kimo
Docs

Bridge security

The Kimo Bridge security controls in one page: outbound-only tunnel, mutual TLS, read-only roles, allow-lists, row filters, audit and revocation.

Updated Oct 9, 20265 min readEdit on GitHub

Kimo Bridge is built so that raw data, database credentials and your policy never leave your network; only results your policy allows do. This page summarizes each control. The security model guide explains the reasoning, the threat model and how to review it, and the trust center covers Kimo as a whole.

What leaves your network

Leaves (to Kimo)Never leaves
Results of allowed queries, usually aggregatesRaw tables
Health and performance metricsDatabase credentials and DSNs
Audit metadata (who, what, when, decision)The bridge private key
In cloud mode only: allowed tables, incrementallyThe policy file

Controls

  • Outbound-only. One connection from the bridge to Kimo on TCP 443. No inbound rule, public IP or VPN. The only listener is 127.0.0.1:8080 for health and metrics.
  • Mutual TLS 1.3. Both sides present certificates. The bridge certificate is valid for 24 hours, renews automatically and is bound to a key generated on your host. Kimo’s endpoint is verified against a CA bundle pinned in the image.
  • Signed requests. Each query carries its own signature and workspace context, so being on the tunnel is not enough to run anything.
  • Read-only execution. The SQL parser rejects anything that is not a read, and the database role you create is read-only with a statement timeout.
  • Allow-lists. Deny-by-default tables and columns. Kimo can ask for less than the policy allows, never more, and cannot change the policy remotely.
  • Row filters and group sizes. Predicates appended on your side; small aggregates suppressed before results leave.
  • Per-query audit. Hash-chained JSON lines on your server, mirrored to Activity. Export them to your SIEM.
  • Revocation. kimo-bridge pause on the host is immediate. Revoking in the console revokes the certificate, drops the tunnel within seconds and purges Kimo-side caches.

Review checklist

  1. 1The bridge role is a dedicated, read-only user that does not own the tables and cannot bypass row-level security.
  2. 2The DSN points at a read replica, not the primary.
  3. 3kimo-bridge.yaml lists only the tables and columns your dashboards need; sensitive columns are absent.
  4. 4Sources holding personal data use bridge mode with a short or zero cache_ttl.
  5. 5The audit log is shipped to your SIEM and retained per your policy.
  6. 6Someone on your team has rehearsed revocation from the console and from the host.

Need documents for a vendor review? Request them from the trust center or contact us.