One sentence comes up in almost every security review we go through: "We like the product, but our customer data cannot leave our infrastructure." It comes from fintechs running Postgres in a single EU region, from healthtech teams whose contracts restrict third-party copies of patient-adjacent data, and from research groups that already run Kimo air-gapped. Until now, the honest answer was a workaround: an export job, a read replica exposed through an allowlisted IP, or a long procurement detour.
Today we are shipping the real answer. Kimo Bridge is a package you install where your data already lives. It connects to Kimo instead of Kimo connecting to it, and it lets you decide — source by source — whether Kimo should query your data live or keep a synced copy in our cloud.
What is Kimo Bridge?
Kimo Bridge is a lightweight agent (kimo-bridge) that runs on a server, VM or Kubernetes cluster inside your network. It holds the read-only credentials for your databases, opens a single encrypted tunnel outward to Kimo, and executes the queries Kimo sends through that tunnel — after checking that each one is allowed. Think of it as a private API in front of your data that only Kimo can call, and only on your terms.
Scroll sideways to see the full diagram.
The design follows the zero-trust principle that no request should be trusted because of where it comes from on the network; access is granted per request, after authentication and authorization.1Source 1 · NIST, 2020SP 800-207: Zero Trust Architecturecsrc.nist.gov Concretely, the bridge treats Kimo as just another client that has to prove who it is and what it is allowed to do, every time.
Why we built it: copying data is a liability
Most analytics tools are built on the same assumption: first copy everything into the vendor’s warehouse, then analyze it. That works, and for many SaaS sources it is still the right call. But for your production database it creates three problems at once.
- A second copy to protect. Every replica of customer data is one more system to secure, monitor, include in breach scope and delete on request. The GDPR already requires personal data to be "limited to what is necessary" and kept in identifiable form no longer than necessary.2Source 2 · gdpr-info.eu (Regulation (EU) 2016/679), 2016Art. 5 GDPR: Principles relating to processing of personal datagdpr-info.eu
- A network hole. Letting a vendor reach your database usually means opening an inbound port, maintaining an IP allowlist or running a site-to-site VPN. Each of those is a standing path into your most sensitive system.
- Stale answers. A nightly sync means the dashboard your CFO opens at 9 a.m. is already hours old, and nobody can tell which numbers are fresh.
Bridge removes all three for the sources where they matter most: the data stays in your database, the network path is outbound-only, and every answer is computed against live tables.
How does Kimo Bridge work?
- Step 1:
Enroll
You create a bridge in Settings → Kimo Bridge and receive a one-time enrollment token. On first start, the agent uses it to obtain its own client certificate; the token cannot be reused.
- Step 2:
Dial out
The agent opens a TLS 1.3 connection to Kimo on port 443 and keeps it alive. TLS always authenticates the server and can optionally authenticate the client;3Source 3 · IETF / RFC Editor, 2018RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3rfc-editor.org Bridge requires both sides, so Kimo knows it is talking to your agent and your agent knows it is talking to Kimo.
- Step 3:
Compile
When someone opens a dashboard or asks Ask Kimo a question, Kimo resolves it against your semantic layer, compiles SQL for your database dialect and sends a signed query request down the tunnel.
- Step 4:
Check
The bridge verifies the signature, confirms the statement is a single read-only query, checks it against the tables and columns you allow-listed, applies row limits, timeouts and rate limits, and writes an audit entry.
- Step 5:
Push down and stream
The query runs on your database — the pushdown model — and only the result set — usually a small aggregate — streams back to Kimo, where it is rendered and then discarded unless you enabled a result cache.
Because aggregation happens in your database, what crosses the tunnel is usually small: a revenue chart by month is a few dozen rows, not the millions of invoice lines behind it. If you run a read replica, point the bridge at it; standby servers accept read-only queries, which keeps analytics load off your primary.4Source 4 · PostgreSQL DocumentationHot Standbypostgresql.org
Bridge mode or Cloud mode: your call, per source
Not every source has the same constraints. Your Postgres cluster holds customer records; your ad accounts hold campaign spend that Google and Meta already store. So the mode is a property of each source, not of your whole workspace.
| Bridge mode | Cloud mode | |
|---|---|---|
| Where data lives | Only in your database | Synced copy in Kimo’s managed cloud |
| What Kimo stores | Nothing, or a short-lived result cache you can disable | Incremental snapshots, kept for history |
| Freshness | Live at query time | As fresh as the sync schedule |
| Query load | On your database (use a replica) | On Kimo’s engine |
| Best for | Production DBs, regulated or contract-bound data | High-volume history, SaaS APIs, heavy exploration |
Arno, one of our solutions architects, wrote a full decision framework for choosing between them: Cloud, hybrid or bridge. The short version: start with Bridge for anything you would hesitate to email to a vendor, and Cloud for anything you want fast history on.
How do you install it?
There are three ways to run the agent, all built from the same release: a Docker image, a Helm chart for Kubernetes, and a single static binary for Linux hosts. The Docker path takes about five minutes: save the one-time enrollment token to /opt/kimo-bridge/secrets/token, then run:
docker run -d --name kimo-bridge --restart unless-stopped \
-e KIMO_BRIDGE_TOKEN_FILE=/run/secrets/token \
-e KIMO_BRIDGE_CONFIG=/etc/kimo-bridge/kimo-bridge.yaml \
-v /opt/kimo-bridge/kimo-bridge.yaml:/etc/kimo-bridge/kimo-bridge.yaml:ro \
-v /opt/kimo-bridge/secrets:/run/secrets:ro \
-v kimo-bridge-data:/var/lib/kimo-bridge \
ghcr.io/getkimo/bridge:latestSources and policy live in kimo-bridge.yaml on your server. Credentials are read from secret files you control, so they never appear in Kimo’s UI or database:
sources:
- id: prod_pg
type: postgres
dsn_file: /run/secrets/prod_dsn # stays on this host
mode: bridge
cache_ttl: 0s # no result cache on Kimo’s side
policy:
default: deny
tables:
public.accounts: { columns: [id, plan, region, created_at] }
public.invoices: { columns: [id, account_id, amount_cents, paid_at] }
limits: { max_rows: 50000, timeout: 30s, rate: 10/s }
- id: events_ch
type: clickhouse
dsn_file: /run/secrets/events_dsn
mode: cloud # synced through the same tunnelGive the bridge a dedicated read-only database role. On PostgreSQL 14 and later, the predefined pg_read_all_data role grants SELECT on all tables and views without any write privileges,5Source 5 · PostgreSQL DocumentationPredefined Roles (pg_read_all_data)postgresql.org but we recommend granting only the schemas you plan to expose:
CREATE ROLE kimo_bridge LOGIN PASSWORD '<stored on the bridge host>';
GRANT USAGE ON SCHEMA public TO kimo_bridge;
GRANT SELECT ON public.accounts, public.invoices TO kimo_bridge;
ALTER ROLE kimo_bridge SET default_transaction_read_only = on;Step-by-step instructions are in Install Kimo Bridge with Docker and Deploy Kimo Bridge on Kubernetes.
What stops Kimo from reading everything?
This is the question every security team asks first, and it deserves a direct answer: you do. The bridge enforces your policy locally, on your hardware, before any query reaches your database. Even a compromised Kimo account could only request what the bridge allows.
Controls enforced by the bridge, on your side
- Read-only statements only; DDL, DML and multi-statement batches are rejected before execution.
- An explicit allowlist of schemas, tables or models per source.
- Statement timeouts, row limits and per-minute rate limits.
- Signed query requests, verified against a Kimo key pinned at enrollment, with a short expiry.
- A local, hash-chained audit log of every request — allowed or denied — with who triggered it and how many rows returned.
- Instant cut-off:
kimo-bridge pauseor stopping the container closes the tunnel; Revoke in the Bridge console revokes the client certificate and purges Kimo-side caches.
What it means for Marketing, BI and Defense
Bridge works the same way under all three Kimo products, but each team gets something different out of it.
- Business Intelligence: finance teams can build the board deck and investor update straight from the billing tables in production, so the numbers in the deck are the numbers in the database — not last week’s export.
- Marketing: join first-party signup and revenue data from your own database with ad and SEO data synced in Cloud mode, without shipping your user table to a vendor.
- Defense Intelligence: research teams can keep sensitive feeds on their own infrastructure and still use Kimo dashboards and alerting; fully disconnected sites continue to use our on-premise deployment.
Availability and what comes next
Kimo Bridge is available today in public beta for every Kimo workspace. Create your first bridge from the Bridge page in the app, or read the product overview first. During the beta we are focused on three things: more SQL dialects, per-user identity passthrough so your database can apply its own row-level security, and a bridge health panel that shows tunnel latency and query volume over time.
We built Kimo to be the data officer you trust with the hard questions. Trust starts with not taking more than you need. If your data has to stay home, it can now — and Kimo will come to it.
Frequently asked questions
Does Kimo Bridge require opening an inbound port?
No. The agent only makes an outbound TLS connection to Kimo on port 443. Your database and the bridge host accept no inbound traffic from the internet.
Does Kimo store my data in Bridge mode?
No. Results are streamed to Kimo to render the chart or answer and then discarded. You can optionally enable a short-lived result cache per source to speed up repeated views, or set it to zero.
Where are my database credentials kept?
On the bridge host only, in secret files (or environment variables) you control. Kimo never receives them.
Can I use Bridge mode and Cloud mode together?
Yes. The mode is set per source, so one workspace can query production Postgres live through the bridge while syncing ad platforms or a large event store into Kimo’s cloud.
How do I cut off access immediately?
On your side, run kimo-bridge pause or stop the container: the tunnel closes immediately. In Kimo, click Revoke in the Bridge console: the bridge certificate is revoked, the bridge cannot reconnect, and any Kimo-side result caches are purged.
Sources
5 references- SP 800-207: Zero Trust Architecture (opens in a new tab)NIST2020csrc.nist.gov
Zero trust: no implicit trust based on network location; access granted per request.
- Art. 5 GDPR: Principles relating to processing of personal data (opens in a new tab)gdpr-info.eu (Regulation (EU) 2016/679)2016gdpr-info.eu
Data minimisation (Art. 5(1)(c)) and storage limitation (Art. 5(1)(e)).
- RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (opens in a new tab)IETF / RFC Editor2018rfc-editor.org
The server side is always authenticated; client authentication is optional.
- Hot Standby (opens in a new tab)PostgreSQL Documentationpostgresql.org
Standby servers can run read-only queries.
- Predefined Roles (pg_read_all_data) (opens in a new tab)PostgreSQL Documentationpostgresql.org
pg_read_all_data grants SELECT on tables, views and sequences and USAGE on schemas.
External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.
- #Kimo Bridge
- #Security
- #Architecture
Writes about Kimo Bridge, Security, Architecture, CDC.
Kimo people and customers mentioned are illustrative; example charts use simulated data unless a source is cited.




