kimo

Introducing Kimo Bridge: your data stays home

Kimo Bridge is a small package you install on your own server, next to your database. It opens an outbound-only, mutually authenticated tunnel to Kimo, so you can ask questions of live production data without copying it into our cloud — and when you do want speed or history, you can switch any source to Cloud mode with one line of config.

Théo Marchand
Co-founder & CTO7 min read5 sources

One sentence comes up in almost every security review we go through: "We like the product, but our customer data cannot leave our infrastructure." It comes from fintechs running Postgres in a single EU region, from healthtech teams whose contracts restrict third-party copies of patient-adjacent data, and from research groups that already run Kimo air-gapped. Until now, the honest answer was a workaround: an export job, a read replica exposed through an allowlisted IP, or a long procurement detour.

Today we are shipping the real answer. Kimo Bridge is a package you install where your data already lives. It connects to Kimo instead of Kimo connecting to it, and it lets you decide — source by source — whether Kimo should query your data live or keep a synced copy in our cloud.

What is Kimo Bridge?

Kimo Bridge is a lightweight agent (kimo-bridge) that runs on a server, VM or Kubernetes cluster inside your network. It holds the read-only credentials for your databases, opens a single encrypted tunnel outward to Kimo, and executes the queries Kimo sends through that tunnel — after checking that each one is allowed. Think of it as a private API in front of your data that only Kimo can call, and only on your terms.

Kimo Bridge architectureThe bridge sits beside your database and dials out to Kimo over one mutually authenticated TLS connection. Nothing in your network accepts inbound traffic.YOUR NETWORK · VPC / ON-PREMKIMO CLOUDPostgreSQLPostgreSQLapp databaseClickHouseClickHouseproduct eventsInternal APIREST · read-onlykimo-bridgeagent · v1read-only credsnever leave hereFirewallno inbound ports openedoutbound TLS · mTLSBridge gatewayauthz · rate limitsAudit logevery query recordedSemantic layermodels · measuresDashboardslive tilesAsk Kimoaudited answersRevoke instantly: stop the agentNothing stored by defaultqueryresults
Figure.The bridge sits beside your database and dials out to Kimo over one mutually authenticated TLS connection. Nothing in your network accepts inbound traffic.

Scroll sideways to see the full diagram.

The design follows the zero-trust principle that no request should be trusted because of where it comes from on the network; access is granted per request, after authentication and authorization.1 Concretely, the bridge treats Kimo as just another client that has to prove who it is and what it is allowed to do, every time.

Why we built it: copying data is a liability

Most analytics tools are built on the same assumption: first copy everything into the vendor’s warehouse, then analyze it. That works, and for many SaaS sources it is still the right call. But for your production database it creates three problems at once.

  • A second copy to protect. Every replica of customer data is one more system to secure, monitor, include in breach scope and delete on request. The GDPR already requires personal data to be "limited to what is necessary" and kept in identifiable form no longer than necessary.2
  • A network hole. Letting a vendor reach your database usually means opening an inbound port, maintaining an IP allowlist or running a site-to-site VPN. Each of those is a standing path into your most sensitive system.
  • Stale answers. A nightly sync means the dashboard your CFO opens at 9 a.m. is already hours old, and nobody can tell which numbers are fresh.

Bridge removes all three for the sources where they matter most: the data stays in your database, the network path is outbound-only, and every answer is computed against live tables.

How does Kimo Bridge work?

  1. Step 1:

    Enroll

    You create a bridge in Settings → Kimo Bridge and receive a one-time enrollment token. On first start, the agent uses it to obtain its own client certificate; the token cannot be reused.

  2. Step 2:

    Dial out

    The agent opens a TLS 1.3 connection to Kimo on port 443 and keeps it alive. TLS always authenticates the server and can optionally authenticate the client;3 Bridge requires both sides, so Kimo knows it is talking to your agent and your agent knows it is talking to Kimo.

  3. Step 3:

    Compile

    When someone opens a dashboard or asks Ask Kimo a question, Kimo resolves it against your semantic layer, compiles SQL for your database dialect and sends a signed query request down the tunnel.

  4. Step 4:

    Check

    The bridge verifies the signature, confirms the statement is a single read-only query, checks it against the tables and columns you allow-listed, applies row limits, timeouts and rate limits, and writes an audit entry.

  5. Step 5:

    Push down and stream

    The query runs on your database — the pushdown model — and only the result set — usually a small aggregate — streams back to Kimo, where it is rendered and then discarded unless you enabled a result cache.

Because aggregation happens in your database, what crosses the tunnel is usually small: a revenue chart by month is a few dozen rows, not the millions of invoice lines behind it. If you run a read replica, point the bridge at it; standby servers accept read-only queries, which keeps analytics load off your primary.4

Bridge mode or Cloud mode: your call, per source

Not every source has the same constraints. Your Postgres cluster holds customer records; your ad accounts hold campaign spend that Google and Meta already store. So the mode is a property of each source, not of your whole workspace.

Bridge modeCloud mode
Where data livesOnly in your databaseSynced copy in Kimo’s managed cloud
What Kimo storesNothing, or a short-lived result cache you can disableIncremental snapshots, kept for history
FreshnessLive at query timeAs fresh as the sync schedule
Query loadOn your database (use a replica)On Kimo’s engine
Best forProduction DBs, regulated or contract-bound dataHigh-volume history, SaaS APIs, heavy exploration
You can mix both in one workspace. We call that hybrid.

Arno, one of our solutions architects, wrote a full decision framework for choosing between them: Cloud, hybrid or bridge. The short version: start with Bridge for anything you would hesitate to email to a vendor, and Cloud for anything you want fast history on.

How do you install it?

There are three ways to run the agent, all built from the same release: a Docker image, a Helm chart for Kubernetes, and a single static binary for Linux hosts. The Docker path takes about five minutes: save the one-time enrollment token to /opt/kimo-bridge/secrets/token, then run:

Run Kimo Bridge with Docker
bash
docker run -d --name kimo-bridge --restart unless-stopped \
  -e KIMO_BRIDGE_TOKEN_FILE=/run/secrets/token \
  -e KIMO_BRIDGE_CONFIG=/etc/kimo-bridge/kimo-bridge.yaml \
  -v /opt/kimo-bridge/kimo-bridge.yaml:/etc/kimo-bridge/kimo-bridge.yaml:ro \
  -v /opt/kimo-bridge/secrets:/run/secrets:ro \
  -v kimo-bridge-data:/var/lib/kimo-bridge \
  ghcr.io/getkimo/bridge:latest

Sources and policy live in kimo-bridge.yaml on your server. Credentials are read from secret files you control, so they never appear in Kimo’s UI or database:

/opt/kimo-bridge/kimo-bridge.yaml
yaml
sources:
  - id: prod_pg
    type: postgres
    dsn_file: /run/secrets/prod_dsn   # stays on this host
    mode: bridge
    cache_ttl: 0s                     # no result cache on Kimo’s side
    policy:
      default: deny
      tables:
        public.accounts: { columns: [id, plan, region, created_at] }
        public.invoices: { columns: [id, account_id, amount_cents, paid_at] }
      limits: { max_rows: 50000, timeout: 30s, rate: 10/s }
  - id: events_ch
    type: clickhouse
    dsn_file: /run/secrets/events_dsn
    mode: cloud                       # synced through the same tunnel

Give the bridge a dedicated read-only database role. On PostgreSQL 14 and later, the predefined pg_read_all_data role grants SELECT on all tables and views without any write privileges,5 but we recommend granting only the schemas you plan to expose:

A narrow read-only role for the bridge
sql
CREATE ROLE kimo_bridge LOGIN PASSWORD '<stored on the bridge host>';
GRANT USAGE ON SCHEMA public TO kimo_bridge;
GRANT SELECT ON public.accounts, public.invoices TO kimo_bridge;
ALTER ROLE kimo_bridge SET default_transaction_read_only = on;

Step-by-step instructions are in Install Kimo Bridge with Docker and Deploy Kimo Bridge on Kubernetes.

What stops Kimo from reading everything?

This is the question every security team asks first, and it deserves a direct answer: you do. The bridge enforces your policy locally, on your hardware, before any query reaches your database. Even a compromised Kimo account could only request what the bridge allows.

Controls enforced by the bridge, on your side

  • Read-only statements only; DDL, DML and multi-statement batches are rejected before execution.
  • An explicit allowlist of schemas, tables or models per source.
  • Statement timeouts, row limits and per-minute rate limits.
  • Signed query requests, verified against a Kimo key pinned at enrollment, with a short expiry.
  • A local, hash-chained audit log of every request — allowed or denied — with who triggered it and how many rows returned.
  • Instant cut-off: kimo-bridge pause or stopping the container closes the tunnel; Revoke in the Bridge console revokes the client certificate and purges Kimo-side caches.

What it means for Marketing, BI and Defense

Bridge works the same way under all three Kimo products, but each team gets something different out of it.

  • Business Intelligence: finance teams can build the board deck and investor update straight from the billing tables in production, so the numbers in the deck are the numbers in the database — not last week’s export.
  • Marketing: join first-party signup and revenue data from your own database with ad and SEO data synced in Cloud mode, without shipping your user table to a vendor.
  • Defense Intelligence: research teams can keep sensitive feeds on their own infrastructure and still use Kimo dashboards and alerting; fully disconnected sites continue to use our on-premise deployment.
Databases you can reach through Kimo Bridge at launch.

Availability and what comes next

Kimo Bridge is available today in public beta for every Kimo workspace. Create your first bridge from the Bridge page in the app, or read the product overview first. During the beta we are focused on three things: more SQL dialects, per-user identity passthrough so your database can apply its own row-level security, and a bridge health panel that shows tunnel latency and query volume over time.

We built Kimo to be the data officer you trust with the hard questions. Trust starts with not taking more than you need. If your data has to stay home, it can now — and Kimo will come to it.

Frequently asked questions

Does Kimo Bridge require opening an inbound port?

No. The agent only makes an outbound TLS connection to Kimo on port 443. Your database and the bridge host accept no inbound traffic from the internet.

Does Kimo store my data in Bridge mode?

No. Results are streamed to Kimo to render the chart or answer and then discarded. You can optionally enable a short-lived result cache per source to speed up repeated views, or set it to zero.

Where are my database credentials kept?

On the bridge host only, in secret files (or environment variables) you control. Kimo never receives them.

Can I use Bridge mode and Cloud mode together?

Yes. The mode is set per source, so one workspace can query production Postgres live through the bridge while syncing ad platforms or a large event store into Kimo’s cloud.

How do I cut off access immediately?

On your side, run kimo-bridge pause or stop the container: the tunnel closes immediately. In Kimo, click Revoke in the Bridge console: the bridge certificate is revoked, the bridge cannot reconnect, and any Kimo-side result caches are purged.

Sources

5 references
  1. SP 800-207: Zero Trust Architecture (opens in a new tab)
    NIST2020csrc.nist.gov

    Zero trust: no implicit trust based on network location; access granted per request.

  2. Art. 5 GDPR: Principles relating to processing of personal data (opens in a new tab)
    gdpr-info.eu (Regulation (EU) 2016/679)2016gdpr-info.eu

    Data minimisation (Art. 5(1)(c)) and storage limitation (Art. 5(1)(e)).

  3. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (opens in a new tab)
    IETF / RFC Editor2018rfc-editor.org

    The server side is always authenticated; client authentication is optional.

  4. Hot Standby (opens in a new tab)
    PostgreSQL Documentationpostgresql.org

    Standby servers can run read-only queries.

  5. Predefined Roles (pg_read_all_data) (opens in a new tab)
    PostgreSQL Documentationpostgresql.org

    pg_read_all_data grants SELECT on tables, views and sequences and USAGE on schemas.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

  • #Kimo Bridge
  • #Security
  • #Architecture
Found this useful? Pass it on.
Written by
Théo Marchand
Co-founder & CTO at Kimo · 2 articles

Writes about Kimo Bridge, Security, Architecture, CDC.

Kimo people and customers mentioned are illustrative; example charts use simulated data unless a source is cited.

Put it to work

Go deeper

Whitepaper

Your Data, Your Rules

The hybrid analytics architecture behind Kimo Bridge: live query pushdown, optional cloud sync, and zero-trust by default.

22 pages
Live demo

Set up Kimo Bridge

Install the bridge, pick Bridge or Cloud mode per source, watch the audit log.

Simulated data · no sign-up

All resources
GuideBeginner
All

Install Kimo Bridge with Docker

Run the bridge next to your database in minutes: outbound-only, read-only, revocable.

Arno Visser
10 min read
GuideIntermediate
All

The Kimo Bridge security model

What leaves your network, what never does, and how every query is authorized and audited.

Rhea Patel
10 min read

Your data officer is ready.

Connect a source — or install Kimo Bridge and keep data on your servers — then ask a question and get an answer you can audit.