Softwr

Databases · head to head

Convex vs Immuta

Convex logo

Convex

Databases

Reactive backend combining a document database, TypeScript server functions and live queries, source-available under the Functional Source Licence.

From
Free
Rated
-
Immuta logo

Immuta

Databases

Attribute-based access control and masking applied inside Snowflake, Databricks and BigQuery

From
On request
Rated
-

The short version

  • Only Convex has a free tier, so it costs nothing to try first.
  • Each has a real cost: Convex the Functional Source Licence is not an OSI open source licence: competing use is prohibited until each release reaches its second anniversary and converts to Apache 2.0, so you may self-host but you may not build a service on it.; Immuta contracts commonly start around one hundred to two hundred thousand US dollars a year for mid-market deployments and exceed five hundred thousand at enterprise scale, which excludes most data teams without a regulatory mandate.
  • They diverge on capability: Convex covers Reactive queries, Immuta covers Attribute-based policy.
  • Prices and features above were last checked on 31 August 2026.

Where they differ

Only the attributes on which Convex and Immuta actually diverge.

Attributes where Convex and Immuta differ
AttributeConvexImmuta
Starting priceFreeOn request
Pricing modelsubscriptionquote
Free tierYesNo
PlatformsWebWeb, API, Cloud

Identical on both: user rating (Not yet rated), category (Databases).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Convex

  • Reactive queries
  • TypeScript server functions
  • ACID transactions
  • Document database
  • Scheduling and workflows
  • File storage
  • Text and vector search
  • End-to-end types

Only in Immuta

  • Attribute-based policy
  • Native enforcement
  • Dynamic masking
  • Row-level filtering
  • Purpose-based access
  • Sensitive data tagging
  • Audit logging
  • Multi-platform

What people use each for

The jobs each tool is most often brought in to do.

Convex

  • Collaborative applications where several users see the same data and every client must reflect a change immediatelynot Immuta
  • Agent backends that need durable state, scheduled work and transactional writes without assembling a queue, a database and a cachenot Immuta
  • Small product teams who need a complete backend, including auth integration, file storage and subscriptions, without hiring infrastructure engineersnot Immuta
  • Prototypes that must become production without a rewrite of the data layer, where end-to-end TypeScript types remove a class of integration bugsnot Immuta

Immuta

  • A bank whose Snowflake estate has grown to tens of thousands of roles that no one can review before an auditnot Convex
  • A healthcare analytics team that must let researchers query patient data with identifiers masked unless a specific purpose is recordednot Convex
  • A multinational applying different residency and access rules per jurisdiction to the same tables without duplicating datasetsnot Convex
  • An organisation running both Snowflake and Databricks that wants one policy set rather than two divergent implementationsnot Convex

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Convex

  • The Functional Source Licence is not an OSI open source licence: competing use is prohibited until each release reaches its second anniversary and converts to Apache 2.0, so you may self-host but you may not build a service on it.
  • Transactions are bounded at one second of user code, 16 MiB read and written, 32,000 documents scanned and 16,000 written, so every backfill, migration or bulk import has to be chunked into scheduled batches rather than written as a single operation.
  • There is no SQL and no query planner; you declare up to 32 indexes per table and traverse them, and joins are loops in TypeScript, so an unanticipated access pattern requires a schema and index change rather than a new query.
  • It is not an analytical database, so reporting means streaming data out to a warehouse and BI tools cannot be pointed at Convex directly, which adds a pipeline the architecture diagram did not originally include.
  • The application is written against Convex's function and client APIs rather than a standard protocol, so leaving means rewriting the data access layer and replacing the reactivity model, not repointing a connection string.

Immuta

  • Contracts commonly start around one hundred to two hundred thousand US dollars a year for mid-market deployments and exceed five hundred thousand at enterprise scale, which excludes most data teams without a regulatory mandate.
  • Policy is only as good as the data classification underneath it, so an organisation with poorly tagged columns will spend months on classification before Immuta enforces anything useful.
  • Native enforcement means capability varies by platform, and a feature available on Snowflake may be absent or behave differently on BigQuery, which undermines the promise of one policy set everywhere.
  • Adding an access governance layer creates a new dependency in the path to data: a misconfigured policy silently returns fewer rows rather than erroring, and analysts can act on incomplete results without noticing.
  • It governs cloud data platforms, so personal data in operational databases, files and SaaS applications sits outside its scope and needs separate controls, meaning Immuta is rarely the whole answer.

Pricing, plan by plan

Convex

Free
  • Free & StarterFree
    • Supports 1-6 developers
    • Reactive database
    • File storage
  • Professional$25/month per developer
    • Supports up to 20 developers
    • All Starter features
    • Log streaming
  • Business & Enterprise$2500/month minimum
    • Supports 50+ developers
    • SAML/SSO
    • Service SLAs

Immuta

On request
  • Immuta Platform$undefined/year
    • Attribute-based policy authoring
    • Native enforcement in supported data platforms
    • Dynamic masking and row-level security

Which should you pick?

Choose Convex if

  • You need reactive queries.
  • You want to start without paying.
  • You also want typescript server functions.

Choose Immuta if

  • You need attribute-based policy.
  • You work on Web, API, Cloud.
  • You also want native enforcement.

Questions people ask

Is Convex or Immuta better?
Neither clearly leads. Convex starts at Free and Immuta at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Convex or Immuta?
Convex has a free tier; the other does not. Paid plans start at Free for Convex and On request for Immuta.
Does Convex or Immuta run on more platforms?
Convex runs on Web. Immuta runs on Web, API, Cloud.
Can I use Convex for free?
Yes. Convex has a free tier, so you can try it without paying. Immuta starts at On request.
What is Convex best used for?
Convex is most often used for collaborative applications where several users see the same data and every client must reflect a change immediately, agent backends that need durable state, scheduled work and transactional writes without assembling a queue, a database and a cache, small product teams who need a complete backend, including auth integration, file storage and subscriptions, without hiring infrastructure engineers, prototypes that must become production without a rewrite of the data layer, where end-to-end typescript types remove a class of integration bugs. Of those, collaborative applications where several users see the same data and every client must reflect a change immediately and agent backends that need durable state, scheduled work and transactional writes without assembling a queue, a database and a cache are not what Immuta is typically brought in for.
What can Convex do that Immuta cannot?
Convex covers Reactive queries, TypeScript server functions, ACID transactions, Document database. Immuta covers Attribute-based policy, Native enforcement, Dynamic masking, Row-level filtering.

Answered from the vendors’ own pages

Convex: Is Convex open source?

It is source-available under FSL-1.1-Apache-2.0. You may read, modify and self-host it, but competing use is prohibited until each release converts to Apache 2.0 on its second anniversary.

Immuta: Does Immuta sit in the query path?

No. It compiles policies into the data platform's own native controls, so queries run at normal speed through your existing tools.

Convex: Can I self-host it?

Yes. The backend, dashboard and CLI can run on your own infrastructure, with most of the features of the cloud product. Self-hosted instances include a telemetry beacon that can be disabled.

Immuta: What does it cost?

Not published. Market data suggests roughly 100,000 to 200,000 US dollars a year for mid-market deployments and considerably more at enterprise scale.

Convex: Does it support SQL?

No. Data is accessed through a TypeScript query builder over declared indexes. Relationships are traversed in code, which is explicit and type-safe but means no ad hoc querying.

Immuta: Is Immuta still independent?

Yes. It remains independently owned, unlike several competitors in data access governance that have been acquired.

Convex: What happens if a mutation exceeds the limits?

It fails rather than running longer, so bulk work must be split into batches and scheduled. The limits are per transaction: one second of user code, 16 MiB read and written, 32,000 documents scanned and 16,000 written.

Immuta: Does it work across more than one warehouse?

Yes, one policy set can target Snowflake, Databricks, BigQuery and Starburst, though enforcement capability varies by platform.

Convex: How does reactivity actually work?

Queries are deterministic functions and Convex records the data each one read. When a mutation changes that data, affected queries are re-run and subscribed clients receive the new result, so cache invalidation is handled by the platform.

Share

Related pages

Other head to heads