Bridge security
The Kimo Bridge security controls in one page: outbound-only tunnel, mutual TLS, read-only roles, allow-lists, row filters, audit and revocation.
Updated Oct 9, 20265 min readEdit on GitHub
Kimo Bridge is built so that raw data, database credentials and your policy never leave your network; only results your policy allows do. This page summarizes each control. The security model guide explains the reasoning, the threat model and how to review it, and the trust center covers Kimo as a whole.
What leaves your network
| Leaves (to Kimo) | Never leaves |
|---|---|
| Results of allowed queries, usually aggregates | Raw tables |
| Health and performance metrics | Database credentials and DSNs |
| Audit metadata (who, what, when, decision) | The bridge private key |
In cloud mode only: allowed tables, incrementally | The policy file |
Controls
- Outbound-only. One connection from the bridge to Kimo on TCP 443. No inbound rule, public IP or VPN. The only listener is
127.0.0.1:8080for health and metrics. - Mutual TLS 1.3. Both sides present certificates. The bridge certificate is valid for 24 hours, renews automatically and is bound to a key generated on your host. Kimo’s endpoint is verified against a CA bundle pinned in the image.
- Signed requests. Each query carries its own signature and workspace context, so being on the tunnel is not enough to run anything.
- Read-only execution. The SQL parser rejects anything that is not a read, and the database role you create is read-only with a statement timeout.
- Allow-lists. Deny-by-default tables and columns. Kimo can ask for less than the policy allows, never more, and cannot change the policy remotely.
- Row filters and group sizes. Predicates appended on your side; small aggregates suppressed before results leave.
- Per-query audit. Hash-chained JSON lines on your server, mirrored to Activity. Export them to your SIEM.
- Revocation.
kimo-bridge pauseon the host is immediate. Revoking in the console revokes the certificate, drops the tunnel within seconds and purges Kimo-side caches.
Review checklist
- 1The bridge role is a dedicated, read-only user that does not own the tables and cannot bypass row-level security.
- 2The DSN points at a read replica, not the primary.
- 3
kimo-bridge.yamllists only the tables and columns your dashboards need; sensitive columns are absent. - 4Sources holding personal data use
bridgemode with a short or zerocache_ttl. - 5The audit log is shipped to your SIEM and retained per your policy.
- 6Someone on your team has rehearsed revocation from the console and from the host.
Need documents for a vendor review? Request them from the trust center or contact us.
