Verifiable evidence custody

The incident happened. Here's the deterministic proof.

When your auditor, your regulator, or your board asks what caused it and whether the fix held — Déjà hands them a cryptographically signed receipt: the incident, the pull request that caused it, the resolution, sealed at the moment each happened.

What changed, what broke, how it was fixed, who did it — one signed receipt.

Deterministic — not an LLM. No probabilistic guessing, no trace IDs, no screenshots.

Start the trial 14-day trial · no card · $10K/mo after
R1Attribution receiptDSR/1.0 · real, not a mockup
Incidentinc_01k2m9x4 · payments-checkout
Causepayments-api#412 · merged 14:02:11Z
ConfidenceCCS 0.96 · 8 weighted signals
Hashsha256:9f2c41…b417 · prior: 8c20fe…
Signatureed25519 · vault key deja.dev#01
Runs locally in your browser — we never see it happen.
Download receipt + verifier·dsr-verifier-cli · no account required
sev-1 · checkout-api · 03:07:41 utc

Checkout is down.

KeyError: total_cents — payments/checkout

The pager goes off. The clock starts.

§what happens next

The story scatters.

GitHub — the deployDatadog — the alertSlack — the callPR #482 — the fixServiceNow — the ticket

The outage ends at 3:07. The archaeology starts at nine.

§one signed receipt

Signed the moment it happens.

deployalertcallfixticket
receipt · r1illustrative
what changedtotal_cents removed · PR #482
what brokecheckout-api · KeyError · 03:07
how it was fixedrevert deploy · 03:19
who did itmerge s.okafor · deploy ci
sha256 9f2c…e41a · ed25519 ✓

Four answers, one artifact. Nothing to reconstruct.

§run it again

A guess drifts. Evidence repeats itself.

probable cause

score 0.81 · likelyscore 0.77 · likelyscore 0.84 · likely

different every run

signed receipt

run 19f2c…e41a
run 29f2c…e41a
run 39f2c…e41a

byte-identical

Deterministic means reproducible — same inputs, same bytes, every run.

§check the math

Verifiable without trusting us.

signaturevalid ✓
hash chainintact ✓
public keypublished ✓
verified — offline

Your audit firm checks it against a published key. Not our word — the math.

Stop writing postmortems by hand.

Cryptographic incident-evidence custody for regulated firms.

Déjà
01 / the break

—— The job this replaces

Stop writing postmortems by hand.

The outage ends at 3:07. The archaeology starts at nine.

When production breaks, the story scatters — the deploy in GitHub, the alert in Datadog, the fix in a PR, the call in Slack, the ticket in ServiceNow. In the morning, a senior engineer scrolls back through all five and rebuilds the story from memory — timeline disputed, evidence screenshotted, postmortem late.

GitHubthe changeDatadogthe alertPull requestthe fixSlackthe decisionsServiceNowthe ticket

These five are also the five places Déjà is already connected.

Déjà writes the record while the incident is still happening — what changed, what broke, how it was fixed, who did it — each link signed at the moment it occurred. When it's over, the facts of the postmortem already exist. The learning stays yours; the archaeology is gone.

know what changed · know what broke · signed at the moment it happened

A faster reconstruction is still a reconstruction.

After the fact

A quicker rebuild

Dashboards and timelines make the after-the-fact assembly faster. Probabilistic root-cause tools rank likely causes. Either way, the story is put together once it's over — and you're asked to trust it.

At the moment

No rebuild

Déjà attributes deterministically and signs each step as it occurs — hash-chained, reproducible, verifiable offline. Nothing to reassemble. Nothing taken on faith.

keep your stack — observability and paging are Déjà's inputs, not its replacement

How it works

Three steps. Then every incident signs itself.

01 · CONNECT

Connect your stack

GitHub for merge events, Datadog or PagerDuty for incident signals. Read-only scopes; we never touch code contents.

Setup: ~15 minutes

02 · ATTRIBUTE

Deterministic attribution

When an incident fires, the engine traces it to the causal pull request through the upstream producer graph — scored, not guessed.

Median: 1.6 seconds, at incident time

03 · SIGN

A receipt, sealed

Every stage gets an Ed25519-signed receipt in an append-only ledger — verifiable offline by your auditor, no Déjà account needed.

Standard: DSR/1.0 · open

—— Where the receipt lands

Signed to the ledger. Delivered where you work.

Every receipt forwards to the channels your team already lives in — at-least-once, with automatic retry, every attempt logged.

SlackEmailWebhookServiceNowJira Service Management
ServiceNow · INC0012047 — work note, attached by DéjàIllustrative
causepayments-api#412 · FIELD_REMOVED: currency_coderesolutionattested · fix holding (R2)scoreCCS 0.86 · eight weighted signalsreceiptrcpt_01k3m0x4 · byte-exact signed JSON attached
$ dsr-verifier-cli verify receipt.json  → signature valid · chain intact
attached to the right incident, or to none — never the wrong one

a failed delivery never means a lost receipt — channels only forward what's already on the chain

The part nobody else signs

Custody holds — signed. Custody breaks — also signed.

Verification passed

A signed clean report

Incident → cause → resolution, every link attributed, every hash continuous. The story your auditor hopes to see — provable.

ed25519 · signed at the moment it happened

Verification failed

A signed failure report

No cause found? Fix didn't hold? Confidence too low? The exception is signed too — a cryptographic record that you looked, and what you found.

ed25519 · the absence is evidence

Tools that only record successes are marketing. Evidence is whatever happened — which is why Déjà's exception receipts exist, and why auditors trust the ledger.

Pricing

Priced by scope. Not per-receipt.

Evidence shouldn't be metered — you never pay more because you had a bad month. Tiers scale by vault scope, and every receipt in scope is included.

Charter

$30K / year

For design partners shaping the roadmap. Limited seats, direct line to the team, locked pricing.

Standard

$10K / month · billed annually

One vault, full receipt lifecycle, framework mapping, offline verification. 14-day trial — fully featured, no card. Trial clock starts at your first signed receipt, not at signup. Trial receipts are watermarked and not audit-valid; production receipts are.

Enterprise

$300K+ / year

Multi-vault, custom retention, 99.99% SLA, custom data residency, procurement-grade security review. Sovereign deployments from $1M+/yr.

No per-receipt fees · no usage anxiety — an incident-heavy quarter costs the same as a quiet one.

Still reading? Good. The rest of this page is your diligence file.

Everything below is for the evaluation: the receipt standard, the trust model, the objections, the process you'd replace.

Diligence · the standard

Ten receipt types. One lifecycle.

They're not ten document kinds — they're stages of one incident's lifecycle, plus signed records of every place that lifecycle can break.

R0a signal arrives
R1a cause is attributed
R2a resolution is attested
Where it can break — signedR1-L low confidenceR1-N no matchR2-F fix failedR2-R recurredVault lifecycleRG governanceRV verificationRE engagement

The exception types are the moat. Attesting a resolution and the fix actually holding are different claims — R2-F and R2-R exist precisely for that gap, and competitors that only record successes can't represent it at all. Full spec: DSR/1.0 — open, in the docs.

Diligence · trust model

You don't have to trust Déjà to trust Déjà.

Independent verification, offline, forever

Every receipt verifies with open tooling on your auditor's machine — no Déjà account, no API call, no source-code access. If Déjà disappeared tomorrow, your evidence still verifies.

$ dsr-verifier-cli verify receipt.json → signature valid · chain intact

The substrate, not the platform

Your audit firm and GRC platform run on top of the ledger — receipts project onto whichever framework your engagement requires. One substrate, every framework; no configuration wizard that outlives the trial.

Anyone can verify it — your auditor, your regulator, your board — without trusting you, and without trusting us.

Diligence · objections

Objections worth answering.

"We already have Datadog and PagerDuty."

Keep them — they're Déjà's inputs. They observe incidents; neither produces signed, offline-verifiable evidence of cause and resolution. Different layer, not a replacement.

"Why should we trust your attribution?"

You shouldn't have to — that's the design. Attribution is deterministic and scored (CCS, eight weighted signals, thresholds published), and when confidence is low or no cause exists, the receipt says so. The system signs its own uncertainty.

"What happens to our evidence if you shut down?"

Receipts verify offline with open tooling against the published DSR/1.0 standard. Your ledger exports in full. Vendor death does not invalidate cryptographic signatures.

"Our auditors won't accept this."

They verify it themselves — independent Ed25519 verification on their machine is a stronger evidentiary posture than the screenshots and spreadsheets they accept today. Bring your audit firm to the trial; that's what it's for.

Diligence · the alternative

The process you'd replace.

Today · reconstruction

  • ·Screenshots of dashboards, pasted into evidence spreadsheets weeks later
  • ·Root cause reconstructed from memory and Slack archaeology
  • ·"The fix held" asserted, never verified
  • ·Evidence trusted because someone says so

With Déjà · custody

  • Signed at the moment it fires — no reconstruction, no recall
  • Cause attributed deterministically to the PR, scored and thresholded
  • Fix failures and recurrences signed too — the gap is on the record
  • Evidence trusted because anyone can verify it

The incident happened.
Here's the proof.

Fifteen minutes to your first signed receipt. Fourteen days to decide.

Start the trial

No card · trial receipts watermarked · production receipts audit-valid