Connect what you already run.
Regulated firms have years of investment in their observability, ITSM and chat tools. Déjà fits your stack — no rip-and-replace, no parallel tooling. Today, Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana alerts are scored against changes read from GitHub and Azure DevOps; every other connector is listed below with what it does now. Two marks, two meanings: Demonstrated end to end, and Connects.
Built for Heads of Risk, CISOs, audit-firm technologists, and security architects at firms operating under SOC 2 Type II, ISO 27001, NYDFS Part 500, DORA, or SR 11-7. Verifiable offline by your audit firm via dsr-verifier-cli.
Everything that connects, and what each does today.
- Demonstrated end to end
- It has produced its artefact end to end in a real organisation, as /status records it. Today that is GitHub, Sentry and outbound webhook delivery.
- Connects
- You can connect it today. That is not the same as scoring: the line under each tile says what it does now — scored, received, shown beside receipts, or delivered to.
A mark here means works with: never partner, certified or endorsed. Each is shown in one colour, beside the status we have measured for it.
Source control
Where the changes an incident is attributed to come from.
GitHub · cloud
Demonstrated end to endReads every merged pull request · imports the last two years on connecting
- Azure DevOps · ReposConnects
Reads every merged pull request · past ones are not imported
GitLab
ConnectsMerged changes not read yet · connects and registers its own webhooks
Deploy sources
Each deploy to production is recorded against its commit. Scoring times a change from its recorded deploy rather than its merge, and from its merge when no deploy is recorded. A deployment setting, off by default, also leaves out a change recorded as deployed after the incident.
- GitHub ActionsConnects
Deploys to an environment named production, read from GitHub Deployments
- CircleCIConnects
A workflow-completed webhook with a secret you choose
- Jenkins and other CIConnects
One HMAC-authenticated POST per deploy, from Jenkins' dejaDeploy library step or any CI
- FluxConnects
A generic-hmac Provider and an Alert that names the environment
- Argo CDConnects
Through GitHub Deployments, which Argo CD Notifications records for each sync
Change sources
Shown on a receipt when they happened in the 24 hours before its incident. They do not change what it attributes, and are not part of the signed record.
- LaunchDarklyConnects
Flag changes, shown beside receipts · not scored
- Terraform CloudConnects
Applied runs, shown beside receipts · not scored
- SpaceliftConnects
Applied runs, shown beside receipts · not scored
Observability & error tracking
Where alerts come from. Only a scored source's alerts end in a receipt.
Sentry
Demonstrated end to endScored · ends in an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N)
Datadog
ConnectsScored · always ends in a no-attribution record (R1-N)
Splunk On-Call
ConnectsScored
- Prometheus AlertmanagerConnects
Scored · beta · usually ends in R1-N
- Grafana AlertingConnects
Scored · beta · usually ends in R1-N
- AWS CloudWatchConnects
Received · whether it reaches scoring is being checked
- Azure MonitorConnects
Received · whether it reaches scoring is being checked
- Google Cloud MonitoringConnects
Received · whether it reaches scoring is being checked
- New RelicConnects
Received · not scored yet
- DynatraceConnects
Received · not scored yet
- HoneycombConnects
Received · not scored yet · Déjà posts an event into it when an incident resolves
- AppDynamicsConnects
Received · not scored yet
Splunk · alerts
ConnectsReceived · not scored yet
Incident & ITSM
PagerDuty
ConnectsReceived · whether it reaches scoring is being checked
- incident.ioConnects
Received · whether it reaches scoring is being checked · opens a Déjà incident
- RootlyConnects
Received · whether it reaches scoring is being checked · opens a Déjà incident
- FireHydrantConnects
Received · whether it reaches scoring is being checked · opens a Déjà incident
ServiceNow
ConnectsBeta · a work note on the matching incident, with the receipt attached
- Jira Service Management · Cloud and Data CenterConnects
Beta · opens an issue for each receipt
Chat & delivery
Outbound webhook
Demonstrated end to endHMAC-SHA256 Deja-Signature on each delivery, retry with backoff, and secret rotation with an overlap in which either secret verifies
Email
ConnectsSupported · up to 20 addresses, each confirmed by email
Slack
ConnectsSupported · posts to one channel
GRC evidence
Each is in beta: built to the vendor's documented API, and not yet validated against a live instance by us.
ServiceNow GRC
ConnectsBeta · files each receipt as evidence on one GRC control
- ArcherConnects
Beta · files each receipt as evidence on one record
- VantaConnects
Beta · files attributions (R1) and no-attribution records (R1-N) as SOC 2 evidence
- DrataConnects
Beta · files attributions (R1) and no-attribution records (R1-N) as SOC 2 evidence
Identity, SSO & SCIM
Single sign-on on every paid tier, Charter included.
- OktaConnects
SAML 2.0 or OIDC
- Azure ADConnects
SAML 2.0
- Google WorkspaceConnects
SAML 2.0
- OneLoginConnects
SAML 2.0
- PingIdentityConnects
SAML 2.0 · beta
- JumpCloudConnects
SAML 2.0 · beta
- Auth0Connects
OIDC
Any SAML 2.0 or OIDC identity provider
ConnectsA generic SAML 2.0 or OIDC setup
SCIM 2.0
ConnectsYour identity provider provisions people, with a token Déjà issues
SIEM & audit-log streams
Any SIEM with an HTTPS receiver
ConnectsYour organisation's audit log, each POST carrying an HMAC-SHA256 Deja-Signature header made with a secret Déjà issues
Keys (KMS)
- AWS KMSConnects
Your own signing key, on Enterprise and Sovereign
Your own tooling
REST API v1 · OpenAPI
ConnectsReads your data, verifies receipts and takes in signals, with scoped, expiring keys
Built in part, not connectable.
Each of these has code in the product, and none of it reaches you yet, so none gets a mark.
- Bitbucket
- Shown as coming soon in the app. Nothing connects it yet, and its merges are never read.
- GitHub Enterprise Server
- The GitHub setup stores an Enterprise Server URL, but nothing reads from it: merged pull requests are fetched only from github.com.
- Microsoft Teams
- No receipt delivery today.
- Rollbar
- Its webhook checks one secret shared by every organisation, so you cannot connect your own Rollbar account.
- Azure Key Vault
- Signing with a key held there is not implemented. Your own signing key must be in AWS KMS.
- Google Cloud KMS
- Signing with a key held there is not implemented. Your own signing key must be in AWS KMS.
- Alert sources
- 16
- Scored today
- 4
- Changes read from
- GitHub and Azure DevOps
- Receipt destinations
- 9
16 alert sources connect. Four are scored today.
An alert is scored against recent changes to find the one behind it, and scoring is what produces a receipt. A source that connects but is not scored yet sends alerts that Déjà receives but does not score.
- SentryInternal integration token and client secret
- ScoredEach alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).
- DatadogAPI key and site
- ScoredEach alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
- Splunk On-CallAPI ID and API key
- ScoredEach alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).
- Alertmanager · GrafanaA webhook URL and bearer secret Déjà issues, added to an Alertmanager receiver or a Grafana contact point
- ScoredEach alert becomes an incident and ends in a signed receipt. Infrastructure alerts (CPU, latency, error rate) usually name no field, so on their own they end in a no-attribution record (R1-N) reading that no field was extracted; they still give the incident its time and service.
- PagerDutyREST API key and webhook signing secret
- Being checkedIncidents are received. Whether PagerDuty's current webhook format reaches scoring is being checked, so no receipt is claimed for it here.
- AWS CloudWatchAn Amazon SNS topic subscribed to a URL Déjà issues; each message's signature is checked
- Being checkedEach alarm that enters ALARM opens an incident and its return to OK resolves it. An alarm that reaches scoring is scored on its name, which names a field only sometimes. No real CloudWatch delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
- Azure MonitorAn action group webhook to a URL Déjà issues, with basic authentication
- Being checkedEach alert that fires opens an incident and its resolved notification resolves it. An alert that reaches scoring is scored on its rule's name, which names a field only sometimes. No real Azure Monitor delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
- Google Cloud MonitoringA webhook notification channel to a URL Déjà issues, with basic authentication
- Being checkedEach incident that opens opens an incident here and its closing resolves it. One that reaches scoring is scored on its policy's and condition's names, which name a field only sometimes. No real Google Cloud Monitoring delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
- New RelicUser key and account ID
- Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
- DynatraceAccess token and environment URL
- Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
- HoneycombConfiguration key and team slug
- Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
- AppDynamicsClient name, client secret and controller URL
- Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
- incident.ioA webhook URL Déjà issues, and incident.io's signing secret
- Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
- RootlyA webhook URL and signing secret Déjà issues
- Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
- FireHydrantA webhook URL and signing secret Déjà issues
- Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
- Splunk (alerts)A webhook URL and token Déjà issues, added to a Splunk alert action
- Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
Changes are read from GitHub and Azure DevOps.
A merged pull request is what feeds the pattern parsers: every field it adds, removes, renames or retypes becomes a candidate an alert can be scored against. How it is read is set out in The Engine §02.
- GitHubGitHub App install
- ReadEvery merged pull request is read and parsed, through the Déjà GitHub App. Connecting imports the last two years of merged pull requests.
- GitHub Enterprise ServerAn Enterprise Server URL in the GitHub setup
- Not read yetThe GitHub setup accepts an Enterprise Server URL and stores it, but nothing reads from it: merged pull requests are fetched only from github.com, so changes on your instance are never candidates.
- Azure DevOpsPersonal access token (Code: Read) and a service hook
- ReadEvery completed pull request in Azure Repos is read and parsed, through a service hook and a personal access token. Past pull requests are not imported, and zones cannot list Azure DevOps repositories yet, so its changes carry no zone.
- GitLabPersonal, group or project access token
- Not read yetConnects, and Déjà registers its own webhooks, but merged merge requests are not read yet, so its changes are never candidates.
Other tools reach Déjà as an incident, not as themselves.
A tool that raises incidents in PagerDuty, or alerts in Splunk On-Call, reaches Déjà as that incident. What Déjà reads is what the hub sends; which tool raised it upstream is not used in scoring.
PagerDuty
- Read
- The incident's title, its service and its priority.
- Recorded as
- Error type
pagerduty_incident, with the title as the message and the service as the zone. - Which incidents
- P1–P4 by default, P5 off. You choose the priorities and the services.
- Set aside
- An incident that starts within 15 minutes of an incident from another connected source, by default.
Being checkedIncidents are received. Whether PagerDuty's current webhook format reaches scoring is being checked, so no receipt is claimed for it here.
Splunk On-Call
- Read
- The alert's title and its routing key.
- Recorded as
- Error type
splunk_oncall_alert, with the title as the message and the routing key as the zone. - Which alerts
- Recoveries are tracked and never scored. You choose the other alert types and the routing keys.
ScoredEach alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).
Déjà uses no stack trace or payload from either hub, so the title has to name the field, as an error message does. An alert whose title names no field ends in an R1-N recording that no field could be read — never in an attribution.
Déjà is not an on-call replacement — it produces attribution receipts. The on-call tool remains your incident-management system of record.
Where receipts are delivered.
Each status is the one the delivery reference gives the channel, and the reference says what each one sends.
- Outbound webhookYour HTTPS endpoint
- Demonstrated
- EmailRecipient addresses
- Supported
- SlackWorkspace incoming webhook
- Supported
- ServiceNowYour instance, via OAuth
- Beta
- Jira Service ManagementAtlassian cloud, via OAuth 3LO
- Beta
- ServiceNow GRCOne control on your instance, via OAuth
- Beta
- ArcherOne record on your instance, via its REST API
- Beta
- VantaDocuments linked to your SOC 2 controls, via an API application
- Beta
- DrataYour SOC 2 controls, via an API key
- Beta
What does not connect, and why.
- Microsoft Teams
- No receipt delivery today.
- Bitbucket
- Not connectable yet.
- Jira, outside Service Management
- Not connectable in the app. Receipts reach Jira Service Management, above.
- Everything else
- Only as an incident in PagerDuty or an alert in Splunk On-Call, on the terms above. Receipts are not relayed back through either hub to a chat tool.
Don't see your tool?
If it raises incidents in PagerDuty or alerts in Splunk On-Call, it reaches Déjà through the hub, on the terms in §03. Your SIEM can already receive your organisation's audit log over HTTPS, each POST carrying an HMAC-SHA256 Deja-Signature header, as an audit-log stream under Connections › Delivers to. For a first-party alert source we don't list, tell us the tool and the volume.