Two reviews ask what changed. One record answers both.
Your auditor tests how you run incidents and changes: SOC 2 CC7 and CC8, ISO 27001 A.5.24 and A.8.32. Then each regulated customer you sell to, a bank, an insurer, a health system, sends its vendor-risk review and asks the same thing. Déjà writes down at the time, and signs, which change it can tie each scored failure to and which it can't, so you answer both from the same record.
Today: attribution of field changes in Python, TypeScript and JavaScript, plus Protobuf and Avro schemas. Demonstrated end to end on GitHub, Sentry and outbound webhook delivery. Data held in US West (N. California) · us-west-1 only. No SOC 2 report is complete. Type I is in preparation.
The controls it maps evidence to, counted, not claimed.
Receipts map evidence to these controls, in each standard's own references. The coverage below is counted from Déjà's control table, and the rest of each standard is evidenced outside Déjà.
SOC 2
MappedAICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria
7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.
- CC2.2Internal communication of objectives and responsibilities for internal controlEvidenced by R1R2RG
- CC7.2Monitoring of system components for anomaliesEvidenced by R1R1-L
- CC7.3Evaluation of security eventsEvidenced by R1R1-LR1-N
- CC7.4Response to identified security incidentsEvidenced by R2
- CC7.5Recovery from identified security incidentsEvidenced by R2
- CC8.1Authorization, design, testing, approval and implementation of changesEvidenced by R1
- CC9.2Vendor and business partner risk managementEvidenced by RG
CC7.4 and CC7.5 are evidenced only by a resolution receipt. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic.
ISO 27001
MappedISO/IEC 27001:2022, Annex A
2 of the 2 ISO 27001 controls listed here have a receipt type that maps evidence to them. Only those are listed: the rest of the standard is evidenced outside Déjà.
- A.5.24Information security incident management planning and preparationEvidenced by R1R1-LR2
- A.8.32Change managementEvidenced by R1R1-L
Every ISO 27001 control, and the ones evidenced outside Déjà
The regimes your customers name
- Also mapped
- NYDFS Part 500, HIPAA
- Your own Frameworks page only, pending counsel
- DORA, SR 11-7
- Not mapped
- SOX ITGC, SEC / FINRA, FCA, PCI DSS, NIST CSF, HITRUST CSF, FedRAMP
These map evidence to your controls under each regime, never your customer's. Every regime, with what each row means, is on Compliance.
Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.
It evidences your controls, not your customer's.
Receipts record changes to your repositories and failures in your production, and map evidence to your controls. They are not evidence of your customer's own controls. What a customer sees is what you hand over.
Who sees what
- You
- Your organisation's ledger, under the roles you assign. Only an Owner answers a Déjà staff-access request; Owners and Admins see every access and export it.
- Your auditor, or your customer's
- Only the receipts inside an engagement you open: its period, its service zones, and the receipt types its frameworks decide. An attribution receipt names the repository, the pull request and the field, so the scope you set is what they read.
- Your customer's vendor-risk team
- What you choose to hand over: a staff-access export, your governance receipts, your SIEM's record of Déjà, or an engagement you open for their auditor.
- Déjà staff
- A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
What your customer can be shown
Your vendor's access to you, approved by you
- What you can show
- A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors. Déjà issues a governance receipt for each approval, decline and end.
- Where it stops
- It covers reads through Déjà's staff console.
Your governance receipts
- What you can show
- Changes to single sign-on, custom roles, staff access and auditor engagements are written as signed governance receipts (RG), each chained by hash to the one before it, back to your organisation's signed genesis receipt. The integrity monitor checks that chain every 15 minutes.
- Where it stops
- A governance receipt signs who made a change, what kind of change it was and when, with the settings before and after as hashes, not as written. An engagement's period report packs only R1, R1-L and R1-N receipts; governance receipts reach a reviewer in the ledger export. The ledger export takes up to 2,500 receipts at a time and leaves out R0, R2-F, R2-R, RV and RE receipts. Each receipt in it is a signed file dsr-verifier-cli checks on its own; the bundle the CLI checks as a whole is the period report of an audit engagement.
Déjà's activity in your SIEM
- What you can show
- Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
- Where it stops
- It sends every entry of your organisation's audit log, from every vault, with each person's name, email and IP address, so it is your whole log, not one customer's slice. Adding or resuming a stream takes an Owner or Admin who can open every vault.
An engagement your customer's auditor checks offline
- What you can show
- Open a scoped, expiring engagement for their auditor. They need no Déjà account, and they verify the period report on their own machine. The Primary Owner, an Owner, an Admin or a Compliance Lead of the vault can open an engagement, and so can a member whose custom role grants sharing with an external auditor.
- Where it stops
- The verifier's public release: [Awaiting owner: public release of the verifier CLI]
How an engagement runs
You open a scoped, expiring engagement
Name the audit firm, the period, the service zones and the frameworks; the frameworks decide which receipt types are in scope. Access ends on the day you choose, at most 365 days out (90 by default), and you can revoke it sooner.Your auditor opens a token link
No Déjà account is needed. The link alone admits them, and it stops working when the engagement ends or is revoked.They see the receipts in scope
Only the receipts inside the engagement's period, zones and receipt types. Each view and download is logged against the engagement.They download the period report
A bundle with a signed manifest and one signed receipt file for each R1, R1-L and R1-N receipt in scope. Other receipt types in scope are listed in the portal but not packed. It is the bundle dsr-verifier-cli checks as a whole.They verify it on their own machine
With dsr-verifier-cli against Déjà's published keys, choosing the key whose validity window contains each receipt's issue time.
Déjà is a vendor too
A customer that reviews your vendors will ask about Déjà. No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none] Questionnaires: [Awaiting owner: whether SIG Lite, CAIQ and the control narrative exist as documents] The DPA gives at least 30 days' written notice before a subprocessor is added or replaced. The documents are on Procurement and the register on Security & trust.
What it reads today, and where it doesn't.
Déjà runs nothing inside your network. Besides receiving webhooks, it calls the APIs of the tools you connect, with the access you grant — for example to import past pull requests, fetch each merged pull request's files, and check once a day that the GitHub App is still installed.
- Source control
GitHubRead
Every merged pull request is read and parsed, through the Déjà GitHub App. Connecting imports the last two years of merged pull requests.
GitHub Enterprise ServerNot read yet
The GitHub setup accepts an Enterprise Server URL and stores it, but nothing reads from it: merged pull requests are fetched only from github.com, so changes on your instance are never candidates.
Azure DevOpsRead
Every completed pull request in Azure Repos is read and parsed, through a service hook and a personal access token. Past pull requests are not imported, and zones cannot list Azure DevOps repositories yet, so its changes carry no zone.
GitLabNot read yet
Connects, and Déjà registers its own webhooks, but merged merge requests are not read yet, so its changes are never candidates.
- Languages
Attribution reads the fields a change removed, renamed or retyped in:
Python .pyTypeScript .ts .tsxJavaScript .js .jsx .mjs .cjsProtobuf .protoAvro .avscJava, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported and cannot be named as the cause.
- Demonstrated end to end
GitHubSource control
Reads every merged pull request · imports the last two years on connecting
SentryObservability & error tracking
Scored · ends in an attribution (R1), a low-confidence record (R1-L) or a no-attribution record (R1-N)
Outbound webhookChat & delivery
HMAC-SHA256 Deja-Signature on each delivery, retry with backoff, and secret rotation with an overlap in which either secret verifies
- Deploy sources
GitHub ActionsConnects
Deploys to an environment named production, read from GitHub Deployments
CircleCIConnects
A workflow-completed webhook with a secret you choose
Jenkins and other CIConnects
One HMAC-authenticated POST per deploy, from Jenkins' dejaDeploy library step or any CI
FluxConnects
A generic-hmac Provider and an Alert that names the environment
Argo CDConnects
Through GitHub Deployments, which Argo CD Notifications records for each sync
Each deploy to production is recorded against its commit. Scoring times a change from its recorded deploy rather than its merge, and from its merge when no deploy is recorded. A deployment setting, off by default, also leaves out a change recorded as deployed after the incident.
Every tool that connects today, and what each does now, is on Integrations.
Two ways to start, on the public price list.
Standard has a 14-day trial and needs no card. Only R1 and R2 receipts count toward an allowance, and crossing it blocks nothing: your Primary Owner gets an email at 80%.
Standard
- Price
- $10K/mo billed annually
- How you buy
- Self-serve · 14-day trial, no card needed
- Allowance
- 200 attribution receipts a month
- Admin seats
- 30
- Vaults
- 1
- Single sign-on
- SAML, OIDC and SCIM
- Custom roles
- Built-in roles only
- Auditor invitations
- Unlimited, with no cap on live engagements
Charter
- Price
- $30K/yr
- How you buy
- By application · No trial
- Allowance
- 42 attribution receipts a month
- Admin seats
- 15
- Vaults
- 1
- Single sign-on
- SAML, OIDC and SCIM
- Custom roles
- Yes
- Auditor invitations
- Unlimited, with one live engagement per vault at a time
Several customers' auditors at once is a Standard need: on Charter a vault has one live engagement at a time, and another can be opened only once it ends or is revoked. Every tier, and what varies between them, is on Pricing.
Better you read it here before a sales call does.
If one of these is a requirement for you, or for the customer you are selling to, Déjà does not fit it today.
- EU or UK data residency, now
- Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
- An estate mostly in Java, .NET or Go
- Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
- GitLab, Bitbucket or GitHub Enterprise Server as your main source control
- Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
- A completed SOC 2 report before contract
- No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
- Alerting that is Datadog only
- Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.
Connect one repository and one alert source.
The Standard trial is 14 days, with no card. Or tell us which customer review is coming and which controls it asks about, and we will say plainly which ones a receipt maps evidence to.