Data Governance Plane · Access Policy Enforcement

Immuta

Data security and access governance with policy-based access control for cloud data platforms.

Overview

Immuta describes itself as the authorisation layer for data access: one policy engine governing requests from people and AI agents across warehouses, lakehouses, databases, storage and APIs.

Policies are written once and compiled into real controls inside your data infrastructure, resolving to allow, mask, filter, deny or escalate.

Authoring is deliberately accessible. A natural-language editor lets non-technical users write the full range of policies without code, from guardrails down to fine-grained column and row rules.

Its architectural signature is policy push rather than proxy. Immuta's own documentation is explicit that nothing sits in the connection path, so queries do not travel through it.

How enforcement actually happens varies by platform, and that detail matters more than the marketing. Snowflake and Databricks Unity Catalog get native primitives, Redshift, Synapse and BigQuery get generated views, and Databricks Spark and Starburst get an in-engine plugin.

Object storage is different again, using AWS S3 Access Grants to vend temporary credentials, and supports subscription policies only, with no data policies at all.

Purpose-based access control is a genuine differentiator: work runs under a project's declared purpose, so Immuta records not just whether data was used but why.

Check the support matrix before assuming parity, because it is uneven. Format-preserving masking and randomised response are Snowflake-only, and the view-based integrations are read-only.

Coverage is narrower than its rivals: eight integrations, and query audit exists on only four of them, which is a fair trade for depth but should be checked against your estate.

The current direction is agentic access, now generally available, treating agents as identities scoped to the sponsoring human's rights and granting data only for as long as a question takes to answer.

Key features and capabilities

The same headings are used for every access policy enforcement entry, so two tools can be read side by side.

How policies are written
  • A natural-language policy editor covering guardrails, subscription policies and fine-grained data policies
  • Attribute-based access control at the core, with user attributes synchronised from your identity provider
  • Global policies written against tags apply automatically to every matching source, including newly discovered tables
  • Three tiers, guardrails setting non-negotiable limits, subscription policies gating requests, data policies governing visibility
  • Purpose-based access control ties use to a declared project purpose, recording why data was accessed
How policies are enforced
  • Policy push rather than proxy; nothing sits in the connection path
  • Snowflake and Databricks Unity Catalog use native row access and column masking policies
  • Redshift, Synapse and BigQuery use generated views, and those integrations are read-only
  • Databricks Spark and Starburst use an in-engine plugin that rewrites the query plan
  • Amazon S3 uses AWS Access Grants to vend temporary credentials, with subscription policies only
Masking and de-identification
  • Hashing, rounding, custom functions and row filtering are available across all policy-capable platforms
  • Format-preserving masking and randomised response are Snowflake-only
  • Reversible masking works on Redshift, Databricks Spark, Snowflake and Starburst, but not Synapse or BigQuery
  • BigQuery supports the fewest policy types, and Synapse cannot do reversible or format-preserving masking
  • Named k-anonymisation and differential privacy policies do not appear in the current support matrix
Classification and discovery
  • Identification automates tagging using regex, dictionary and column-name identifiers
  • Regex and dictionary identifiers work on only four of the eight integrations
  • Schema monitoring detects new tables and columns and applies existing policies automatically
  • Tags can be consumed from Alation, Atlan, Collibra, Microsoft Purview or a custom catalogue, polled daily
  • Native tag ingestion from the platform itself works on Snowflake and Unity Catalog only
Platform coverage
  • Eight integrations, the narrowest here, covering the major warehouses plus Databricks, Starburst and S3
  • Snowflake, Databricks Unity Catalog, Databricks Spark, Starburst, Redshift, Synapse, BigQuery and S3
  • Databricks Spark is positioned for data still in the Hive metastore, with Unity Catalog the forward path
  • No coverage of transactional databases or SaaS applications is published
Audit and monitoring
  • A universal audit model feeding dashboards, covering access and detecting behavioural anomalies
  • Query audit is available on only four of eight integrations, and not on Redshift, S3, Synapse or BigQuery
  • Audit fidelity varies; Spark does not record columns or rows returned, and Starburst records no unauthorised access
  • Governance reports are built in natural language and pivot by user, project, purpose or policy
  • Self-managed audit retention defaults to seven days and must be raised deliberately
Where it runs and what it costs
  • Software as a service is the recommendation, receiving features first with zero-downtime updates
  • Self-managed on Kubernetes through a Helm chart, for on-premises or private cloud
  • Twelve published regions across Asia Pacific, Europe and North America, with egress addresses for allow-listing
  • No unit of pricing is published

Pricing

Price on requestQuote only; nothing published

Entirely quote-only. Immuta publishes no pricing at all: its pricing page does not exist, and there is no list price, currency, tier name or unit of metering anywhere, whether per user, per table or per terabyte. The only published route is a demo request, though it does offer a return-on-investment calculator that publishes no rates. No free tier or trial is currently offered; a trial existed in much older documentation but nothing current publishes one or its length.

Vendor pricing page →

Demos and videos

About Immuta

Immuta was founded in 2015 by Matthew Carroll, its chief executive, and Steve Touw, and is based in Boston with offices in Maryland, Ohio, London and Sydney. It is private and venture-backed, raising $267m by its $100m Series E in June 2022 led by NightDragon, with earlier rounds led by Intel Capital and DFJ Growth, followed by undisclosed strategic investments from ServiceNow and Databricks Ventures in 2023. It publishes no customer or employee count, naming JPMorgan Chase, General Motors, Roche, NVIDIA and several US federal agencies instead. It remains independent, having neither acquired nor been acquired.

Founded 2015 · Boston, Massachusetts · immuta.com

Other access policy enforcement tools

Apache Ranger

Data Governance Plane · Access Policy Enforcement

Framework for centrally managing fine-grained access policies across Hadoop and related data services.

  • Open source

Privacera (Trust3 AI)

Data Governance Plane · Access Policy Enforcement

Data access governance built on Apache Ranger, for cloud and hybrid data platforms. Rebranded to Trust3 AI in March 2026 under the same company; product documentation still carries the Privacera name.

  • Commercial

Drafted with AI assistance and checked against the vendor’s own documentation.