A guess is not evidence.
Incident tools tell you what probably caused an outage, so you can fix it — a ranking that shifts when you re‑run it, with nothing to check. Déjà produces a deterministic, cryptographically‑verifiable record of what caused it: the same receipt, byte‑for‑byte, every time, checkable against a published key without taking our word for it.
Scope Strongest where it matters most for audit: cross‑service schema and payload errors — a downstream service breaking because an upstream one changed a field. Not a blanket claim to attribute every incident.
What they give you
A ranked guess
- PR #441 payments-svc61%
- PR #447 auth-edge24%
- config change infra9%
- PR #438 checkout-ui6%
Re-run it tomorrow and the ranking moves. There is nothing to verify — you trust the model.
What Déjà gives youIllustrative
A signed receipt
- type
- DSR/1.0 · R1 attribution
- incident
- #8c8f8c9a · downstream KeyError
- mutation
- FIELD_REMOVED · customer_tier
- caused by
- PR #447 · auth-edge
- confidence
- CCS 0.86
- trace_used
- false
- ledger
- append-only · hash-linked
sig: ed25519 · 4f9a…c0d3
key: published verification keysignature valid · verified against published key
Same inputs, same receipt — byte-for-byte, every time. Check the signature yourself. No trust required.
The difference is not the number. It is whether you can prove it.
| Probabilistic toolsML & correlation-based attribution | Déjàdeterministic evidence engine | |
|---|---|---|
| What you get | Probabilistic toolsA ranked list of likely causes | DéjàA signed receipt naming the cause |
| How it is decided | Probabilistic toolsML / statistical correlation scoring | DéjàA deterministic process over fixed inputs |
| Run it twice | Probabilistic toolsRanking can shift on re-run or retrain | DéjàThe same receipt — byte-for-byte |
| Can you verify it? | Probabilistic toolsNo — you trust the vendor model | DéjàYes — check the signature against a published key |
| Is it evidence? | Probabilistic toolsNo — a lead for a human to chase | DéjàYes — tamper-evident, audit-ready |
| Built for | Probabilistic toolsThe on-call engineer | DéjàThe compliance & audit team |
One feeds a model. The other runs a process.
Probabilistic — a likelihood that drifts
incident + 12 changesML modelrun 1 → PR #441run 2 → PR #447✕ different answer — nothing to verify
Déjà — a signed result you can reproduce
incident + 12 changesdeterministic enginerun 1 → PR #447 ✓run 2 → PR #447 ✓✓ identical receipt — byte-for-byte, signed & verifiable
Deterministic here means reproducible: the same inputs produce the same signed receipt. It is a process you can re-run and check — not a probability, and not a claim of certainty beyond the evidence.
Same inputs means the same time of issue and the same rows the engine reads. Byte-for-byte includes the signature when the receipt is signed with the Déjà-managed Ed25519 key; a vault that signs with its own RSA-PSS or ECDSA key gets the same signed bytes and a different signature each time.
The moat is the architecture — not the cryptography.
Determinism is not a promise; it is a consequence of what the engine refuses to use at runtime. That is the part that is patent-pending.
01
Pre-computed, not parsed live
The producer graph and field-level mutation records are built at merge time. So runtime attribution is a lookup against pre-computed evidence — not live source parsing, not a version-control query while the incident burns.
02
Four runtime exclusions
- Distributed tracing
- Runtime version-control queries
- Runtime source-code analysis
- ML / LLM inference
The score uses only table lookups and arithmetic.
03
Trace-independence, recorded
No trace ID is read at any stage. The engine's input has no field for one, and the receipts table constrains
trace_id_usedto false.
On the cryptography
The crypto is deliberately standard — SHA-256 and Ed25519, off the shelf. The novelty is what gets signed (a deterministic, field-level cross-service attribution) and how it is produced — not the signing. The moat does not depend on the crypto being proprietary.
On scope
Scoped honestly: attribution of a schema-mutation error to a specific field-level producer change — which field, which mutation, which PR. Deeper and forensic within that lane, rather than a thin guess across every incident type.
Architecture patent-pending · crypto is off-the-shelf by design
Incident tools help you fix it.
Déjà helps you prove what happened.
When an auditor or a regulator asks what caused an incident, a ranked guess will not survive the question. A signed, verifiable receipt will. Built for the compliance, audit, and risk buyer — and complementary to the evidence-automation stack you already run.
The guess tells you what might have caused it. The signed receipt tells you what changed, what broke, how it was fixed, who did it — and it will still say the same thing five years from now. Nothing to reconstruct at audit time.
- Deterministic process
- Reproducible result
- Verifiable evidence