Security
Built around your e-Financials key.
Encryption at rest, signed in memory, scoped per tenant.
Your e-Financials API key is encrypted with AES-256-GCM using a per-tenant data key. The data key is itself encrypted with a master key held in our infrastructure. We decrypt the API key only in memory at the moment of posting — never log it, never echo it.
You can revoke the key from e-Financials anytime; Kirje stops posting immediately.
Data: Neon Postgres (eu-central-1) and S3 (eu-central-1). AI calls route through OpenRouter to EU-resident models when available.
Report vulnerabilities to security@kirje.ee. Full technical detail is in the privacy policy.