · period to dateSignals from a source that can name a changed field15Signals that cannot26Governance receipts7Chain breaks0

26 of 33 no-attribution receipts came from threshold alerts that carried no affected field. Their receipts record that they were received and that the attribution gate was not entered.

Review signal sources

Signals in

3

received and queued for scoring · sealed in the receipt scoring ends in

sig-8f21c4Receivedsentry

KeyError: total_cents — checkout-api

pythonsha 9f2c…e41a03:07:41
sig-8f21c9Receiveddatadog

Error rate above threshold — ledger-sync

monitor.alert03:11:02

no field named · attribution unavailable

sig-8f2204Receivedsplunk-oncall

Critical alert — statement-render

CRITICAL04:52:10

no field named · attribution unavailable

Examined

2

candidates enumerated from the change graph, scored against the signal

ex-4471Scoringcheckout-api

14 changes in the lookback window · 8 weighted signals

window 30dcandidates 141.6s
ex-4472Scoringledger-sync

9 changes recorded · signal carried no affected field

gate not entered0.4s

Attributed

2

R1 / R1-L · a producer change scored above threshold for the affected field

R1-a3f0d2R1checkout-api

total_cents removed by payments-api#412

CCS 0.96FIELD_REMOVEDed25519

scoring_version 1.0.9 · signed 03:07:43 · prior 8c20fe…

R1L-1b46d3R1-Lbilling-worker

currency_code renamed — two candidates within the tie band

CCS 0.71margin 0.004

below threshold · sealed as low confidence, not as a finding

No attribution

4

R1-N · scored and nothing cleared, or not scorable at all — the receipt says which

Scored · nothing cleared

The signal named an affected field. Twelve changes were examined against it; none cleared the threshold. All twelve are listed on the receipt.

R1N-0e51a9R1-Nreporting-api

KeyError: tax_region — no producing change found

examined 12cleared 009:44:12

highest candidate 0.34 · threshold 0.80

R1N-0e51b7R1-Nledger-sync

Connection pool exhausted

gate not enteredin window 903:11:06

no affected field in the signal · not scorable

R1N-0e51c2R1-Nstatement-render

Memory limit reached during batch render

gate not entered04:52:14

threshold alert · cannot carry an affected field

Resolution

0

R2 / R2-F / R2-R · what was done, and whether it held

R2R2not issued today

No resolution receipt is issued yet

not issued—

Déjà does not yet read the telemetry R2's gates need

Illustrative ledger. Every receipt here — including the ones where nothing was found — is sealed. No resolution receipt (R2) is issued today.

vverifyeexport bundlej/kmove↵open receipt
What Déjà is

The facts nobody owns are the ones between two systems.

Every vendor already proves what happened inside itself. Sentry proves the exception. GitHub proves the merge. The relationship between the two is owned by nobody — which is exactly the relationship an examiner asks about.

One

Observe

Reads the tools you already run, and approves nothing, blocks nothing, remediates nothing. Besides delivering receipts where you point them, it writes back in two places: an event into Honeycomb when an incident is resolved, and ServiceNow incidents if you turn on incident sync.

Two

Seal

Signals from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana are sealed when Déjà scores them: each one that reaches scoring ends in a signed receipt, whether or not a cause is found. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, so they get no receipt, and whether PagerDuty, AWS CloudWatch, Azure Monitor, Google Cloud Monitoring, incident.io, Rootly and FireHydrant incidents reach scoring is still being checked. The ledger is append-only, not assembled the next morning from Slack and recollection.

Three

Examine

When a signal carries the required attribution inputs, changes in the lookback window are enumerated and scored against the affected field. Otherwise the failed eligibility condition is recorded without scoring.

Four

Attribute

One narrow failure mode: a producer removed, renamed or retyped a field and a consumer broke on it. Scored, thresholded, and sealed with the score.

Five

Verify

Open tooling on your auditor's machine. No Déjà account, no API call, no source access. Signed receipts stay signature-verifiable offline, and exported bundles stay independently integrity-checkable, whether or not we are still here.

Not

What it isn't

Not a GRC platform, not a control, not an opinion. Déjà supplies the record. It doesn't discharge an obligation, and it doesn't tell you what to conclude.

Layer oneGovernance — connector grants, key rotations, zone locks, auditor invitations. Independent of any incident.RG · always on
Layer twoOccurrence — a signal from a scored source (Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana today) is sealed when it is scored, as proof it arrived and was examined, even when nothing is attributed. Alerts from the other connected sources get no receipt yet, and R0 is issued only for incidents posted to Déjà's own endpoint.R0 · R1-N
Layer threeCausation — a producer-side field change linked to the downstream error it broke. Narrow by design, and the only layer that names a cause.R1 · R1-L · R2

Layers one and two run continuously and don't depend on any incident attributing. Layer three is the narrowest of the three and the only one people usually hear about, which is why it's stated last here rather than first.

How it works

Four connections. Then the record keeps itself.

Nothing to install, and no change to how anyone works. Your observability and paging stay exactly where they are — they're Déjà's inputs, not its replacement.

  1. youConnect your sources
  2. youSign the genesis receipt
  3. Déjà · unattendedSignals sealed, changes examined, receipts chained
  4. exceptionsGaps and failures sealed too
  5. your auditorVerifies offline, without an account
  1. Connect your sources

    An error tracker for the signal, a source-control provider for the change. Déjà writes nothing back to Sentry or GitHub; it reads events and each pull request's metadata and diff as it's opened, updated and merged, secrets scrubbed, never a file outside that diff.
  2. Seal the genesis receipt

    Sequence zero, the root of your governance chain. Every later governance receipt chains behind it, and the ledger is append-only — enforced in the database, not by convention.
  3. Signals are queued for scoring

    Each new signal from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana is queued for scoring as it arrives, and whatever scoring finds — a cause, low confidence or nothing — ends in a sealed receipt. That is what makes the ledger a record of the period rather than a record of the interesting parts of it. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, and get no receipt.
  4. Changes are examined and scored

    Producer-side changes in the lookback window are enumerated and scored against the affected field the signal carried — eight weighted signals, published thresholds. Above the threshold the receipt carries the score and the candidate. Below it, the receipt says so.
  5. The exceptions are sealed as well

    Nothing matched, confidence below threshold, the fix didn't hold, the same field broke again — each has its own receipt type. A ledger that only records the cases that worked is a brochure.
  6. Your auditor verifies without us

    Export the bundle; they run the open CLI on their own machine against a published key. No account, no call to our API, no request we could refuse or fail to answer.

No-attribution receipt · unscorable signal

R1N-0e51b7R1-Nledger-sync

Connection pool exhausted · 03:11:02

SIGNAL
No affected field present in the payload. error_class: other
GATE
Not entered — attribution requires an affected field to score against.
WINDOW
30 days, 9 changes recorded across 2 producers.
CANDIDATES
#318 #319 #322 #327 #331 #334 #340 #341 #344
REASON
Outside attribution scope. Recorded and listed, not scored.
sha 4d1e…90bcchain +103:11:06
The receipt nobody else writes

The ledger records the outcome, not only the finding.

Whole classes of incident will never produce an attribution — timeouts, capacity, infrastructure, logic bugs — and pretending otherwise would be the fastest way to lose an auditor's confidence in the cases that do attribute. Déjà doesn't claim those, and their receipts are not less useful for it.

A no-attribution receipt comes in two kinds, and it says which. When scoring runs, the receipt records what was examined and why nothing cleared the threshold. When the signal isn't scorable — no affected field to score against — it records the eligibility condition that failed and why scoring was never entered, and still lists the changes in the window.

Either way the receipt is built to be worth reading: what came in, how far back the window reached, which changes were in it, and the reason the outcome was what it was. That is a result — here is what the system did and did not do — rather than a shrug.

A tool that records only its successes has told you nothing about the period it covers. This is the part an examiner is actually testing for.

Scope · attribution

Three patterns. And everything else.

The narrow part of Déjà is stated plainly here rather than discovered in month two. Layers one and two cover far more; layer three covers this.

Pattern one

A field was removed

A producer stops emitting total_cents. A consumer reading it raises KeyError. The signal names the field; the change removed it.

Pattern two

A field was renamed

currency_code becomes currency. Same shape as removal from the consumer's side, and the same evidence on the producer's.

Pattern three

A field changed type

A string becomes an object. The consumer raises TypeError or AttributeError on a field the change touched.

  • else

    Everything else gets a receipt, not an attribution

    Timeouts, memory, capacity, auth failures, rate limits, logic bugs, performance regressions, infrastructure. These are sealed as no-attribution receipts carrying the processing outcome and, when scoring ran, what was examined. They are evidence of the period; they are not a claim about cause.
  • gate

    Four conditions have to hold at once

    The signal arrives from a connected source; the signal carries the affected field; the language has a real parser; and a matching change exists in the lookback window on a change with a resolved edge. Fail any one and the result is a no-attribution receipt.
  • yours

    The proportion is yours to establish

    What share of your incidents are cross-team field breaks is a number about your architecture, not about Déjà, and we won't invent it for you. It's also the wrong number on its own: the cross-team schema break is the case where nobody knows the cause, because it lives in another team's repository.
The argument

A postmortem is a memory of an outage, written by tired people.

The outage ends at 3:07. The reconstruction starts at nine. Somebody scrolls back through five tools and assembles a story that is broadly true, mostly in order, and entirely dependent on what people remembered and what hadn't yet rotated out of a log.

Nobody thinks this is good. Everybody does it, because the alternative — writing the record while the thing is happening — competes with fixing the thing that is happening. So it loses, every time, correctly. The record was never too hard to keep. It was only ever kept afterwards.

Change what it costs to keep the record, and the argument about discipline disappears.

That is the whole of it. Déjà doesn't ask anyone to be more rigorous during an incident. It watches the systems that were already going to fire and writes what they said, at the moment they said it, into a record that gets checked rather than remembered.

The second-order effect is the one people underestimate. When the record is contemporaneous, the interesting question stops being what happened and becomes what does the record show — which is a question with an answer, and the only kind an examiner can test.

Verification

You don't have to trust Déjà to trust Déjà.

A vendor's own attestation is not independently verifiable evidence by itself, and that constraint applies to us as hard as to anyone. So every attribution receipt is signed — with Déjà's Ed25519 key, or on Enterprise and Sovereign with your vault's own KMS key — and verifies against a published public key with open tooling on a machine we don't control, with no account and no call to our API.

The ledger is append-only, and that constraint is enforced in the database rather than by application policy — an issued receipt cannot be updated through the product, and your auditor can read the constraint definition themselves. What each signature independently establishes is narrower and more durable: that this receipt's content is the content that was signed by the holder of the published key.

The bundle states, per receipt, whether it is signed or content-hashed, rather than letting the stronger word cover both.

Offline verification · your auditor's machine

Signature · ed25519 against published key
valid
Hash chain · 41 receipts, sequence continuous
intact
Canonical form · recomputes to the signed bytes
match
Governance receipts · ed25519 signed
7
Déjà API calls required
0

$ dsr-verifier-cli verify-bundle bundle.zip --key deja-managed-v1.pub

Compare

Everything here keeps a record. None of them keeps this one.

These systems each preserve what happened inside themselves, and they do it well. What none of them produces is a single artefact spanning several of them, carrying its own examination outcome, that a third party can check without asking any of us anything.

How Déjà compares with observability and paging, probabilistic RCA, and GRC platforms
CapabilityObservability & pagingProbabilistic RCAGRC platformDéjà
Primary artefactTelemetry and events, inside its own environmentA ranked inference over that telemetryAn entry in a control registerA cross-system receipt linking what several systems reported
Captured as it happensYes, within the systemYes, over the same dataNo — entered afterwards by a personYes for scored sources — sealed into an append-only chain when scored
Explicit no-attribution outcomeNot generally what it is forUsually surfaces as a lower-ranked candidateA blank fieldA receipt stating what was examined, or which eligibility condition failed
Deterministic attributionCorrelation and change tracking, not a deterministic claimProbabilistic and ranked by designWhatever was typedThree field-change patterns, scored against published thresholds
Independent verificationGenerally not its evidence modelGenerally not its evidence modelSelf-asserted by the customerOffline signature check against a published key, for signed receipt types
Evidence formatVendor-specificVendor-specificPlatform-specificDSR/1.0 receipts and bundles — open spec
If the vendor disappearsExport, typically unattestedThe inference goes with itExport, still self-assertedSigned receipts still verify against the published key

Keep all of them. Observability and paging are Déjà's inputs; a GRC platform is where the evidence lands. Déjà is the substrate underneath, not a replacement for any of the three.

Our own status

What we can show you today — and what we can't yet.

Déjà is early. Pretending otherwise would waste the first hour of your security review, so here is the position in writing. If a connector matters to you and it's in the second list, say so before the trial rather than after.

  • Sentry

    Signal-to-receipt path demonstrated end to end

    A real exception in a production organisation produced a sealed receipt through the full signal path. That is a narrower statement than cross-system attribution demonstrated in production, which we are not yet making. It is currently the one qualifying source we can say even this much about.
  • GitHub

    Change side demonstrated

    Merge events write producer-side edges. Consumer-side resolution across services is built and being validated; until it lands, cross-service attribution isn't something we'll claim.
  • Datadog

    Connected · cannot name a field

    Its alerts are scored, but Déjà's intake keeps no title, message or stack trace — Error Tracking included — so a Datadog alert cannot name the field, and its receipt records that none was extracted. Our endpoint accepts a delivery that carries the connection's secret in a header, which a Datadog webhook can be set to send, and we have not yet shown a real Datadog delivery end to end.
  • Slack · PagerDuty

    Connected, not yet demonstrated

    They deliver and they page. A PagerDuty incident that reaches scoring is scored on its title, from which a field can be read, but whether PagerDuty's current webhook format reaches scoring is still being checked, so no PagerDuty receipt is claimed.
  • ServiceNow · Jira

    Beta, untested by us

    In the codebase, not yet validated end to end. Listed here rather than on an integrations grid with a checkmark next to it.
  • GitLab

    Connects, not read yet

    Déjà registers its own webhooks on the projects you choose, but merged merge requests are not read yet, so nothing the GitLab connection receives becomes a candidate for attribution.
  • Languages

    Python demonstrated

    The Python parser is demonstrated. JavaScript and TypeScript are supported but not yet demonstrated by us. Other languages produce signal receipts without field-level classification.
  • Certifications

    In progress, not complete

    Charter and trial customers get the control narrative and the gap list as it stands. We'd rather lose a deal than imply an attestation we don't hold.

Everything in the second list either becomes a demonstration or comes off this page. Ask for the current version of it before the demo — it's the fastest way to find out whether this is worth either of our time.

Pricing

Priced by scope. Never metered.

A bad quarter costing more than a quiet one is an incentive pointed the wrong way. Tiers are priced on vaults, retention, isolation and support — never on how many receipts your systems produced.

Charter$30Kper year · locked for life
  • For design partners shaping the roadmap
  • Direct line to the team, DSR working-group seat
  • Up to 15 seats · one vault · single framework
  • Two-year receipt retention
  • Limited seats
Standard · recommended$10Kper month · billed annually
  • One vault, full receipt lifecycle, framework mapping
  • 30 admin seats · unlimited auditor invitations
  • Five-year retention · SSO/SAML · governance log
  • Offline verification and exportable evidence bundles
  • 14-day trial, fully featured, no card
Enterprise$300K+per year · custom contract
  • Multi-vault, isolated tenant, custom retention
  • Uptime, support and incident-response commitments written into the agreement
  • Procurement-grade review
  • Sovereign deployments from $1M a year

No receipt quota and no overage on any tier — a quarter with four hundred incidents costs what a quarter with four costs. The trial runs fourteen days from signup, and it needs a work email address: a vault is identified by an organisation, so personal domains are declined at signup.

Reasonable objections

Questions we would ask too.

We already have Datadog and PagerDuty.
Keep them — they're inputs. They observe and they page; neither produces a sealed, offline-verifiable record of what arrived and what changed. Different layer, not a replacement, and Déjà is worth nothing without them.
Why should we trust your attribution?
You shouldn't have to. Scoring is deterministic and published, the score travels on the receipt, and where confidence is below threshold or nothing matched the receipt states that instead. A system that records its uncertainty explicitly is the only kind worth checking.
What if it attributes the wrong change?
Then the receipt carries the score and the margin, and an engineer can see the second candidate was 0.004 behind. That's why the number is on the artifact rather than behind it. Where two candidates sit inside the tie band, the receipt is sealed as low confidence rather than as a finding.
What happens to our evidence if you shut down?
Signed receipts remain signature-verifiable offline against a published key, and an audit engagement's period report remains independently integrity-checkable. None of that depends on us being reachable — or existing. The ledger export does not hold everything: it takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE.
Our auditors won't accept this.
They don't have to accept it — they verify it, on their own machine, without an account. Bring your audit firm into the trial; that's what the trial is for, and their objections are more useful to us than our answers are to them.
Does this satisfy DORA or Part 500?
No, and be wary of anyone who says it does. Déjà supplies the record. Filing, determination, classification and certification remain with your named accountable individuals, and no vendor can take that on for you.

Has an examiner ever asked for a record you couldn't produce?

Fourteen days to decide. Bring your auditor.