Skip to content
Financial services · asset management

Your examiner asks what changed. Answer with a record, not a reconstruction.

A firm your size runs many platforms, on many vendors' tools, built by many engineering teams. You do not start with all of them. Start with one platform: Déjà writes down at the time, and signs, which change it can tie each scored failure to and which it can't, and your examiner checks that record on their own machine.

Today: attribution of field changes in Python, TypeScript and JavaScript, plus Protobuf and Avro schemas. Demonstrated end to end on GitHub, Sentry and outbound webhook delivery. Data held in US West (N. California) · us-west-1 only. No SOC 2 report is complete. Type I is in preparation.

01 · The question you keep being asked

The same question, Three ways it arrives.

Internal audit, an examiner and a client each ask what changed and what you knew. Here is what Déjà hands over to each, and where it stops.

  • Internal audit, testing change management

    Which change broke production, and what did you know at the time?

    What Déjà hands over
    An attribution receipt (R1), signed when it was issued, naming the repository, the pull request, the field it removed, renamed or retyped, the score and the scoring version. Déjà issues one when the score reaches 0.80; from 0.60 it issues a low-confidence record (R1-L) instead. Where a deploy ran under a ServiceNow change number, that change record is shown beside the receipt.
    Where it stops
    It covers one failure mode: a producer removed, renamed or retyped a field and a consumer broke on it. The ServiceNow change record is shown beside the receipt, not scored and not in its signed bytes.
  • An examination request

    Show us every production incident in the period, and what you recorded when it happened.

    What Déjà hands over
    A scoped, expiring engagement. Your examiner or auditor opens a token link with no Déjà account, sees the receipts in scope, and downloads the period report: a bundle with a signed manifest and one signed file for each R1, R1-L and R1-N receipt in scope, which dsr-verifier-cli checks on their own machine. Signals from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana are sealed when Déjà scores them: each one that reaches scoring ends in a signed receipt, whether or not a cause is found.
    Where it stops
    Issuance time is asserted by Déjà and not externally anchored. The verifier's public release: [Awaiting owner: public release of the verifier CLI]
  • A client's due-diligence questionnaire

    How do you control changes to your systems, and your vendors' access to them?

    What Déjà hands over
    Your governance ledger. Changes to sign-in, connectors, signing keys, roles and auditor access are written as signed governance receipts (RG), each chained by hash to the one before it, back to your organisation's signed genesis receipt. The ledger export takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE receipts. Each receipt in it is a signed file dsr-verifier-cli checks on its own; the bundle the CLI checks as a whole is the period report of an audit engagement. A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
    Where it stops
    No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
02 · Where it sits against your regimes

A record for your examination file. Not a claim that your obligation is discharged.

Receipts map evidence to the controls below, in each standard's own references. Every regime a regulated firm asks about has a row, including the ones Déjà does not map, because a table that leaves a regime out reads as a claim about it.

SOC 2Mapped

CC2.2CC7.2CC7.3CC7.4CC7.5CC8.1CC9.2

Common criteria of the 2017 Trust Services Criteria. Every other criterion is evidenced outside Déjà.

CC7.4 and CC7.5 are evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet.

NYDFS Part 500Mapped

500.2500.16

23 NYCRR Part 500, as amended in November 2023. Every other section is evidenced outside Déjà.

ISO 27001Mapped

A.5.24A.8.32

ISO/IEC 27001:2022 Annex A: incident management planning and change management.

HIPAAMapped

164.308(a)(1)164.308(a)(6)164.308(a)(8)

The Security Rule's administrative safeguards, 45 CFR 164.308.

164.308(a)(8) is evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet.

DORAOwner view only · pending counsel

DORA.2DORA.3DORA.4DORA.5DORA.6

Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the regulation's references, and left out of the auditor's evidence pack until then. Data is held in the US only today.

DORA.3 is evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet.

SR 11-7Owner view only · pending counsel

SR11-7.1SR11-7.2SR11-7.3SR11-7.4SR11-7.5

Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.

SR11-7.5 is evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet.

SOX ITGCNot mapped

Not mapped. Supports change-management evidence through SOC 2 CC8.1, and through the ServiceNow change record a deploy ran under, which is shown beside the receipt. [Awaiting owner: counsel review of the SOX change-management wording]

SEC / FINRANot mapped

Not mapped. No control in Déjà's table names an SEC or FINRA rule.

FCANot mapped

Not mapped. No control in Déjà's table names an FCA rule, and data is held in the US only.

PCI DSSNot mapped

Not mapped. No control in Déjà's table names a PCI DSS requirement.

NIST CSFNot mapped

Not mapped. No control in Déjà's table names a NIST CSF function or category.

FedRAMPNot mapped

Not mapped, and Déjà holds no FedRAMP authorisation.

Receipts can be filed into ServiceNow GRC, Archer, Vanta or Drata. Each is in beta: built to the vendor's documented API, and not yet validated against a live instance by us.

Déjà supplies the record; the obligation stays with your named accountable individuals.

03 · How a large firm starts

One platform, not the estate.

The first buyer in a large group is one platform or business unit: a digital, data-platform or client-portal team. It fits today when its stack looks like this.

  • Source control

    Merged changes in GitHub or Azure DevOps

    Déjà reads merged pull requests from GitHub and Azure DevOps. GitHub is the path demonstrated end to end.
  • Code

    Services in Python, TypeScript or JavaScript, or .proto and .avsc contracts between teams

    Attribution reads the fields a change removed, renamed or retyped in those files. Anything else is recorded as unsupported and cannot be named as the cause.
  • Alerts

    An alert source whose alerts can name a field

    Sentry, Splunk On-Call and Alertmanager · Grafana are the scored sources whose alerts can name a field, so can end in an attribution. Demonstrated end to end today: GitHub, Sentry and outbound webhook delivery.
  • Deploys

    Deploys through GitHub Actions, CircleCI, Jenkins and other CI, Flux or Argo CD

    Each deploy to production is recorded against its commit. Scoring times a change from its recorded deploy rather than its merge, and from its merge when no deploy is recorded. A deployment setting, off by default, also leaves out a change recorded as deployed after the incident.
  • Identity

    Sign-in through Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity or JumpCloud

    With Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity, JumpCloud or any SAML 2.0 identity provider. The setup marks PingIdentity and JumpCloud as beta.

Then a vault per platform

Standard and Charter hold one vault. Enterprise and Sovereign set no vault cap, so each further platform gets its own vault, ledger and engagements under one organisation. On Enterprise and Sovereign, one auditor engagement can cover 2 to 10 vaults. Enterprise is $300K+/yr.

Your security team's review

A vendor you can audit the way you audit everyone else, including its own access to you.

Déjà staff access, approved by you
A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
SAML single sign-on
With Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity, JumpCloud or any SAML 2.0 identity provider. The setup marks PingIdentity and JumpCloud as beta.
OpenID Connect sign-in
With Auth0, Okta or any OpenID Connect (OIDC) provider.
SCIM 2.0 provisioning
Your identity provider adds, updates and suspends members through SCIM 2.0, with a token Déjà issues. Removing a member stays on the Team page. Each change to the token is a governance receipt.
Multi-factor authentication, required
Required on every paid plan. Members get 14 days to enrol; after that, sign-in and changes are refused until they do. An Owner can accept an identity provider's own MFA for sign-ins through it.
Audit log streamed to your SIEM
Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
Your own signing key (BYOK)
On Enterprise and Sovereign, a vault can sign with your AWS KMS key. Azure Key Vault and GCP KMS are not implemented.
Where it stops
No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none] Penetration test: [Awaiting owner: pen-test firm, dates, and whether a summary is shared] Vaults on Déjà's managed key sign with Ed25519, and every managed vault shares that one key. Enterprise and Sovereign vaults can sign with their own AWS KMS key instead, using RSA-PSS or ECDSA. Déjà's managed key is published with any key it has retired, so receipts signed with it verify offline. For vaults on their own KMS key, Déjà publishes the current public key of at most one such vault per organisation and no key that has been rotated out, so any other key an auditor needs comes from the customer. Data is held in US West (N. California) · us-west-1 only. The full register is on Security & trust.
04 · What doesn't fit yet

Better you read it here before a sales call does.

If one of these is a requirement for the platform you have in mind, Déjà does not fit it today.

EU or UK data residency, now
Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
An estate mostly in Java, .NET or Go
Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
GitLab, Bitbucket or GitHub Enterprise Server as your main source control
Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
A completed SOC 2 report before contract
No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
Alerting that is Datadog only
Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
05 · Model risk

Same inputs, same receipt.

Attribution is arithmetic: eight factors with published weights that sum to 1.00, and two thresholds: 0.80 for an attribution (R1), 0.60 for a low-confidence record (R1-L). No learned weights.

Deterministic
Given the same inputs and the same reference time (nowMs, fixed when scoring starts), Déjà produces a byte-identical attribution receipt: the same canonical bytes and, on Déjà's managed Ed25519 key, the same signature. The inputs include database state: the field changes and producer-graph edges in the lookback window, the authors' earlier receipts, and the field's most recent change. So a re-run reproduces the receipt only while those rows are unchanged, which is the point: the receipt records the state at the time it was computed. A vault on its own RSA-PSS or ECDSA key signs the same bytes, and those schemes never give the same signature twice.
Versioned
Scoring version 1.0.13 is signed into every R1, R1-L and R1-N as scoring_version, so a receipt from one quarter can be checked against that quarter's rules. R1-L and R1-N receipts issued before version 1.0.9 carry none. The current weights are on the engine page.
SR 11-7Owner view only · pending counsel
Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.
06 · Who is building it

Built from the side of the desk that gets asked.

The founder spent fifteen years in financial services across wealth management, banking and asset management, in roles where producing evidence for an examiner was somebody's actual Tuesday.

[Awaiting owner: founder name and biography, if shown]

References

Charter programme open; no production customer deployments to reference yet.

[Awaiting owner: design partners or customers, each named only with written permission]

The company facts, and what we do not claim, are on About.

Bring one platform and one quarter.

Tell us which platform, which regimes it answers to and who signs off on its evidence. We will tell you plainly whether it fits today, and what would stop it.