Apache Ranger
Data Governance Plane · Access Policy Enforcement
Framework for centrally managing fine-grained access policies across Hadoop and related data services.
- Open source
Data Governance Plane · Access Policy Enforcement
Data security and access governance with policy-based access control for cloud data platforms.
Immuta describes itself as the authorisation layer for data access: one policy engine governing requests from people and AI agents across warehouses, lakehouses, databases, storage and APIs.
Policies are written once and compiled into real controls inside your data infrastructure, resolving to allow, mask, filter, deny or escalate.
Authoring is deliberately accessible. A natural-language editor lets non-technical users write the full range of policies without code, from guardrails down to fine-grained column and row rules.
Its architectural signature is policy push rather than proxy. Immuta's own documentation is explicit that nothing sits in the connection path, so queries do not travel through it.
How enforcement actually happens varies by platform, and that detail matters more than the marketing. Snowflake and Databricks Unity Catalog get native primitives, Redshift, Synapse and BigQuery get generated views, and Databricks Spark and Starburst get an in-engine plugin.
Object storage is different again, using AWS S3 Access Grants to vend temporary credentials, and supports subscription policies only, with no data policies at all.
Purpose-based access control is a genuine differentiator: work runs under a project's declared purpose, so Immuta records not just whether data was used but why.
Check the support matrix before assuming parity, because it is uneven. Format-preserving masking and randomised response are Snowflake-only, and the view-based integrations are read-only.
Coverage is narrower than its rivals: eight integrations, and query audit exists on only four of them, which is a fair trade for depth but should be checked against your estate.
The current direction is agentic access, now generally available, treating agents as identities scoped to the sponsoring human's rights and granting data only for as long as a question takes to answer.
The same headings are used for every access policy enforcement entry, so two tools can be read side by side.
Price on requestQuote only; nothing published
Entirely quote-only. Immuta publishes no pricing at all: its pricing page does not exist, and there is no list price, currency, tier name or unit of metering anywhere, whether per user, per table or per terabyte. The only published route is a demo request, though it does offer a return-on-investment calculator that publishes no rates. No free tier or trial is currently offered; a trial existed in much older documentation but nothing current publishes one or its length.
Immuta was founded in 2015 by Matthew Carroll, its chief executive, and Steve Touw, and is based in Boston with offices in Maryland, Ohio, London and Sydney. It is private and venture-backed, raising $267m by its $100m Series E in June 2022 led by NightDragon, with earlier rounds led by Intel Capital and DFJ Growth, followed by undisclosed strategic investments from ServiceNow and Databricks Ventures in 2023. It publishes no customer or employee count, naming JPMorgan Chase, General Motors, Roche, NVIDIA and several US federal agencies instead. It remains independent, having neither acquired nor been acquired.
Founded 2015 · Boston, Massachusetts · immuta.com
Data Governance Plane · Access Policy Enforcement
Framework for centrally managing fine-grained access policies across Hadoop and related data services.
Data Governance Plane · Access Policy Enforcement
Data access governance built on Apache Ranger, for cloud and hybrid data platforms. Rebranded to Trust3 AI in March 2026 under the same company; product documentation still carries the Privacera name.
Drafted with AI assistance and checked against the vendor’s own documentation.