Skip to content
SaaS and technology providers

Two reviews ask what changed. One record answers both.

Your auditor tests how you run incidents and changes: SOC 2 CC7 and CC8, ISO 27001 A.5.24 and A.8.32. Then each regulated customer you sell to, a bank, an insurer, a health system, sends its vendor-risk review and asks the same thing. Déjà writes down at the time, and signs, which change it can tie each scored failure to and which it can't, so you answer both from the same record.

Today: attribution of field changes in Python, TypeScript and JavaScript, plus Protobuf and Avro schemas. Demonstrated end to end on GitHub, Sentry and outbound webhook delivery. Data held in US West (N. California) · us-west-1 only. No SOC 2 report is complete. Type I is in preparation.

01 · Your SOC 2 and ISO 27001 evidence

The controls it maps evidence to, counted, not claimed.

Receipts map evidence to these controls, in each standard's own references. The coverage below is counted from Déjà's control table, and the rest of each standard is evidenced outside Déjà.

SOC 2

Mapped

AICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria

7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.

  • CC2.2Internal communication of objectives and responsibilities for internal controlEvidenced by R1R2RG
  • CC7.2Monitoring of system components for anomaliesEvidenced by R1R1-L
  • CC7.3Evaluation of security eventsEvidenced by R1R1-LR1-N
  • CC7.4Response to identified security incidentsEvidenced by R2
  • CC7.5Recovery from identified security incidentsEvidenced by R2
  • CC8.1Authorization, design, testing, approval and implementation of changesEvidenced by R1
  • CC9.2Vendor and business partner risk managementEvidenced by RG

CC7.4 and CC7.5 are evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic.

Every SOC 2 control, and the ones evidenced outside Déjà

ISO 27001

Mapped

ISO/IEC 27001:2022, Annex A

2 of the 2 ISO 27001 controls listed here have a receipt type that maps evidence to them. Only those are listed: the rest of the standard is evidenced outside Déjà.

  • A.5.24Information security incident management planning and preparationEvidenced by R1R1-LR2
  • A.8.32Change managementEvidenced by R1R1-L

Every ISO 27001 control, and the ones evidenced outside Déjà

The regimes your customers name

Also mapped
NYDFS Part 500, HIPAA
Your own Frameworks page only, pending counsel
DORA, SR 11-7
Not mapped
SOX ITGC, SEC / FINRA, FCA, PCI DSS, NIST CSF, HITRUST CSF, FedRAMP

These map evidence to your controls under each regime, never your customer's. Every regime, with what each row means, is on Compliance.

Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.

02 · Your customers' security review

It evidences your controls, not your customer's.

Receipts record changes to your repositories and failures in your production, and map evidence to your controls. They are not evidence of your customer's own controls. What a customer sees is what you hand over.

Who sees what

You
Your organisation's ledger, under the roles you assign. Only an Owner answers a Déjà staff-access request; Owners and Admins see every access and export it.
Your auditor, or your customer's
Only the receipts inside an engagement you open: its period, its service zones, and the receipt types its frameworks decide. An attribution receipt names the repository, the pull request and the field, so the scope you set is what they read.
Your customer's vendor-risk team
What you choose to hand over: a staff-access export, your governance receipts, your SIEM's record of Déjà, or an engagement you open for their auditor.
Déjà staff
A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.

What your customer can be shown

  • Your vendor's access to you, approved by you

    What you can show
    A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors. Déjà issues a governance receipt for each approval, decline and end.
    Where it stops
    It covers reads through Déjà's staff console.
  • Your governance receipts

    What you can show
    Changes to single sign-on, custom roles, staff access and auditor engagements are written as signed governance receipts (RG), each chained by hash to the one before it, back to your organisation's signed genesis receipt. The integrity monitor checks that chain every 15 minutes.
    Where it stops
    A governance receipt signs who made a change, what kind of change it was and when, with the settings before and after as hashes, not as written. An engagement's period report packs only R1, R1-L and R1-N receipts; governance receipts reach a reviewer in the ledger export. The ledger export takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE receipts. Each receipt in it is a signed file dsr-verifier-cli checks on its own; the bundle the CLI checks as a whole is the period report of an audit engagement.
  • Déjà's activity in your SIEM

    What you can show
    Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
    Where it stops
    It sends every entry of your organisation's audit log, from every vault, with each person's name, email and IP address, so it is your whole log, not one customer's slice. Adding or resuming a stream takes an Owner or Admin who can open every vault.
  • An engagement your customer's auditor checks offline

    What you can show
    Open a scoped, expiring engagement for their auditor. They need no Déjà account, and they verify the period report on their own machine. The Primary Owner, an Owner, an Admin or a Compliance Lead of the vault can open an engagement, and so can a member whose custom role grants sharing with an external auditor.
    Where it stops
    The verifier's public release: [Awaiting owner: public release of the verifier CLI]

How an engagement runs

  1. You open a scoped, expiring engagement

    Name the audit firm, the period, the service zones and the frameworks; the frameworks decide which receipt types are in scope. Access ends on the day you choose, at most 365 days out (90 by default), and you can revoke it sooner.
  2. Your auditor opens a token link

    No Déjà account is needed. The link alone admits them, and it stops working when the engagement ends or is revoked.
  3. They see the receipts in scope

    Only the receipts inside the engagement's period, zones and receipt types. Each view and download is logged against the engagement.
  4. They download the period report

    A bundle with a signed manifest and one signed receipt file for each R1, R1-L and R1-N receipt in scope. Other receipt types in scope are listed in the portal but not packed. It is the bundle dsr-verifier-cli checks as a whole.
  5. They verify it on their own machine

    With dsr-verifier-cli against Déjà's published keys, choosing the key whose validity window contains each receipt's issue time.

Déjà is a vendor too

A customer that reviews your vendors will ask about Déjà. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none] Questionnaires: [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents] The DPA gives at least 30 days' written notice before a subprocessor is added or replaced. The documents are on Procurement and the register on Security & trust.

03 · The stack it fits

What it reads today, and where it doesn't.

Déjà runs nothing inside your network. Besides receiving webhooks, it calls the APIs of the tools you connect, with the access you grant — for example to import past pull requests, fetch each merged pull request's files, and check once a day that the GitHub App is still installed.

Source control

GitHubRead

Every merged pull request is read and parsed, through the Déjà GitHub App. Connecting imports the last two years of merged pull requests.

GitHub Enterprise ServerNot read yet

The GitHub setup accepts an Enterprise Server URL and stores it, but nothing reads from it: merged pull requests are fetched only from github.com, so changes on your instance are never candidates.

Azure DevOpsRead

Every completed pull request in Azure Repos is read and parsed, through a service hook and a personal access token. Past pull requests are not imported, and zones cannot list Azure DevOps repositories yet, so its changes carry no zone.

GitLabNot read yet

Connects, and Déjà registers its own webhooks, but merged merge requests are not read yet, so its changes are never candidates.

Languages

Attribution reads the fields a change removed, renamed or retyped in:

Python .pyTypeScript .ts .tsxJavaScript .js .jsx .mjs .cjsProtobuf .protoAvro .avsc

Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported and cannot be named as the cause.

Demonstrated end to end

GitHubSource control

Reads every merged pull request · imports the last two years on connecting

SentryObservability & error tracking

Scored · ends in an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N)

Outbound webhookChat & delivery

HMAC-SHA256 Deja-Signature on each delivery, retry with backoff, and secret rotation with an overlap in which either secret verifies

Deploy sources

GitHub ActionsConnects

Deploys to an environment named production, read from GitHub Deployments

CircleCIConnects

A workflow-completed webhook with a secret you choose

Jenkins and other CIConnects

One HMAC-authenticated POST per deploy, from Jenkins' dejaDeploy library step or any CI

FluxConnects

A generic-hmac Provider and an Alert that names the environment

Argo CDConnects

Through GitHub Deployments, which Argo CD Notifications records for each sync

Each deploy to production is recorded against its commit. Scoring times a change from its recorded deploy rather than its merge, and from its merge when no deploy is recorded. A deployment setting, off by default, also leaves out a change recorded as deployed after the incident.

Every tool that connects today, and what each does now, is on Integrations.

04 · Pricing for a scale-up

Two ways to start, on the public price list.

Standard has a 14-day trial and needs no card. Only R1 and R2 receipts count toward an allowance, and crossing it blocks nothing: your Primary Owner gets an email at 80%.

Standard

Price
$10K/mo billed annually
How you buy
Self-serve · 14-day trial, no card needed
Allowance
200 attribution receipts a month
Admin seats
30
Vaults
1
Single sign-on
SAML, OIDC and SCIM
Custom roles
Built-in roles only
Auditor invitations
Unlimited, with no cap on live engagements

Charter

Price
$30K/yr
How you buy
By application · No trial
Allowance
42 attribution receipts a month
Admin seats
15
Vaults
1
Single sign-on
SAML, OIDC and SCIM
Custom roles
Yes
Auditor invitations
Unlimited, with one live engagement per vault at a time

Apply for Charter

Several customers' auditors at once is a Standard need: on Charter a vault has one live engagement at a time, and another can be opened only once it ends or is revoked. Every tier, and what varies between them, is on Pricing.

05 · What doesn't fit yet

Better you read it here before a sales call does.

If one of these is a requirement for you, or for the customer you are selling to, Déjà does not fit it today.

EU or UK data residency, now
Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
An estate mostly in Java, .NET or Go
Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
GitLab, Bitbucket or GitHub Enterprise Server as your main source control
Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
A completed SOC 2 report before contract
No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
Alerting that is Datadog only
Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.

Connect one repository and one alert source.

The Standard trial is 14 days, with no card. Or tell us which customer review is coming and which controls it asks about, and we will say plainly which ones a receipt maps evidence to.