Regulated, audited from outside, shipping software every day.
Déjà is for organisations whose change and incident controls an outside auditor or examiner tests, and whose engineers ship every day. Sector by sector: the regimes Déjà maps evidence to, what fits, and what does not fit yet.
Seven sectors served today, each with what does not fit yet. Four not served yet, and why.
Seven sectors, and the regimes in each.
A receipt maps evidence to a control, never the whole of it: the rest of each control is tested outside Déjà. Every sector gets the same product; what changes is which regimes your auditors test you against, and which limits matter to you.
Banks and credit unions
Who reads this Internal audit and IT audit · Information security and third-party risk · Compliance · Model risk management
Read more · Financial servicesRegimes
- Maps evidence to
CC2.2, CC7.2, CC7.3, CC7.4 (R2 only), CC7.5 (R2 only), CC8.1, CC9.2
- Maps evidence to
NYDFS Part 500 · for NY-chartered or licensed institutions
500.2, 500.16
- Maps evidence to
A.5.24, A.8.32
- Owner's view only
SR 11-7
In Déjà's own numbering, on your own Frameworks page.
What fits
A signed record of which change a production failure was tied to, and of the failures nothing could be tied to, that your auditors check offline with no Déjà account. A Déjà staff read of your data through Déjà's staff console needs an Owner's approval and is listed.
What doesn't fit yet
SR 11-7. Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.
An estate mostly in Java, .NET or Go. Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
A completed SOC 2 report before contract. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
- Maps evidence to
Insurers
Who reads this Internal audit · Information security · Compliance · Engineering and SRE
Read more · Financial servicesRegimes
- Maps evidence to
NYDFS Part 500 · for insurers licensed in New York
500.2, 500.16
- Maps evidence to
CC2.2, CC7.2, CC7.3, CC7.4 (R2 only), CC7.5 (R2 only), CC8.1, CC9.2
- Maps evidence to
A.5.24, A.8.32
What fits
Evidence for incident response and change management, the parts of NYDFS Part 500, SOC 2 and ISO 27001 that Déjà's receipts map evidence to, handed to your auditor through a scoped engagement that expires.
What doesn't fit yet
A completed SOC 2 report before contract. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
An estate mostly in Java, .NET or Go. Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
- Maps evidence to
Asset and wealth managers, and broker-dealers
Who reads this Internal audit and IT audit · The CISO and vendor risk · Compliance · Engineering and SRE
Read more · Financial servicesRegimes
- Maps evidence to
CC2.2, CC7.2, CC7.3, CC7.4 (R2 only), CC7.5 (R2 only), CC8.1, CC9.2
- Maps evidence to
NYDFS Part 500 · for firms licensed by NYDFS
500.2, 500.16
- Maps evidence to
A.5.24, A.8.32
What fits
A signed attribution receipt names the pull request a field break was tied to, with its score, and a signed no-attribution receipt records what was examined when nothing cleared the threshold, across every team and vendor you connect.
What doesn't fit yet
SEC / FINRA. Not mapped. No control in Déjà's table names an SEC or FINRA rule.
A completed SOC 2 report before contract. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
- Maps evidence to
Payments, fintech and crypto
Who reads this Compliance · Information security · Engineering and SRE
Read more · Financial servicesRegimes
- Maps evidence to
NYDFS Part 500 · for licensed money transmitters and virtual-currency businesses
500.2, 500.16
- Maps evidence to
CC2.2, CC7.2, CC7.3, CC7.4 (R2 only), CC7.5 (R2 only), CC8.1, CC9.2
- Maps evidence to
A.5.24, A.8.32
What fits
Change and incident evidence your auditor verifies offline, with sign-in through your identity provider, SCIM provisioning and required MFA, and a signed governance receipt when an admin changes SSO, rotates a signing key or connects a tool.
What doesn't fit yet
PCI DSS. Not mapped. No control in Déjà's table names a PCI DSS requirement.
An estate mostly in Java, .NET or Go. Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
- Maps evidence to
Healthcare, health tech and health plans
Who reads this The HIPAA security official · Internal audit · Information security · Engineering and SRE
Read more · HealthcareRegimes
What fits
Receipts map evidence to three of the Security Rule's administrative safeguards in 45 CFR 164.308: security management process, security incident procedures and evaluation. The rest of the Security Rule is evidenced outside Déjà.
What doesn't fit yet
A business associate agreement. No business associate agreement (BAA) is published or offered on this site. [Awaiting owner: whether Déjà signs a HIPAA business associate agreement (BAA)]
Patient data in what Déjà reads. Déjà receives error events from the sources you connect and reads each pull request's diff, title and description; any of them can carry patient data. The diff, title and description are scrubbed of credential patterns, such as API keys and connection strings, not of health information.
SaaS and technology providers selling to regulated customers
Who reads this Security and trust teams answering vendor reviews · Engineering and SRE · Compliance
Read more · SaaS and technologyRegimes
What fits
Evidence for the vendor reviews your regulated customers run: a Déjà staff read through Déjà's staff console needs an Owner's approval and is listed; a signed governance receipt when an admin rotates a signing key, changes SSO, connects a tool or opens an audit engagement; and your organisation's audit log streamed to your SIEM over HTTPS.
What doesn't fit yet
A completed SOC 2 report before contract. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
GitLab, Bitbucket or GitHub Enterprise Server as your main source control. Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
Alerting that is Datadog only. Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
EU financial entities
Who reads this ICT risk management · Internal audit · Compliance
Regimes
- Owner's view only
DORA
In Déjà's own numbering, on your own Frameworks page.
What fits
The same receipts, mapped to DORA on your own Frameworks page in Déjà's own numbering.
What doesn't fit yet
DORA. Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the regulation's references, and left out of the auditor's evidence pack until then. Data is held in the US only today.
EU or UK data residency, now. Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
No page of its own yet.
- Owner's view only
A control marked R2 only is evidenced only by a resolution receipt (R2). Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic.
A regime marked owner's view only is shown on your own Frameworks page in Déjà's numbering until counsel has reviewed the standard's references, and is left out of an auditor's evidence pack until then. Every regime, including the ones Déjà does not map, is on Compliance.
Who Déjà does not serve yet, and why.
If one of these is you, Déjà does not fit today, and it is better to know that now than in month two of an evaluation.
Public sector and FedRAMP
Not served yet
Not mapped, and Déjà holds no FedRAMP authorisation.
PCI-only programmes
Not served yet
Not mapped. No control in Déjà's table names a PCI DSS requirement.
Organisations that need EU or UK data residency now
Not served yet
Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
Estates mostly in Java, .NET or Go
Not served yet
Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
Bring your control matrix, and your sector's regimes.
We will say which rows a receipt maps evidence to, and which ones it does not. What Déjà does, job by job, is on Use cases; every regime and where Déjà stands on it is on Compliance.