Test the evidence without asking us for anything.
Once an engagement is open, you get a token link. You see the receipts in its scope, download a signed period report, and check that report on your own machine with dsr-verifier-cli against Déjà's published keys. No Déjà account is needed. The verifier is in early access for customers: [Awaiting owner: public release of the verifier CLI]
For internal audit and IT audit teams, and the external firm they work with, testing change and incident controls.
From a token link to a check on your own machine.
The Primary Owner, an Owner, an Admin or a Compliance Lead of the vault can open an engagement, and so can a member whose custom role grants sharing with an external auditor. Internal audit can open one itself when it holds one of those roles. The link then goes to whoever tests, your external firm or your own team.
You open a scoped, expiring engagement
Name the audit firm, the period, the service zones and the frameworks; the frameworks decide which receipt types are in scope. Access ends on the day you choose, at most 365 days out (90 by default), and you can revoke it sooner.Your auditor opens a token link
No Déjà account is needed. The link alone admits them, and it stops working when the engagement ends or is revoked.They see the receipts in scope
Only the receipts inside the engagement's period, zones and receipt types. Each view and download is logged against the engagement.They download the period report
A bundle with a signed manifest and one signed receipt file for each R1, R1-L and R1-N receipt in scope. Other receipt types in scope are listed in the portal but not packed. It is the bundle dsr-verifier-cli checks as a whole.They verify it on their own machine
With dsr-verifier-cli against Déjà's published keys, choosing the key whose validity window contains each receipt's issue time.
- Access, by default
- 90 days
- Access, at most
- 365 days
- Déjà account needed
- None
- Packed in the period report
- R1, R1-L and R1-N
Each download of the period report is itself a governance receipt in the audited organisation's ledger, written before the download link is handed over; if it cannot be written, the download is refused.
dsr-verifier-cli · Apache-2.0 · no Déjà account required · early access for customers · [Awaiting owner: public release of the verifier CLI]
What is signed, and what is only hashed.
A signed receipt carries a signature over its canonical payload, which you check offline against the published key. A hashed receipt carries a SHA-256 content hash: it shows the receipt has not changed, but binds it to no key.
| Receipt | Integrity | Period report |
|---|---|---|
| R1Attribution Receipt | Signed | Packed |
| R2Resolution Receipt | Signed | Not packed |
| R0Ingestion Receipt | Hashed | Not packed |
| R1-LLow-Confidence Attribution | Signed | Packed |
| R1-NNo-Attribution Receipt | Signed | Packed |
| R2-FResolution-Failed Receipt | Hashed | Not packed |
| R2-RResolution-Reopened Receipt | Hashed | Not packed |
| RGGovernance Receipt | Signed | Not packed |
| GENESISGenesis Receipt | Signed | Not packed |
| RVVerification Receipt | Signed | Not packed |
| REEngagement Receipt | Signed | Not packed |
Vaults on Déjà's managed key sign with Ed25519, and every managed vault shares that one key. Enterprise and Sovereign vaults can sign with their own AWS KMS key instead, using RSA-PSS or ECDSA. Déjà's managed key is published with any key it has retired, so receipts signed with it verify offline. For vaults on their own KMS key, Déjà publishes the current public key of at most one such vault per organisation and no key that has been rotated out, so any other key an auditor needs comes from the customer.
What it checks, and what it leaves out.
Every 15 minutes, Déjà's integrity monitor runs these checks, in this order:
- 1 · receipt sequence
- 2 · signature validity
- 3 · content hash
- 4 · key authority
- 5 · vault isolation
- 6 · verification schedule
- 7 · governance chain
- 8 · genesis anchor
- Checked
- R1
- R2
- RG
- GENESIS
- Not checked
- R1-L
- R1-N
- R0
- R2-F
- R2-R
- RE
The monitor reads none of these, so it would not report a fault in one.
RVis the record of a check: what the monitor writes, not something it checks.
The controls a receipt maps evidence to.
A receipt is evidence for a control, never the whole of it: the rest of each control is tested outside Déjà. Every regime a regulated firm asks about has a row here, including the ones Déjà does not map.
- SOC 2Maps evidence to
- CC2.2
- CC7.2
- CC7.3
- CC7.4 (evidenced only by an R2)
- CC7.5 (evidenced only by an R2)
- CC8.1
- CC9.2
Common criteria of the 2017 Trust Services Criteria. Every other criterion is evidenced outside Déjà.
- NYDFS Part 500Maps evidence to
- 500.2
- 500.16
23 NYCRR Part 500, as amended in November 2023. Every other section is evidenced outside Déjà.
- ISO 27001Maps evidence to
- A.5.24
- A.8.32
ISO/IEC 27001:2022 Annex A: incident management planning and change management.
- HIPAAMaps evidence to
- 164.308(a)(1)
- 164.308(a)(6)
- 164.308(a)(8) (evidenced only by an R2)
The Security Rule's administrative safeguards, 45 CFR 164.308.
- DORAOwner's view only
- DORA.2
- DORA.3 (evidenced only by an R2)
- DORA.4
- DORA.5
- DORA.6
Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the regulation's references, and left out of the auditor's evidence pack until then. Data is held in the US only today.
- SR 11-7Owner's view only
- SR11-7.1
- SR11-7.2
- SR11-7.3
- SR11-7.4
- SR11-7.5 (evidenced only by an R2)
Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.
- SOX ITGCNot mapped
Not mapped. Supports change-management evidence through SOC 2 CC8.1, and through the ServiceNow change record a deploy ran under, which is shown beside the receipt. [Awaiting owner: counsel review of the SOX change-management wording]
- SEC / FINRANot mapped
Not mapped. No control in Déjà's table names an SEC or FINRA rule.
- FCANot mapped
Not mapped. No control in Déjà's table names an FCA rule, and data is held in the US only.
- PCI DSSNot mapped
Not mapped. No control in Déjà's table names a PCI DSS requirement.
- NIST CSFNot mapped
Not mapped. No control in Déjà's table names a NIST CSF function or category.
- FedRAMPNot mapped
Not mapped, and Déjà holds no FedRAMP authorisation.
† Evidenced only by a resolution receipt (R2). Most organisations get no resolution receipt (R2) yet, so these controls usually get no evidence from Déjà; §05 says when one is issued. A regime marked owner's view only is shown on the audited organisation's own Frameworks page in Déjà's numbering, and is left out of your evidence pack.
What you cannot test with Déjà.
- Recovery controls, most of the time
- SOC 2 CC7.4, SOC 2 CC7.5, HIPAA 164.308(a)(8), DORA.3 and SR11-7.5 get evidence from a resolution receipt (R2) only. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic. Until one is issued, these controls get no evidence from Déjà. An R2 in an engagement's scope is listed in the portal, not packed in the period report.
- Independent issuance time
- Issuance time is asserted by Déjà, not externally anchored. A receipt's issue time comes from Déjà's own clock, and no timestamp authority or public log countersigns it. If your test depends on independent time, raise it before the engagement.
- The whole ledger in one file
- The ledger export takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE receipts. Each receipt in it is a signed file dsr-verifier-cli checks on its own; the bundle the CLI checks as a whole is the period report of an audit engagement.
- A source that went quiet
- Déjà does not yet alert you when a connected source stops sending, and in the ledger a quiet source looks the same as a quiet period.
- Which vault signed, from the signature alone
- Every vault on Déjà's managed key signs with the same Ed25519 key, so a signature shows that Déjà signed a receipt and that it has not changed since, not which organisation's vault it came from. On Enterprise and Sovereign, a vault can sign with its own AWS KMS key instead.
Evidence about the vendor itself.
Déjà staff access, approved by you
A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
Each approval, decline and end is a governance receipt. This covers reads through Déjà's staff console.
Governance receipts
Changes to how the audited organisation's evidence is kept are written as governance receipts (RG): signed, chained to the one before, and checked by the integrity monitor. They cover:
- Signal sources and integrations
- Delegated set-up
- Members and ownership
- The organisation
- Vaults and zones
- Service zones
- Frameworks
- Signing
- Sign-in and SSO
- Domains
- Access policy
- API keys
- Notification routing
- Déjà staff access
- Engagements and exports
- Evidence packs
- Billing
Audit log streamed to your SIEM
Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
Auditor access is per engagement, read-and-verify only, and never charged.
Each engagement has its own link. Through it an auditor reads, verifies and downloads, and sets the name shown against their activity; nothing in it changes a receipt or the engagement. Auditors hold no seat, and every plan allows unlimited auditor invitations.
The fields in each receipt's signed or hashed bytes are listed under receipt types.