Immutavs
Snowflake


Snowflake: If your estate is a single warehouse and its own masking and row access policies are sufficient

Attribute-based access control and masking applied inside Snowflake, Databricks and BigQuery
As of 31 August 2026, Immuta's pricing is not published; the vendor quotes on request. Immuta replaces thousands of hand-maintained database roles with policies written once and enforced natively by the warehouse. Softwr lists it under Databases. Immuta is available on Web, API, Cloud.
Overview
Immuta is a data access governance platform for cloud data platforms. Instead of granting access through per-table roles, teams write policies in plain terms, such as analysts may see transaction data with account numbers masked unless they are in the fraud team, and Immuta compiles those into native controls enforced by Snowflake, Databricks, BigQuery, Starburst and similar engines. It handles dynamic masking, row-level filtering, purpose-based access, tag-driven policy and audit logging of who queried what. The commercial argument is role explosion. A data platform with many tables, many teams and several regulatory constraints ends up with tens of thousands of roles and grants that no one can reason about, and the practical outcome is that access reviews become guesswork and sensitive columns end up broadly readable because tightening them would break something. Attribute-based policy collapses that into a small number of readable rules. Because enforcement happens natively in the warehouse rather than through a proxy, query performance is not mediated by Immuta and users keep their existing tools, which is the technical detail that separates it from proxy-based competitors that sit in the query path. What vendor pages do not say is the price floor. Market data puts mid-market deployments at roughly one hundred to two hundred thousand US dollars a year, with large enterprise deployments above five hundred thousand depending on platforms, users and policy count. That makes Immuta a purchase for organisations with a real regulatory driver, typically financial services, healthcare or government, rather than a data team that would simply prefer tidier permissions. Immuta remains independently owned, which is worth noting in a category where several rivals have been absorbed.
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Immuta.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Snowflake: If your estate is a single warehouse and its own masking and row access policies are sufficient


Databricks: If Unity Catalog governance covers your needs and you do not have multi-platform policy requirements


SailPoint: If your problem is enterprise identity and entitlement review rather than fine-grained data policy
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Immuta Platform
On request
Capabilities
Attribute-based policy
Access rules written against user and data attributes rather than per-table roles
Native enforcement
Compiles policies into the warehouse's own controls rather than proxying queries
Dynamic masking
Redacts, hashes or generalises column values by user context at query time
Row-level filtering
Restricts which rows a user sees based on attributes and purpose
Purpose-based access
Grants access tied to a declared and recorded analytical purpose
Sensitive data tagging
Classifies columns and drives policy from tags rather than table names
Audit logging
Records queries against sensitive data for regulatory review
Multi-platform
One policy set applied across Snowflake, Databricks, BigQuery and Starburst
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
No. It compiles policies into the data platform's own native controls, so queries run at normal speed through your existing tools.
Not published. Market data suggests roughly 100,000 to 200,000 US dollars a year for mid-market deployments and considerably more at enterprise scale.
Yes. It remains independently owned, unlike several competitors in data access governance that have been acquired.
Yes, one policy set can target Snowflake, Databricks, BigQuery and Starburst, though enforcement capability varies by platform.
Keep looking
Centralised data access governance from the creators of Apache Ranger, now rebranding as Trust3 AI
Google Cloud's serverless analytical warehouse, billed either by bytes scanned per query or by reserved compute slots.
Long-established enterprise MPP data warehouse, rebranded in 2026 as the Autonomous Knowledge Platform, sold for cloud, on-premises and hybrid.
Apache 2.0 distributed graph database written in Go, maintained by Hypermode, queried through GraphQL or its own DQL language.
Hosted no-code database and web app builder priced by stored records and storage, with unlimited user accounts on every plan.
The heart of the Elastic Stack for search and analytics
MIT-licensed analytical SQL database that runs inside your process, with no server, no dependencies and one writer at a time.
AWS-only managed key-value and document database with fixed per-partition throughput limits and no ad hoc queries.
The world's most complete, reliable, and secure database
SQL transformation framework enabling analytics engineers to version, test and deploy models
Erlang MQTT broker for large IoT fleets, relicensed to BSL with production free use limited to one node
Document-relational database whose hosted service closed in 2025 and whose core is now unmaintained Apache 2.0 code.
Store and sync data in real-time across all clients
Softwr does not host reviews and shows no star rating for Immuta, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Industrial process historian with published per-tag pricing and no client licence fees
Per tag band per yearNetApp-owned managed service for Cassandra, Kafka, OpenSearch, PostgreSQL and Cadence with a bring-your-own-cloud model
quoteErlang MQTT broker for large IoT fleets, relicensed to BSL with production free use limited to one node
Per month by connection and session volumeMPP analytical database with a MySQL wire protocol and sub-second aggregation on wide tables
Open source, no licence feeStreaming database that maintains incremental materialised views in SQL instead of Flink jobs
Per RisingWave Unit hourCentralised data access governance from the creators of Apache Ranger, now rebranding as Trust3 AI
quoteThe Meta-lineage distributed SQL query engine, distinct from the Trino fork
Open source, no licence fee