The vendor review, answered before you ask.
Everything your questionnaire asks, answered in public. Every row says yes, no, partial or awaiting, with what it rests on.
For procurement and vendor-risk teams. Where an answer is the owner's to give, the row says so in place rather than filling the gap.
The questions every review asks.
- Yes
- 8
- Partial
- 2
- No
- 5
- Awaiting
- 2
- Single sign-on
- Yes
SAML 2.0 with Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity, JumpCloud or any SAML 2.0 identity provider, or OpenID Connect with Auth0, Okta or any OpenID Connect (OIDC) provider. The setup marks PingIdentity and JumpCloud as beta. On Standard, Charter, Enterprise and Sovereign.
Rests on: /security, access and identity
- SCIM provisioning
- Yes
Your identity provider adds, updates and suspends members through SCIM 2.0, with a token Déjà issues. Removing a member stays on the Team page. Each change to the token is a governance receipt. On Standard, Charter, Enterprise and Sovereign.
Rests on: /security, access and identity
- MFA enforced
- Yes
Required on every paid plan. Members get 14 days to enrol; after that, sign-in and changes are refused until they do. An Owner can accept an identity provider's own MFA for sign-ins through it.
Rests on: /security, access and identity
- Role-based access and custom roles
- Partial
Create and assign custom roles on Charter, Enterprise and Sovereign. Standard uses the built-in roles.
Rests on: /security, access and identity
- Audit log to your SIEM
- Yes
Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
Rests on: /security
- Vendor access approved by you
- Yes
A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors. This covers reads through Déjà's staff console.
Rests on: /security
- Bring your own key
- Partial
On Enterprise and Sovereign, a vault can sign with your AWS KMS key. Azure Key Vault and GCP KMS are not implemented.
Rests on: /security, key custody
- Encryption at rest and in transit
- Yes
At rest: AES-256 with managed key rotation. In transit: TLS 1.2 or higher, and TLS 1.3 where the client supports it.
Rests on: /security, handling
- EU or UK data residency
- No
Data is held in US West (N. California) · us-west-1 only. No EU or UK region is offered today. Residency, and the EU plan
Rests on: §05 below
- SOC 2 report
- No
No SOC 2 report is complete. Type I is in preparation. The report in the document pack
Rests on: /security, attestations
- Penetration test
- Awaiting
An independent engagement is in progress, with no report yet. [Awaiting owner: pen-test firm, dates, and whether a summary is shared]
Rests on: /security, attestations
- ISO 27001 certification
- No
No certification yet. A certification programme is planned alongside Enterprise general availability, in 2027.
Rests on: /security, attestations
- Uptime SLA
- No
Uptime is not measured yet, so Déjà publishes no uptime figure, and /status is not a service-level commitment. Contractual availability terms, where they exist, are set out in the customer agreement.
Rests on: /status
- Dedicated tenancy
- Awaiting
Tenancy is row-level in a shared database. Whether a dedicated deployment is offered: [Awaiting owner: whether a dedicated deployment is offered, and what it means]
Rests on: /security, handling
- Customer references
- No
Charter programme open; no production customer deployments to reference yet. Company facts
Rests on: /about, company facts
- Breach notification
- Yes
Without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer Data, under the DPA.
Rests on: DPA, breach notification
- Subprocessor change notice
- Yes
At least 30 days' written notice before a subprocessor is added or replaced, except where an urgent security or legal circumstance requires shorter, with a right to object.
Rests on: DPA, subprocessors
A row moves to yes only when the code does what it says. The placeholders are open questions with the owner, shown as they are rather than answered with a guess.
Who you would be contracting with.
- Legal
- Déjà, Inc. — Delaware C corporation
- Structure
- Founder-led, engineering team plus contract security and reliability specialists
- Funding
- Self-funded to date
- IP
- Patent applications pending on the schema deduction engine and the dual-layer ledger
- Standard
- DSR/1.0 — receipt and bundle format, published. Its verifier, dsr-verifier-cli, is in early access for customers: [Awaiting owner: public release of the verifier CLI]
- Customers
- Charter programme open; no production customer deployments to reference yet
Named customers and design partners: [Awaiting owner: design partners or customers, each named only with written permission]
What you can read now, and what you can't yet.
Public
The published text. A countersignable copy, with the annexes and the Standard Contractual Clauses completed, is available on request.
9 vendors, what each can see, and where it runs.
What Déjà collects, who processes it, how long it is kept, and how deletion works with an append-only ledger.
What the service does, how receipts and trials work, and what happens when the relationship ends.
Receipt format, signing scheme and verification procedure.
dsr-verifier-cli: Apache-2.0, needs no Déjà account. Documented at v1.7.1, the current version for customers with early access.
Under NDA
Data-minimisation pipeline, key management and tenant separation: the engineering detail behind /security.
Awaiting confirmation
SIG Lite and CAIQ responses
For your vendor-review process. [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents]
Control narrative and gap list
What is in place, and what is not yet. [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents]
Insurance certificate
Cyber and errors-and-omissions cover. [Awaiting owner: cyber and E&O insurance]
Penetration-test summary
The engagement is in progress. [Awaiting owner: pen-test firm, dates, and whether a summary is shared]
SOC 2 Type I report
No SOC 2 report is complete. Type I is in preparation. Reports go to customers under NDA on completion. [Awaiting owner: SOC 2 Type I target date, or none]
Verifier CLI general release
The documentation is public; the tool's general release is not yet. [Awaiting owner: public release of the verifier CLI]
Prices are public.
Standard
$10K/mo billed annually
- How you buy
- Self-serve
- Attribution receipt allowance
- 200 attribution receipts a month
- Retention commitment
- 5 years
Charter
$30K/yr
- How you buy
- By application
- Attribution receipt allowance
- 42 attribution receipts a month
- Retention commitment
- 2 years
Enterprise
$300K+/yr
- How you buy
- Through a conversation with us
- Attribution receipt allowance
- Unmetered
- Retention commitment
- Custom, per contract
Sovereign
$1M+/yr
- How you buy
- Through a conversation with us
- Attribution receipt allowance
- Unmetered
- Retention commitment
- Custom, per contract
- Auditor invitations: unlimited, on every plan, and an auditor never needs a Déjà account.
- Only R1 and R2 receipts count toward an allowance. Reaching 80% of it sends your Primary Owner a warning email, and going past it never blocks a receipt or bills an overage.
- Receipts are not deleted on any tier: no scheduled job deletes a receipt. A plan's retention period is the period its terms commit to, and the weekly retention sweep applies it only to incidents that no attribution or resolution receipt points at, and to records of signals that could not be taken in.
- A 14-day trial on Standard, with no card.
What each plan includes, side by side, is on Pricing.
Where your data is held, and what is on record.
- Held in
- US West (N. California) · us-west-1, and nowhere else.
- On record
- The region is written into your organisation's genesis receipt, the first receipt in its ledger, and cannot be changed afterwards. A different region means a new organisation.
- Transfers
- The DPA states that Customer Data is processed and stored in the United States, and that a transfer from the EEA, the UK or Switzerland relies on Standard Contractual Clauses or another recognised mechanism. The Standard Contractual Clauses are annexed to the signable copy of the DPA.
- EU and UK
- EU regional infrastructure is planned, and no date is published. No UK region exists in the product. [Awaiting owner: EU or UK residency date, if any]
Who answers, and how fast.
- Support response times
- [Awaiting owner: support response times]
- Security reports
- security@deja.dev. As Talk to us states it: “Vulnerability reports go straight to the security inbox and are acknowledged within one business day.”
- Everything else
- Security reviews, procurement questions and contract terms go through Talk to us, read by the people building the product.
Where Déjà does not fit yet.
If any of these is a requirement, it is cheaper for both of us to know now than after a security review.
EU or UK data residency, now
Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
An estate mostly in Java, .NET or Go
Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
GitLab, Bitbucket or GitHub Enterprise Server as your main source control
Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
A completed SOC 2 report before contract
No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
Alerting that is Datadog only
Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
Send us your questionnaire, and we will answer it in writing.
A written answer first, the current gap list included, and a straight no where Déjà does not fit.