kimo
Kimo BridgePrivate data access for every Kimo product

Your data stays home.

Install one small package next to your database. It opens an outbound-only, mutually authenticated tunnel to Kimo, so you get live dashboards and Ask Kimo on production data without copying it anywhere, unless you choose to.

  • No inbound ports
  • Mutual TLS 1.3
  • Read-only by design
  • Revoke in seconds
Per source · mix both (hybrid)
Your network
10.20.0.0/16
PostgreSQL 16
finance · read replica
role: read-onlytimeout 30s
kimo-bridge 1.4.2
the package you install
policy: deny-by-defaultpushdown: liveaudit.jsonl
SQLΣ 4 rowsSQLΣ 12 rows
mTLS · TLS 1.3
Outbound 443 only
Kimo Cloud
region: eu
Ask Kimo & dashboards
Result cache
optional · TTL 5 min · or off
0 raw rows stored

Only query results cross the tunnel. Kimo pushes each query down to your database through the bridge and gets aggregates back. Raw tables, credentials and your policy never leave your network.

Install

One command. No firewall tickets.

Run the package on any host that can reach your database. It enrolls with a one-time token, generates its own key, and dials out. Your network team has nothing to open.

  • Container runs read-only, non-root, all capabilities dropped
  • One-time enrollment token, then a short-lived certificate bound to a key that never leaves the host
  • Deny-by-default: nothing is queryable until you allow it
docker run -d --name kimo-bridge \
  --restart unless-stopped --read-only --cap-drop ALL \
  -e KIMO_BRIDGE_TOKEN=<your-enrollment-token> \
  -v kimo-bridge-data:/var/lib/kimo-bridge \
  ghcr.io/getkimo/bridge:1.4.2
Any Linux host with Docker or Podman. 1 vCPU, 1 GB RAM.
How it works

From install to first live chart in about fifteen minutes

Four steps, all on your side of the firewall. Kimo never needs a VPN, a public IP or your database password.

  1. 01

    Create a read-only role

    A dedicated database user with SELECT on the schemas you want to expose and a statement timeout. It is the control that holds even if everything else failed.

    ALTER ROLE kimo_bridge
      SET statement_timeout
      = '30s';
  2. 02

    Install the bridge

    Docker, Helm or a static binary on any host that can reach the database. It enrolls once, then authenticates with its own short-lived certificate.

    enrolled · cert ttl=24h
    tunnel up · region=eu
    tls=1.3 · inbound=none
  3. 03

    Allow what Kimo may see

    List tables and columns in kimo-bridge.yaml, add row filters and a minimum group size. Pick Bridge, Cloud or Hybrid mode per source.

    default: deny
    min_group_size: 5
    mode: bridge
  4. 04

    Query it live

    Dashboards, alerts and Ask Kimo compile to SQL, push down through the tunnel and get aggregates back. Every query lands in the audit log.

    pushdown → finance.mrr
    Σ 4 rows · 0.6 KB
    audit ✓ · 164 ms
Bridge, Cloud or Hybrid

Choose per source. Change it with one line.

There is no single right answer: residency, freshness and speed pull in different directions. Most teams run a mix.

Comparison of Kimo Bridge, Cloud and Hybrid modes
Dimension
Bridge
Live pushdown
Cloud
Synced to Kimo
Hybrid
Rollups synced, detail live
Query latencyYour database’s speed, plus a few ms of tunnel overheadFastest: Kimo’s columnar engine, sub-second on large tablesFast for aggregates; drill-downs at database speed
FreshnessReal time: every uncached query is liveYour sync cadence, from 5 minutes to dailyRollups on sync cadence, details live
What Kimo storesNo raw rows. Optional result cache with a TTL you set, or offAllowed tables, encrypted, in your workspace regionPre-aggregated rollups only
Compliance & residencyData never leaves your network or jurisdictionRegion-pinned (EU or US), covered by our DPARow-level detail stays on your servers
Load on your databaseEvery uncached query; point it at a replicaOne incremental read per syncLight: rollup syncs plus occasional drill-downs
Cost profileNo Kimo storage; compute runs on your sideStorage included per plan, scales with volumeSmall storage footprint
Best forFinance ledgers, product DBs with PII, regulated dataEvents, marketing data, long history, heavy explorationBoard metrics with sensitive underlying detail

Deciding? The Cloud, hybrid or bridge article walks through the trade-offs with real workloads.

Security model

Trust nothing by network position. Check every query.

Controls are layered: the bridge policy, the database role and your database’s own row security. One misconfiguration does not become a breach.

  • egress 443/tcp

    Outbound-only

    The bridge dials out to Kimo on TCP 443 and keeps the connection open. Queries ride back on it. No VPN, no public IP, no inbound firewall rule.

  • mTLS · TLS 1.3

    Mutual TLS

    Both ends present certificates over TLS 1.3. The bridge’s certificate lives 24 hours, renews itself, and is bound to a key generated on your host.

  • read_only = on

    Read-only roles

    The bridge connects as a dedicated read-only database user with a statement timeout, and its SQL parser rejects anything that is not a read.

  • default: deny

    Column allow-lists

    Deny-by-default. Columns missing from kimo-bridge.yaml do not exist as far as Kimo knows. Kimo can ask for less than your policy allows, never more.

  • min_group_size: 5

    Row filters

    Predicates appended to every query on your side, plus a minimum group size that suppresses small aggregates before results leave.

  • audit.jsonl

    Per-query audit

    Who asked, the exact SQL, the decision, rows and bytes returned. Hash-chained on your server and mirrored to Kimo’s activity log.

  • kimo-bridge pause

    Instant revoke

    Revoke in the console or pause on the host. The tunnel drops within seconds, in-flight queries are cancelled, Kimo-side caches are purged.

  • 127.0.0.1:8080

    No inbound ports

    The only listener is a local health and metrics endpoint bound to 127.0.0.1. Nothing to scan, nothing to expose, nothing to pentest from outside.

kimo-bridge.yamlstays on your server
sources:
- id: finance_pg
type: postgres
dsn_file: /run/secrets/finance_dsn
mode: bridge
cache_ttl: 0s
policy:
default: deny
tables:
analytics.invoices:
columns: [account_id, amount_cents,
currency, paid_at]
row_filters:
- "region IN ('EU', 'UK')"
min_group_size: 5
limits: { timeout: 30s, rate: 10/s }
Leaves your network
Allowed query results, health metrics, audit metadata
Never leaves
Raw tables, credentials, private keys, the policy
Read the full security model
Live query trace

Watch one question cross the bridge

Ask Kimo in plain English. The heavy lifting happens next to your data; only the answer travels.

Trace
0 ms
  1. Kimo · semantic layer

    Question compiled to SQL against the governed finance model

  2. Tunnel → bridge fra-prod-01

    Signed request pushed down the open outbound connection

  3. Bridge · local policy

    Tables and columns allowed, EU row filter applied, groups ≥ 5

  4. PostgreSQL read replica

    Executed as kimo_bridge (read-only); 1.2M rows scanned in place

  5. Tunnel → Kimo

    4 aggregate rows returned, 0.6 KB. No raw rows leave

  6. Audit log

    Entry appended and hash-chained on your server, mirrored to Kimo

Ask Kimo

“What was net revenue retention by plan last quarter?”

pushed-down SQLfinance_pg · mode=bridge
SELECT a.plan,
       sum(i.amount_cents) FILTER (WHERE q = 'Q3')
     / sum(i.amount_cents) FILTER (WHERE q = 'Q2') AS nrr
FROM analytics.invoices i
JOIN analytics.accounts a ON a.id = i.account_id
GROUP BY a.plan

Net revenue retention by plan, Q3

Illustrative data
  • Starter96%
  • Growth108%
  • Scale117%
  • Enterprise124%
One bridge, three products

Built for the data you cannot copy

The same package powers every Kimo product. Here is how teams use it.

Business Intelligence

The finance database stays on-prem, in the EU.

Board-pack metrics such as ARR, burn multiple and net revenue retention are computed live against the ledger in your Frankfurt data center. Kimo receives the aggregates for the deck; the invoices never move.

  • Ledger and invoices in Bridge mode, result cache off
  • Board metrics as Hybrid rollups for instant decks
  • Customer names and VAT numbers never allow-listed
Build your board deck on live data
Marketing

Your product database never leaves.

Join signups, activation and paid conversion from your Postgres replica to GA4, ad spend and Search Console, without exporting a single user row. Funnels stay live; personal data stays home.

  • Users, workspaces, plans: live through the bridge
  • Emails, names and IPs: invisible to Kimo by policy
  • Ad and analytics data synced to Kimo Cloud for speed
See the one-dashboard overview
Defense Intelligence

Enclave and air-gapped variant.

In sovereign deployments the Kimo control plane runs inside your enclave and bridges connect to it over the local network: still outbound-only, mutually authenticated and deny-by-default. Updates arrive as signed offline bundles; nothing phones home.

  • ADS-B track archives and receiver telemetry stay in the enclave
  • No external egress at all in air-gapped mode
  • Per-query audit exportable to your SIEM
Explore airspace awareness
FAQ

What platform and security teams ask

Something missing? The security model guide covers each control in depth, or ask us directly.

No. The bridge makes one outbound TLS connection to Kimo’s regional endpoint on TCP 443 and keeps it open. Kimo’s queries travel back over that connection. The only port the bridge listens on is a local health and metrics port you bind to 127.0.0.1.

Keep your data home. Get the answers anyway.

Fifteen minutes from a clean host to your first live chart. Start with one read replica and one table; widen when your security team is happy.