Skip to content
Integrations

Connect what you already run.

Regulated firms have years of investment in their observability, ITSM and chat tools. Déjà fits your stack — no rip-and-replace, no parallel tooling. Today, Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana alerts are scored against changes read from GitHub and Azure DevOps; every other connector is listed below with what it does now. Two marks, two meanings: Demonstrated end to end, and Connects.

Built for Heads of Risk, CISOs, audit-firm technologists, and security architects at firms operating under SOC 2 Type II, ISO 27001, NYDFS Part 500, DORA, or SR 11-7. Verifiable offline by your audit firm via dsr-verifier-cli.

Works with

Everything that connects, and what each does today.

Demonstrated end to end
It has produced its artefact end to end in a real organisation, as /status records it. Today that is GitHub, Sentry and outbound webhook delivery.
Connects
You can connect it today. That is not the same as scoring: the line under each tile says what it does now — scored, received, shown beside receipts, or delivered to.

A mark here means works with: never partner, certified or endorsed. Each is shown in one colour, beside the status we have measured for it.

Source control

Where the changes an incident is attributed to come from.

  • GitHub · cloud

    Demonstrated end to end

    Reads every merged pull request · imports the last two years on connecting

  • Azure DevOps · Repos
    Connects

    Reads every merged pull request · past ones are not imported

  • GitLab

    Connects

    Merged changes not read yet · connects and registers its own webhooks

Deploy sources

Each deploy to production is recorded against its commit. Scoring times a change from its recorded deploy rather than its merge, and from its merge when no deploy is recorded. A deployment setting, off by default, also leaves out a change recorded as deployed after the incident.

  • GitHub Actions
    Connects

    Deploys to an environment named production, read from GitHub Deployments

  • CircleCI
    Connects

    A workflow-completed webhook with a secret you choose

  • Jenkins and other CI
    Connects

    One HMAC-authenticated POST per deploy, from Jenkins' dejaDeploy library step or any CI

  • Flux
    Connects

    A generic-hmac Provider and an Alert that names the environment

  • Argo CD
    Connects

    Through GitHub Deployments, which Argo CD Notifications records for each sync

Change sources

Shown on a receipt when they happened in the 24 hours before its incident. They do not change what it attributes, and are not part of the signed record.

  • LaunchDarkly
    Connects

    Flag changes, shown beside receipts · not scored

  • Terraform Cloud
    Connects

    Applied runs, shown beside receipts · not scored

  • Spacelift
    Connects

    Applied runs, shown beside receipts · not scored

Observability & error tracking

Where alerts come from. Only a scored source's alerts end in a receipt.

  • Sentry

    Demonstrated end to end

    Scored · ends in an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N)

  • Datadog

    Connects

    Scored · always ends in a no-attribution record (R1-N)

  • Splunk On-Call

    Connects

    Scored

  • Prometheus Alertmanager
    Connects

    Scored · beta · usually ends in R1-N

  • Grafana Alerting
    Connects

    Scored · beta · usually ends in R1-N

  • AWS CloudWatch
    Connects

    Received · whether it reaches scoring is being checked

  • Azure Monitor
    Connects

    Received · whether it reaches scoring is being checked

  • Google Cloud Monitoring
    Connects

    Received · whether it reaches scoring is being checked

  • New Relic
    Connects

    Received · not scored yet

  • Dynatrace
    Connects

    Received · not scored yet

  • Honeycomb
    Connects

    Received · not scored yet · Déjà posts an event into it when an incident resolves

  • AppDynamics
    Connects

    Received · not scored yet

  • Splunk · alerts

    Connects

    Received · not scored yet

Incident & ITSM

  • PagerDuty

    Connects

    Received · whether it reaches scoring is being checked

  • incident.io
    Connects

    Received · whether it reaches scoring is being checked · opens a Déjà incident

  • Rootly
    Connects

    Received · whether it reaches scoring is being checked · opens a Déjà incident

  • FireHydrant
    Connects

    Received · whether it reaches scoring is being checked · opens a Déjà incident

  • ServiceNow

    Connects

    Beta · a work note on the matching incident, with the receipt attached

  • Jira Service Management · Cloud and Data Center
    Connects

    Beta · opens an issue for each receipt

Chat & delivery

  • Outbound webhook

    Demonstrated end to end

    HMAC-SHA256 Deja-Signature on each delivery, retry with backoff, and secret rotation with an overlap in which either secret verifies

  • Email

    Connects

    Supported · up to 20 addresses, each confirmed by email

  • Slack

    Connects

    Supported · posts to one channel

GRC evidence

Each is in beta: built to the vendor's documented API, and not yet validated against a live instance by us.

  • ServiceNow GRC

    Connects

    Beta · files each receipt as evidence on one GRC control

  • Archer
    Connects

    Beta · files each receipt as evidence on one record

  • Vanta
    Connects

    Beta · files attributions (R1) and no-attribution records (R1-N) as SOC 2 evidence

  • Drata
    Connects

    Beta · files attributions (R1) and no-attribution records (R1-N) as SOC 2 evidence

Identity, SSO & SCIM

Single sign-on on every paid tier, Charter included.

  • Okta
    Connects

    SAML 2.0 or OIDC

  • Azure AD
    Connects

    SAML 2.0

  • Google Workspace
    Connects

    SAML 2.0

  • OneLogin
    Connects

    SAML 2.0

  • PingIdentity
    Connects

    SAML 2.0 · beta

  • JumpCloud
    Connects

    SAML 2.0 · beta

  • Auth0
    Connects

    OIDC

  • Any SAML 2.0 or OIDC identity provider

    Connects

    A generic SAML 2.0 or OIDC setup

  • SCIM 2.0

    Connects

    Your identity provider provisions people, with a token Déjà issues

SIEM & audit-log streams

  • Any SIEM with an HTTPS receiver

    Connects

    Your organisation's audit log, each POST carrying an HMAC-SHA256 Deja-Signature header made with a secret Déjà issues

Keys (KMS)

  • AWS KMS
    Connects

    Your own signing key, on Enterprise and Sovereign

Your own tooling

  • REST API v1 · OpenAPI

    Connects

    Reads your data, verifies receipts and takes in signals, with scoped, expiring keys

Not on this wall, and why

Built in part, not connectable.

Each of these has code in the product, and none of it reaches you yet, so none gets a mark.

Bitbucket
Shown as coming soon in the app. Nothing connects it yet, and its merges are never read.
GitHub Enterprise Server
The GitHub setup stores an Enterprise Server URL, but nothing reads from it: merged pull requests are fetched only from github.com.
Microsoft Teams
No receipt delivery today.
Rollbar
Its webhook checks one secret shared by every organisation, so you cannot connect your own Rollbar account.
Azure Key Vault
Signing with a key held there is not implemented. Your own signing key must be in AWS KMS.
Google Cloud KMS
Signing with a key held there is not implemented. Your own signing key must be in AWS KMS.
Alert sources
16
Scored today
4
Changes read from
GitHub and Azure DevOps
Receipt destinations
9
01 · Alert sources

16 alert sources connect. Four are scored today.

An alert is scored against recent changes to find the one behind it, and scoring is what produces a receipt. A source that connects but is not scored yet sends alerts that Déjà receives but does not score.

SentryInternal integration token and client secret
ScoredEach alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).
DatadogAPI key and site
ScoredEach alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
Splunk On-CallAPI ID and API key
ScoredEach alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).
Alertmanager · GrafanaA webhook URL and bearer secret Déjà issues, added to an Alertmanager receiver or a Grafana contact point
ScoredEach alert becomes an incident and ends in a signed receipt. Infrastructure alerts (CPU, latency, error rate) usually name no field, so on their own they end in a no-attribution record (R1-N) reading that no field was extracted; they still give the incident its time and service.
PagerDutyREST API key and webhook signing secret
Being checkedIncidents are received. Whether PagerDuty's current webhook format reaches scoring is being checked, so no receipt is claimed for it here.
AWS CloudWatchAn Amazon SNS topic subscribed to a URL Déjà issues; each message's signature is checked
Being checkedEach alarm that enters ALARM opens an incident and its return to OK resolves it. An alarm that reaches scoring is scored on its name, which names a field only sometimes. No real CloudWatch delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
Azure MonitorAn action group webhook to a URL Déjà issues, with basic authentication
Being checkedEach alert that fires opens an incident and its resolved notification resolves it. An alert that reaches scoring is scored on its rule's name, which names a field only sometimes. No real Azure Monitor delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
Google Cloud MonitoringA webhook notification channel to a URL Déjà issues, with basic authentication
Being checkedEach incident that opens opens an incident here and its closing resolves it. One that reaches scoring is scored on its policy's and condition's names, which name a field only sometimes. No real Google Cloud Monitoring delivery has been recorded yet, so whether one reaches scoring is being checked, and no receipt is claimed for it here.
New RelicUser key and account ID
Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
DynatraceAccess token and environment URL
Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
HoneycombConfiguration key and team slug
Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
AppDynamicsClient name, client secret and controller URL
Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
incident.ioA webhook URL Déjà issues, and incident.io's signing secret
Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
RootlyA webhook URL and signing secret Déjà issues
Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
FireHydrantA webhook URL and signing secret Déjà issues
Being checkedIncidents arrive by the platform's signed webhook and open a Déjà incident, which is scored when an affected service matches one of your service zones. No delivery from a real account has reached Déjà yet, so no receipt is claimed for it here.
Splunk (alerts)A webhook URL and token Déjà issues, added to a Splunk alert action
Not scored yetAlerts are received, but not scored yet, so no receipt is issued.
02 · Source control

Changes are read from GitHub and Azure DevOps.

A merged pull request is what feeds the pattern parsers: every field it adds, removes, renames or retypes becomes a candidate an alert can be scored against. How it is read is set out in The Engine §02.

GitHubGitHub App install
ReadEvery merged pull request is read and parsed, through the Déjà GitHub App. Connecting imports the last two years of merged pull requests.
GitHub Enterprise ServerAn Enterprise Server URL in the GitHub setup
Not read yetThe GitHub setup accepts an Enterprise Server URL and stores it, but nothing reads from it: merged pull requests are fetched only from github.com, so changes on your instance are never candidates.
Azure DevOpsPersonal access token (Code: Read) and a service hook
ReadEvery completed pull request in Azure Repos is read and parsed, through a service hook and a personal access token. Past pull requests are not imported, and zones cannot list Azure DevOps repositories yet, so its changes carry no zone.
GitLabPersonal, group or project access token
Not read yetConnects, and Déjà registers its own webhooks, but merged merge requests are not read yet, so its changes are never candidates.
03 · Through an on-call hub

Other tools reach Déjà as an incident, not as themselves.

A tool that raises incidents in PagerDuty, or alerts in Splunk On-Call, reaches Déjà as that incident. What Déjà reads is what the hub sends; which tool raised it upstream is not used in scoring.

  • PagerDuty

    Read
    The incident's title, its service and its priority.
    Recorded as
    Error type pagerduty_incident, with the title as the message and the service as the zone.
    Which incidents
    P1–P4 by default, P5 off. You choose the priorities and the services.
    Set aside
    An incident that starts within 15 minutes of an incident from another connected source, by default.
    Being checked

    Incidents are received. Whether PagerDuty's current webhook format reaches scoring is being checked, so no receipt is claimed for it here.

  • Splunk On-Call

    Read
    The alert's title and its routing key.
    Recorded as
    Error type splunk_oncall_alert, with the title as the message and the routing key as the zone.
    Which alerts
    Recoveries are tracked and never scored. You choose the other alert types and the routing keys.
    Scored

    Each alert that reaches scoring ends in a signed receipt: an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N).

Déjà uses no stack trace or payload from either hub, so the title has to name the field, as an error message does. An alert whose title names no field ends in an R1-N recording that no field could be read — never in an attribution.

Déjà is not an on-call replacement — it produces attribution receipts. The on-call tool remains your incident-management system of record.

04 · Destinations

Where receipts are delivered.

Each status is the one the delivery reference gives the channel, and the reference says what each one sends.

Outbound webhookYour HTTPS endpoint
Demonstrated
EmailRecipient addresses
Supported
SlackWorkspace incoming webhook
Supported
ServiceNowYour instance, via OAuth
Beta
Jira Service ManagementAtlassian cloud, via OAuth 3LO
Beta
ServiceNow GRCOne control on your instance, via OAuth
Beta
ArcherOne record on your instance, via its REST API
Beta
VantaDocuments linked to your SOC 2 controls, via an API application
Beta
DrataYour SOC 2 controls, via an API key
Beta
05 · Not here

What does not connect, and why.

Microsoft Teams
No receipt delivery today.
Bitbucket
Not connectable yet.
Jira, outside Service Management
Not connectable in the app. Receipts reach Jira Service Management, above.
Everything else
Only as an incident in PagerDuty or an alert in Splunk On-Call, on the terms above. Receipts are not relayed back through either hub to a chat tool.

Don't see your tool?

If it raises incidents in PagerDuty or alerts in Splunk On-Call, it reaches Déjà through the hub, on the terms in §03. Your SIEM can already receive your organisation's audit log over HTTPS, each POST carrying an HMAC-SHA256 Deja-Signature header, as an audit-log stream under Connections › Delivers to. For a first-party alert source we don't list, tell us the tool and the volume.