Alternative
Immuta Alternatives and Immuta Competitors: Access Governance Compared on Real Pricing
Immuta is a data access governance platform: it enforces who can query which rows and columns across Snowflake, Databricks, Starburst and Teradata, and masks what a user is not cleared to see. It publishes no price on its own website, and its AWS Marketplace listing sells 960 Immuta Units for $96,000.00 a year. Datatrail solves the neighboring problem rather than the same one. It maps column-level lineage read-only, so you can prove where sensitive data actually flows before you write a policy about it.
Last updated August 2026
Side by side
Datatrail vs Immuta
| Capability | Datatrail | Immuta |
|---|---|---|
| Column-level data lineage | Via catalog integration | |
| Impact analysis before a change ships | ||
| Freshness and schema-change monitoring | ||
| Attribute-based access control and policy enforcement | ||
| Dynamic masking and row-level security | ||
| Published list price | Yes, on our pricing page | $96,000/yr, Marketplace only |
| Planned self-serve signup, no sales call | ||
| Read-only, writes nothing to your warehouse | Writes policy objects | |
| Planned to be live in minutes, no rollout |
Comparison reflects general product positioning and is provided in good faith. Verify current capabilities with each vendor.
See it live
Lineage and impact, self-serve
Read-only connection. Datatrail never moves or mutates your data.
What Immuta does well
Immuta is a serious product in a category Datatrail does not compete in, and it is worth being precise about that before comparing anything. Immuta enforces data access policy at query time. You write a rule once, in attribute-based terms, and Immuta pushes it down into Snowflake, Databricks, Starburst, Teradata, BigQuery, Redshift, Azure Synapse and the rest of its connector list, so the same rule holds no matter which engine the query arrives through. Rows a user is not entitled to see disappear. Columns they are not cleared for come back masked. The audit trail records what was asked for and what was returned.
The reason enterprises buy it is that the alternative is maintaining the same policy by hand in every platform, in each platform's own dialect of grants and row access policies, and then proving to an auditor that the copies never drifted. Immuta collapses that into one policy surface. In 2026 the company positions itself as "the data provisioning company", organized around three modules it calls Govern, Provision and Comply, and it has extended the model to AI agents under the name Agentic Data Access, treating an agent as an identity that receives entitlements like any other user.
It also integrates with catalogs rather than replacing them. Immuta lists Alation, Atlan, Collibra, Snowflake Horizon and Databricks Unity Catalog among its connectors and pulls their tags in to drive policy. That tells you exactly where it sits in a stack: it is the enforcement layer, not the inventory and not the map.
What Immuta costs: the only published price is $96,000 a year
Immuta does not publish pricing anywhere on its own website. Checked on 26 August 2026, the URL immuta.com/pricing returns a 404 page reading "Whoops, that page is gone." There is no pricing page to quote from.
There is exactly one place Immuta is obliged to post a real dollar figure, and it is the same place Collibra and Alation are: a transactable AWS Marketplace listing has to carry a transactable price. The Immuta Data Security Platform listing does. Here is what it says, read from the live listing on 26 August 2026.
| Immuta Data Security Platform, AWS Marketplace | Published value |
|---|---|
| Contract dimension | 960 Immuta Units |
| Dimension description | "A monthly metric based on user subscription count and data store type" |
| Cost per 12 months | $96,000.00 |
| Implied price per Unit | $100.00 |
| Contract terms offered | 12 months only |
| Is a Unit defined? | No |
| Refund policy | "No refunds" |
Read directly from the public AWS Marketplace product page on 26 August 2026. US list price for a standard contract, excluding private offers, reseller margin and negotiated discounts.
Two things are worth pulling out of that table.
The unit price is exactly $100. $96,000.00 divided by 960 Units is $100.00 per Immuta Unit, with no rounding at all. A number that round is a strong hint that the listing is a packaged reference bundle rather than a computed quote, which is useful context before you treat it as a ceiling.
The unit is not defined. The listing describes an Immuta Unit as a monthly metric based on user subscription count and data store type. It never says how many users make one Unit, which data store types cost more than others, or whether 960 Units is an annual pool or a monthly allowance billed twelve times over. So the published price buys an undefined quantity of an undefined thing. This is not a failing unique to Immuta, we found the same pattern on the Alation listing when we compared Alation and Collibra pricing, but it does mean $96,000.00 is a starting coordinate rather than a quote. Note also that Immuta offers a single 12-month term with no 24 or 36 month option, where Collibra offers all three.
Use the figure the way a buyer should: as the only public floor that exists anywhere, and as evidence in the room when a sales conversation opens somewhere very different.
Immuta competitors, and which one replaces which part
Immuta gets compared against tools that do genuinely different jobs, which is why shortlists in this category tend to be incoherent. It helps to sort the field by what each thing actually replaces.
| Tool | What it really is | Replaces Immuta? |
|---|---|---|
| Privacera | Centralized access policy across analytics engines | Yes, closest direct rival |
| Databricks Unity Catalog | Native governance inside one platform | Yes, if you are single-platform |
| Snowflake Horizon | Native governance inside one platform | Yes, if you are single-platform |
| Collibra, Alation, Atlan | Governance and catalog suites | No, usually bought alongside |
| BigID | Sensitive data discovery and classification | Partly, feeds policy rather than enforcing it |
| Datatrail | Column-level lineage and observability | No, different problem |
Privacera is the closest like-for-like. It does the same job, centralized policy across analytics engines, and builds on Apache Ranger, which it lists among the open source projects under its umbrella. It has also pushed into AI governance under the Trust3 AI name. If you are running a real Immuta evaluation, Privacera belongs in it.
The platform-native options are the ones most teams underweight. If everything you govern lives in one warehouse, Databricks Unity Catalog or Snowflake Horizon already gives you row access policies, masking policies and tag-based governance with no extra vendor. Immuta earns its price when you have two or more engines and refuse to maintain the same rule twice. Buying it for a single Snowflake account is usually paying to solve a problem you do not have yet.
The catalog suites are not substitutes. Collibra, Alation and Atlan document, classify and steward data. Immuta enforces the decision at query time. Directory sites list them as Immuta alternatives because they share the word governance, but swapping one for the other leaves a real gap. The wider field is laid out in our data governance tools comparison.
Companies similar to Immuta and Anomalo in the Snowflake and Databricks ecosystem
These are two different categories that buyers routinely shortlist together, which is why the answer looks messy until you split it. Immuta belongs to access governance, where the peers are Privacera, Satori and ALTR plus the platform-native Unity Catalog and Snowflake Horizon. Anomalo belongs to data observability and quality, where the peers are Monte Carlo, Bigeye, Metaplane, Soda, Acceldata and Sifflet. Nothing in the first lane substitutes for anything in the second.
| Company | Lane | What it actually does |
|---|---|---|
| Immuta | Access governance | Enforces row and column access policy at query time across engines |
| Privacera | Access governance | Centralized policy across analytics engines, built on Apache Ranger |
| Satori | Access governance | Access control and masking through a data access proxy |
| ALTR | Access governance | Access control and tokenization, Snowflake-first |
| BigID, Securiti | Data security posture | Discover and classify sensitive data, feed policy rather than enforce it |
| Databricks Unity Catalog | Access governance, native | Governance built into Databricks, no extra vendor |
| Snowflake Horizon | Access governance, native | Governance built into Snowflake, no extra vendor |
| Anomalo | Data quality | Automated, model-based quality checks on warehouse tables |
| Monte Carlo | Data observability | Freshness, volume and schema incident detection at scale |
| Bigeye, Metaplane, Sifflet | Data observability | Monitoring and anomaly detection over warehouse metadata |
| Soda, Great Expectations | Data quality testing | Declarative or code-defined tests you run in CI |
| Acceldata | Data observability | Pipeline, spend and reliability monitoring across the stack |
| Datafold | Change testing | Diffs data between environments before a change ships |
| Datatrail | Lineage and observability | Column-level lineage plus freshness and schema-change alerts, read-only |
The reason the two lanes get bundled is that both are bought by the same person, usually a data platform lead on Snowflake or Databricks who has just been asked an uncomfortable question by security or by an auditor. They are not competing purchases. A team that has Immuta and no quality monitoring will still ship a broken dashboard; a team that has Anomalo and no access policy will still leak a column. Most mature stacks in this ecosystem end up with one tool from each lane.
Lineage is the layer underneath both, which is the honest reason Datatrail shows up on these shortlists without replacing either. Access policy needs to know where a sensitive column actually flows before you can claim it is covered, and quality monitoring needs to know what breaks downstream when a table changes. The wider field is laid out in our data observability tools and data governance tools comparisons.
What Immuta's competitors actually list at, read from live rate cards
Immuta's $96,000.00 is easier to judge next to the rest of the category. Almost every article says these vendors do not publish pricing, which is true of their own websites and false of their AWS Marketplace listings, where a transactable offer has to carry a real dollar amount. Here is what those listings said when we read them.
| Vendor | What the listing sells | 12-month list | Read on |
|---|---|---|---|
| BigID | BigID Next, Discovery Foundation | $175,000.00 | 31 Aug 2026 |
| Collibra | Collibra Cloud Platform, 1 Unit | $170,000.00 | 1 Sep 2026 |
| Satori, Business | Satori Data Security Platform | $150,000.00 | 1 Sep 2026 |
| Privacera | Data Access Governance Starter pack | $100,000.00 | 1 Sep 2026 |
| Immuta | 960 Immuta Units | $96,000.00 | 26 Aug 2026 |
| Satori, Base | Satori Data Security Platform | $70,000.00 | 1 Sep 2026 |
| Varonis, Snowflake | Per-connector unit | $30,000.00 | 1 Sep 2026 |
| Varonis, one SaaS app | Per-connector unit | $310.00 | 1 Sep 2026 |
| Satori, Starter | Satori Data Security Platform | $0.00 | 1 Sep 2026 |
US list prices read from the public AWS Marketplace product pages on the dates shown, excluding private offers, reseller margin and negotiated discounts.
Immuta sits in the middle of its direct rivals and well below the discovery platforms. Against Privacera, the nearest architectural match, it is $4,000 cheaper at list for an entirely different unit, so the comparison is directional rather than exact. Against Satori it is more expensive than Base and cheaper than Business, though Satori is the only one here with a real $0 tier. Against BigID and Collibra it is roughly half the price, which is the right result given those tools solve broader problems.
Two structural things are worth knowing before a negotiation. Immuta offers a 12-month term only, where Collibra and Privacera also list 24 and 36 month options. And on every vendor that does offer them, the multi-year price is exactly two or three times the annual one, so a longer commitment buys nothing at list and any multi-year discount is a concession you have to ask for. The full field, including Varonis, Netwrix, Cyera and the native controls in Snowflake and Databricks, is laid out in our comparison of data access governance tools, and the Varonis rate card is broken down connector by connector in our guide to Varonis pricing.
Why access governance needs lineage underneath it
Here is the honest version of where Datatrail fits, and it is not as a replacement for Immuta.
An access policy protects the column you knew to write a policy about. Sensitive data does not stay in that column. Someone selects it into a derived table, an analyst aggregates that into a mart, a dbt model joins the mart into a wider table, and six hops later a field derived from protected data is sitting in a dashboard that no policy was ever applied to. Nothing was bypassed and no rule was broken. The data simply moved somewhere the rule did not follow.
That is a lineage question, not a policy question, and it is the one that tends to surface during an audit rather than during a rollout. Answering it means being able to say, for a given source column, every downstream table, model, exposure and dashboard that derives from it. Datatrail builds that from query history and dbt artifacts as column-level lineage, then turns it into impact analysis, so you can see the blast radius of a change or a classification before it ships instead of after. Our data governance use case covers how teams pair the two.
So choose on the actual job. If you need to stop a user from seeing a row, buy Immuta, or Privacera, or use what your warehouse already ships. Datatrail does not enforce policy and we would not suggest routing enforcement through a third party that reads your metadata. If you need to know where regulated data has spread, prove it to an auditor, and catch the change that is about to leak it into a new table, that is lineage, that is us, and it is read-only, planned to be self-serve and priced on the pricing page. The difference between the two categories is unpacked further in data lineage vs data catalog, and the full field is in our data lineage tools comparison.
Questions people ask
Immuta and Datatrail, answered
What companies are similar to Immuta and Anomalo?
They sit in two different categories that buyers shortlist together. Companies similar to Immuta enforce data access governance: Privacera, Satori and ALTR, plus the platform-native Databricks Unity Catalog and Snowflake Horizon. Companies similar to Anomalo monitor data quality and observability: Monte Carlo, Bigeye, Metaplane, Soda, Acceldata and Sifflet. A tool from the first group does not substitute for one in the second, and most mature Snowflake or Databricks stacks run one of each.
How much does Immuta cost?
Immuta publishes no pricing on its own website, and immuta.com/pricing returned a 404 page when checked on 26 August 2026. Its AWS Marketplace listing carries the only public figure: 960 Immuta Units for $96,000.00 on a 12-month contract, which works out to exactly $100.00 per Unit. The listing does not define what one Unit entitles you to.
What are the best Immuta alternatives?
It depends which part of Immuta you actually need. For centralized access policy across several engines, Privacera is the closest direct rival. If everything lives in one platform, Databricks Unity Catalog or Snowflake Horizon already covers it at no extra vendor cost. For governance and cataloging rather than enforcement, Collibra, Alation or Atlan. For lineage and impact analysis, Datatrail.
Is Immuta a data catalog?
No. Immuta is an access governance and policy enforcement platform, and it integrates with catalogs rather than replacing them. Its connector list includes Alation, Atlan, Collibra, Snowflake Horizon and Databricks Unity Catalog, and it consumes their tags to drive policy decisions. If you need an inventory of what data exists and what it means, you still need a catalog alongside it.
Does Immuta do data lineage?
Not as a lineage product. Immuta is built to enforce policy at query time and to audit what was accessed, and it relies on integrations with catalogs for lineage and tag context. If your requirement is tracing a column back to its source or listing every downstream table and dashboard derived from a protected field, that is a lineage tool job rather than an access governance job.
Immuta vs Privacera: what is the difference?
Both centralize data access policy across analytics engines and push enforcement down natively rather than proxying queries, so the category is the same. Privacera was founded in 2016 by the creators of Apache Ranger and its pitch is carrying an existing Ranger policy model into the cloud. Immuta positions around attribute-based policy, its Govern, Provision and Comply modules, and agent access. Neither publishes pricing on its own website, but both have AWS Marketplace listings that do: Immuta lists 960 Units at $96,000.00 a year, and Privacera lists a dimension named Data Access Governance Starter pack at $100,000.00 a year, read 1 September 2026. Note that privacera.com now redirects to trust3.ai, so confirm which entity your contract will name.
Does Immuta work with Databricks and Snowflake?
Yes, both are native integrations and they are the two platforms Immuta is most commonly deployed against. Its documented connector list also covers Starburst and Trino, Teradata, Google BigQuery, Amazon Redshift, Athena, EMR and S3, PostgreSQL, Oracle and Azure Synapse. The multi-engine coverage is the main reason to pay for Immuta rather than use the governance features your warehouse already includes.
Other comparisons
See it on your own warehouse
Connect read-only, transparent pricing, see your lineage in minutes. Datatrail never moves or mutates your data. Decide for yourself.