Skip to content
Procurement · vendor review

The vendor review, answered before you ask.

Everything your questionnaire asks, answered in public. Every row says yes, no, partial or awaiting, with what it rests on.

For procurement and vendor-risk teams. Where an answer is the owner's to give, the row says so in place rather than filling the gap.

01 · Quick answers

The questions every review asks.

Yes
8
Partial
2
No
5
Awaiting
2
Single sign-on
Yes

SAML 2.0 with Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity, JumpCloud or any SAML 2.0 identity provider, or OpenID Connect with Auth0, Okta or any OpenID Connect (OIDC) provider. The setup marks PingIdentity and JumpCloud as beta. On Standard, Charter, Enterprise and Sovereign.

Rests on: /security, access and identity

SCIM provisioning
Yes

Your identity provider adds, updates and suspends members through SCIM 2.0, with a token Déjà issues. Removing a member stays on the Team page. Each change to the token is a governance receipt. On Standard, Charter, Enterprise and Sovereign.

Rests on: /security, access and identity

MFA enforced
Yes

Required on every paid plan. Members get 14 days to enrol; after that, sign-in and changes are refused until they do. An Owner can accept an identity provider's own MFA for sign-ins through it.

Rests on: /security, access and identity

Role-based access and custom roles
Partial

Create and assign custom roles on Charter, Enterprise and Sovereign. Standard uses the built-in roles.

Rests on: /security, access and identity

Audit log to your SIEM
Yes

Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.

Rests on: /security

Vendor access approved by you
Yes

A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors. This covers reads through Déjà's staff console.

Rests on: /security

Bring your own key
Partial

On Enterprise and Sovereign, a vault can sign with your AWS KMS key. Azure Key Vault and GCP KMS are not implemented.

Rests on: /security, key custody

Encryption at rest and in transit
Yes

At rest: AES-256 with managed key rotation. In transit: TLS 1.2 or higher, and TLS 1.3 where the client supports it.

Rests on: /security, handling

EU or UK data residency
No

Data is held in US West (N. California) · us-west-1 only. No EU or UK region is offered today. Residency, and the EU plan

Rests on: §05 below

SOC 2 report
No

No SOC 2 report is complete. Type I is in preparation. The report in the document pack

Rests on: /security, attestations

Penetration test
Awaiting

An independent engagement is in progress, with no report yet. [Awaiting owner: pen-test firm, dates, and whether a summary is shared]

Rests on: /security, attestations

ISO 27001 certification
No

No certification yet. A certification programme is planned alongside Enterprise general availability, in 2027.

Rests on: /security, attestations

Uptime SLA
No

Uptime is not measured yet, so Déjà publishes no uptime figure, and /status is not a service-level commitment. Contractual availability terms, where they exist, are set out in the customer agreement.

Rests on: /status

Dedicated tenancy
Awaiting

Tenancy is row-level in a shared database. Whether a dedicated deployment is offered: [Awaiting owner: whether a dedicated deployment is offered, and what it means]

Rests on: /security, handling

Customer references
No

Charter programme open; no production customer deployments to reference yet. Company facts

Rests on: /about, company facts

Breach notification
Yes

Without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer Data, under the DPA.

Rests on: DPA, breach notification

Subprocessor change notice
Yes

At least 30 days' written notice before a subprocessor is added or replaced, except where an urgent security or legal circumstance requires shorter, with a right to object.

Rests on: DPA, subprocessors

A row moves to yes only when the code does what it says. The placeholders are open questions with the owner, shown as they are rather than answered with a guess.

02 · Company facts

Who you would be contracting with.

Legal
Déjà, Inc. — Delaware C corporation
Structure
Founder-led, engineering team plus contract security and reliability specialists
Funding
Self-funded to date
IP
Patent applications pending on the schema deduction engine and the dual-layer ledger
Standard
DSR/1.0 — receipt and bundle format, published. Its verifier, dsr-verifier-cli, is in early access for customers: [Awaiting owner: public release of the verifier CLI]
Customers
Charter programme open; no production customer deployments to reference yet

Named customers and design partners: [Awaiting owner: design partners or customers, each named only with written permission]

03 · Document pack

What you can read now, and what you can't yet.

Public

  • Data processing addendum

    The published text. A countersignable copy, with the annexes and the Standard Contractual Clauses completed, is available on request.

  • Subprocessor list

    9 vendors, what each can see, and where it runs.

  • Privacy policy

    What Déjà collects, who processes it, how long it is kept, and how deletion works with an append-only ledger.

  • Terms of service

    What the service does, how receipts and trials work, and what happens when the relationship ends.

  • DSR/1.0 specification

    Receipt format, signing scheme and verification procedure.

  • Verifier CLI documentation

    dsr-verifier-cli: Apache-2.0, needs no Déjà account. Documented at v1.7.1, the current version for customers with early access.

Under NDA

  • Architecture pack

    Data-minimisation pipeline, key management and tenant separation: the engineering detail behind /security.

Awaiting confirmation

  • SIG Lite and CAIQ responses

    For your vendor-review process. [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents]

  • Control narrative and gap list

    What is in place, and what is not yet. [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents]

  • Insurance certificate

    Cyber and errors-and-omissions cover. [Awaiting owner: cyber and E&O insurance]

  • Penetration-test summary

    The engagement is in progress. [Awaiting owner: pen-test firm, dates, and whether a summary is shared]

  • SOC 2 Type I report

    No SOC 2 report is complete. Type I is in preparation. Reports go to customers under NDA on completion. [Awaiting owner: SOC 2 Type I target date, or none]

  • Verifier CLI general release

    The documentation is public; the tool's general release is not yet. [Awaiting owner: public release of the verifier CLI]

04 · Commercial terms

Prices are public.

Standard

$10K/mo billed annually

How you buy
Self-serve
Attribution receipt allowance
200 attribution receipts a month
Retention commitment
5 years

Charter

$30K/yr

How you buy
By application
Attribution receipt allowance
42 attribution receipts a month
Retention commitment
2 years

Enterprise

$300K+/yr

How you buy
Through a conversation with us
Attribution receipt allowance
Unmetered
Retention commitment
Custom, per contract

Sovereign

$1M+/yr

How you buy
Through a conversation with us
Attribution receipt allowance
Unmetered
Retention commitment
Custom, per contract
  • Auditor invitations: unlimited, on every plan, and an auditor never needs a Déjà account.
  • Only R1 and R2 receipts count toward an allowance. Reaching 80% of it sends your Primary Owner a warning email, and going past it never blocks a receipt or bills an overage.
  • Receipts are not deleted on any tier: no scheduled job deletes a receipt. A plan's retention period is the period its terms commit to, and the weekly retention sweep applies it only to incidents that no attribution or resolution receipt points at, and to records of signals that could not be taken in.
  • A 14-day trial on Standard, with no card.

What each plan includes, side by side, is on Pricing.

05 · Data and residency

Where your data is held, and what is on record.

Held in
US West (N. California) · us-west-1, and nowhere else.
On record
The region is written into your organisation's genesis receipt, the first receipt in its ledger, and cannot be changed afterwards. A different region means a new organisation.
Transfers
The DPA states that Customer Data is processed and stored in the United States, and that a transfer from the EEA, the UK or Switzerland relies on Standard Contractual Clauses or another recognised mechanism. The Standard Contractual Clauses are annexed to the signable copy of the DPA.
EU and UK
EU regional infrastructure is planned, and no date is published. No UK region exists in the product. [Awaiting owner: EU or UK residency date, if any]
06 · Support and contact

Who answers, and how fast.

Support response times
[Awaiting owner: support response times]
Security reports
security@deja.dev. As Talk to us states it: “Vulnerability reports go straight to the security inbox and are acknowledged within one business day.”
Everything else
Security reviews, procurement questions and contract terms go through Talk to us, read by the people building the product.
07 · Qualify us early

Where Déjà does not fit yet.

If any of these is a requirement, it is cheaper for both of us to know now than after a security review.

  • EU or UK data residency, now

    Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]

  • An estate mostly in Java, .NET or Go

    Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.

  • GitLab, Bitbucket or GitHub Enterprise Server as your main source control

    Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.

  • A completed SOC 2 report before contract

    No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]

  • Alerting that is Datadog only

    Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.

Send us your questionnaire, and we will answer it in writing.

A written answer first, the current gap list included, and a straight no where Déjà does not fit.