Softwr

Databases · head to head

Apache Doris vs Immuta

Apache Doris logo

Apache Doris

Databases

MPP analytical database with a MySQL wire protocol and sub-second aggregation on wide tables

From
Free
Rated
-
Immuta logo

Immuta

Databases

Attribute-based access control and masking applied inside Snowflake, Databricks and BigQuery

From
On request
Rated
-

The short version

  • Only Apache Doris has a free tier, so it costs nothing to try first.
  • Each has a real cost: Apache Doris two competing commercial vendors, VeloDB and SelectDB, were founded by overlapping core contributors, which makes the long-term governance and roadmap of the project harder to predict than a single-sponsor project.; Immuta contracts commonly start around one hundred to two hundred thousand US dollars a year for mid-market deployments and exceed five hundred thousand at enterprise scale, which excludes most data teams without a regulatory mandate.
  • They diverge on capability: Apache Doris covers MySQL wire protocol, Immuta covers Attribute-based policy.
  • Prices and features above were last checked on 31 August 2026.

Where they differ

Only the attributes on which Apache Doris and Immuta actually diverge.

Attributes where Apache Doris and Immuta differ
AttributeApache DorisImmuta
Starting priceFreeOn request
Pricing modelOpen source, no licence feequote
Free tierYesNo
PlatformsLinux, Docker, KubernetesWeb, API, Cloud

Identical on both: user rating (Not yet rated), category (Databases).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Apache Doris

  • MySQL wire protocol
  • Aggregate and unique key models
  • Materialised views
  • Multi-catalogue federation
  • Routine load from Kafka
  • Compute storage separation
  • Inverted indexes
  • Workload groups

Only in Immuta

  • Attribute-based policy
  • Native enforcement
  • Dynamic masking
  • Row-level filtering
  • Purpose-based access
  • Sensitive data tagging
  • Audit logging
  • Multi-platform

What people use each for

The jobs each tool is most often brought in to do.

Apache Doris

  • A team whose MySQL read replica can no longer serve reporting queries and wants an OLAP engine its existing drivers already speaknot Immuta
  • A real-time dashboard backend needing sub-second aggregation over billions of rows with hundreds of concurrent usersnot Immuta
  • An ad or ecommerce platform that needs updates and deletes on analytical tables, which append-only OLAP engines handle badlynot Immuta
  • A data team that wants one SQL endpoint over both internal tables and existing Hive or Iceberg tables in the lakenot Immuta

Immuta

  • A bank whose Snowflake estate has grown to tens of thousands of roles that no one can review before an auditnot Apache Doris
  • A healthcare analytics team that must let researchers query patient data with identifiers masked unless a specific purpose is recordednot Apache Doris
  • A multinational applying different residency and access rules per jurisdiction to the same tables without duplicating datasetsnot Apache Doris
  • An organisation running both Snowflake and Databricks that wants one policy set rather than two divergent implementationsnot Apache Doris

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Apache Doris

  • Two competing commercial vendors, VeloDB and SelectDB, were founded by overlapping core contributors, which makes the long-term governance and roadmap of the project harder to predict than a single-sponsor project.
  • A large share of design discussion, issue reports and documentation detail originates in Chinese, so teams that do not read it get a thinner picture of known problems and workarounds.
  • Operating a cluster means managing frontend and backend node roles, tablet balancing and compaction tuning, and compaction backlogs under heavy upsert load are a recurring production complaint.
  • The MySQL protocol compatibility is at the wire level, not full MySQL semantics, so queries and functions still need porting and the familiarity can mislead.
  • Managed cloud availability outside China and major clouds is limited compared with ClickHouse or Snowflake, so many Western adopters end up self-hosting whether they wanted to or not.

Immuta

  • Contracts commonly start around one hundred to two hundred thousand US dollars a year for mid-market deployments and exceed five hundred thousand at enterprise scale, which excludes most data teams without a regulatory mandate.
  • Policy is only as good as the data classification underneath it, so an organisation with poorly tagged columns will spend months on classification before Immuta enforces anything useful.
  • Native enforcement means capability varies by platform, and a feature available on Snowflake may be absent or behave differently on BigQuery, which undermines the promise of one policy set everywhere.
  • Adding an access governance layer creates a new dependency in the path to data: a misconfigured policy silently returns fewer rows rather than erroring, and analysts can act on incomplete results without noticing.
  • It governs cloud data platforms, so personal data in operational databases, files and SaaS applications sits outside its scope and needs separate controls, meaning Immuta is rarely the whole answer.

Pricing, plan by plan

Apache Doris

Free
  • Apache DorisFree
    • Apache 2.0 licence with no usage restrictions
    • All engine features included
    • Community support via mailing list and Slack

Immuta

On request
  • Immuta Platform$undefined/year
    • Attribute-based policy authoring
    • Native enforcement in supported data platforms
    • Dynamic masking and row-level security

Which should you pick?

Choose Apache Doris if

  • You need mysql wire protocol.
  • You want to start without paying.
  • You work on Linux, Docker, Kubernetes.
  • You also want aggregate and unique key models.

Choose Immuta if

  • You need attribute-based policy.
  • You work on Web, API, Cloud.
  • You also want native enforcement.

Questions people ask

Is Apache Doris or Immuta better?
Neither clearly leads. Apache Doris starts at Free and Immuta at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Apache Doris or Immuta?
Apache Doris has a free tier; the other does not. Paid plans start at Free for Apache Doris and On request for Immuta.
Does Apache Doris or Immuta run on more platforms?
Apache Doris runs on Linux, Docker, Kubernetes. Immuta runs on Web, API, Cloud.
Can I use Apache Doris for free?
Yes. Apache Doris has a free tier, so you can try it without paying. Immuta starts at On request.
What is Apache Doris best used for?
Apache Doris is most often used for a team whose mysql read replica can no longer serve reporting queries and wants an olap engine its existing drivers already speak, a real-time dashboard backend needing sub-second aggregation over billions of rows with hundreds of concurrent users, an ad or ecommerce platform that needs updates and deletes on analytical tables, which append-only olap engines handle badly, a data team that wants one sql endpoint over both internal tables and existing hive or iceberg tables in the lake. Of those, a team whose mysql read replica can no longer serve reporting queries and wants an olap engine its existing drivers already speak and a real-time dashboard backend needing sub-second aggregation over billions of rows with hundreds of concurrent users are not what Immuta is typically brought in for.
What can Apache Doris do that Immuta cannot?
Apache Doris covers MySQL wire protocol, Aggregate and unique key models, Materialised views, Multi-catalogue federation. Immuta covers Attribute-based policy, Native enforcement, Dynamic masking, Row-level filtering.

Answered from the vendors’ own pages

Apache Doris: Is Apache Doris really free?

Yes, it is Apache 2.0 with no usage restrictions. The commercial products are managed services from VeloDB and SelectDB.

Immuta: Does Immuta sit in the query path?

No. It compiles policies into the data platform's own native controls, so queries run at normal speed through your existing tools.

Apache Doris: Can I use my MySQL tools with it?

Yes, it implements the MySQL wire protocol, so clients and BI connectors attach without a new driver, though SQL semantics differ.

Immuta: What does it cost?

Not published. Market data suggests roughly 100,000 to 200,000 US dollars a year for mid-market deployments and considerably more at enterprise scale.

Apache Doris: How does it compare with ClickHouse?

Doris handles updates and high concurrency more comfortably; ClickHouse is generally faster on raw single-query scan throughput and has far wider Western support.

Immuta: Is Immuta still independent?

Yes. It remains independently owned, unlike several competitors in data access governance that have been acquired.

Apache Doris: Who maintains it?

The Apache Software Foundation project, with most committers employed by VeloDB or SelectDB.

Immuta: Does it work across more than one warehouse?

Yes, one policy set can target Snowflake, Databricks, BigQuery and Starburst, though enforcement capability varies by platform.

Share

Related pages

Other head to heads