Security

Built around your e-Financials key.

Encryption at rest, signed in memory, scoped per tenant.

Your e-Financials API key is encrypted with AES-256-GCM using a per-tenant data key. The data key is itself encrypted with a master key held in our infrastructure. We decrypt the API key only in memory at the moment of posting — never log it, never echo it.

You can revoke the key from e-Financials anytime; Kirje stops posting immediately.

Data: Neon Postgres (eu-central-1) and S3 (eu-central-1). AI calls route through OpenRouter to EU-resident models when available.

Report vulnerabilities to security@kirje.ee. Full technical detail is in the privacy policy.

Security · Kirje