Data Access Governance Software and Tools: 12 Platforms Compared on Verified Pricing
Twelve platforms checked against vendor documentation, with real US list prices read from live AWS Marketplace rate cards. Nine vendors that are widely reported not to publish pricing do publish it, two of the pure plays have quietly changed owner, and the entry price is far above what published guidance claims.
Read-only connection. Datatrail never moves or mutates your data.
In short
Data access governance software controls and proves who can reach which data, under what conditions, and for how long. The leading data access governance tools in 2026 are Immuta, Privacera, Satori, Varonis, BigID, Microsoft Purview, Securiti, Cyera, Sentra and Netwrix, alongside the native controls in Snowflake Horizon and Databricks Unity Catalog. They fall into three groups that are not interchangeable: warehouse-native policy engines that enforce at query time, security-led platforms that lead with permissions and discovery across files and SaaS, and posture tools that score risk without enforcing anything. Real US list prices exist for most of them on AWS Marketplace, and they start far higher than published guidance suggests: Privacera's dimension named "Starter pack" lists at $100,000 a year.
Last updated September 2026
What it actually costs
Data access governance pricing, read from live rate cards
Nearly every article about this category says the vendors do not publish pricing, then quotes a range with no source. Both halves are wrong. The vendors do not publish on their own websites, but a transactable AWS Marketplace listing is obliged to carry a real dollar amount, and most of these companies have one. Below is what those listings actually said when we read them, in US dollars, at list, before any negotiation or private offer.
| Vendor | What the listing sells | 12-month list | 24 / 36 month | Read on |
|---|---|---|---|---|
| BigID | BigID Next, Discovery Foundation, 1 Unit | $175,000 | None offered | 31 Aug 2026 |
| Collibra | Collibra Cloud Platform, 1 Unit | $170,000 | $340,000 / $510,000 | 1 Sep 2026 |
| Satori, Business | Satori Data Security Platform | $150,000 | None offered | 1 Sep 2026 |
| Informatica | 120 IPU per month | $131,760 | Exactly 2x and 3x | 26 Aug 2026 |
| Privacera | Data Access Governance Starter pack | $100,000 | $200,000 / $300,000 | 1 Sep 2026 |
| Immuta | 960 Immuta Units | $96,000 | None offered | 26 Aug 2026 |
| Satori, Base | Satori Data Security Platform | $70,000 | None offered | 1 Sep 2026 |
| Alation | Alation Data Catalog, 1 Unit | $60,000 | None offered | 26 Aug 2026 |
| Varonis, Snowflake | Per-connector unit | $30,000 | $60,000 / $90,000 | 1 Sep 2026 |
| Varonis, any database | Universal Database Connector unit | $15,000 | $30,000 / $45,000 | 1 Sep 2026 |
| Varonis, SaaS apps | Per-connector unit, Box or Slack or Okta | $310 | $620 / $930 | 1 Sep 2026 |
| Sentra, Enterprise | Sentra Enterprise Plan | $500,000 | None offered | 2 Sep 2026 |
| Cyera, Enterprise | Cloud Data Security Platform, up to 250TB | $250,000 | None offered | 2 Sep 2026 |
| Securiti | Securiti Platform Fee, 1 Unit | $100,000 | None offered | 2 Sep 2026 |
| Cyera, Standard | Cloud Data Security Platform, up to 25TB | $50,000 | None offered | 2 Sep 2026 |
| Satori, Starter | Satori Data Security Platform | $0 | None offered | 1 Sep 2026 |
Every figure above was read directly from the public AWS Marketplace product page on the date shown. US list price for a standard public contract, excluding private offers, reseller margin and negotiated discounts. Marketplace listings change, so re-check before you put one of these numbers in a business case.
$100k
The word "Starter" costs six figures
Privacera's Marketplace dimension is named, in the vendor's own words, Data Access Governance Starter pack, and it lists at $100,000.00 a year. Several widely cited articles put departmental deployments in this category at $5,000 to $25,000. The transactable listings do not support that number anywhere.
0%
A longer term buys nothing at list
Across five vendors and more than twenty pricing dimensions, every multi-year term is exactly two or three times the annual price. Collibra runs $170,000, $340,000, $510,000. Privacera runs $100,000, $200,000, $300,000. All seventeen Varonis connectors scale linearly. Any multi-year discount is a concession you negotiate, not a published rate.
97x
Covering the warehouse costs far more
Varonis charges $310 per unit per year to cover Slack, Box, Okta or Salesforce, and $30,000 per unit to cover Snowflake. That is roughly ninety-seven times as much for the structured estate, which tells you where the vendor believes the risk and the willingness to pay both sit.
The only bottom-up estimate available
The full Varonis per-connector rate card
Varonis is the one vendor in this category you can budget for without a sales call, because its listing publishes seventeen separate per-connector unit prices rather than a single platform fee. We have not seen this rate card reproduced anywhere else, so here it is in full, sorted by annual unit price. Every one of these doubles at 24 months and triples at 36.
| Connector dimension | Per unit, 12 months |
|---|---|
| Varonis for Snowflake | $30,000.00 |
| Universal Database Connector, any structured database | $15,000.00 |
| Varonis for AWS, S3, EC2 and RDS | $750.00 |
| Varonis for Azure IaaS | $750.00 |
| Varonis for M365 | $400.00 |
| Varonis for Windows and NAS file shares | $400.00 |
| Varonis Interceptor for Email and Browser | $400.00 |
| Varonis for Salesforce | $310.00 |
| Varonis for Box | $310.00 |
| Varonis for Slack | $310.00 |
| Varonis for Google Drive | $310.00 |
| Varonis for Okta | $310.00 |
| Varonis for Jira | $310.00 |
| Varonis for GitHub | $310.00 |
| Varonis for Zoom | $310.00 |
Three things are worth pulling out of that table before you use it.
The unit is not defined on the listing. Varonis sells these dimensions in "Units" and does not state what one Unit covers: not a seat, not a terabyte, not a mailbox. So the rate card gives you the shape of the pricing and the relative cost of each platform, which is genuinely useful, but you still cannot compute your own bill from it. That is the same limitation we found on the Immuta and Alation listings, where an undefined Unit carries the whole price.
The SaaS connectors are deliberately flat. Box, Salesforce, Slack, Google Drive, Okta, Jira, GitHub and Zoom are all priced identically at $310. A vendor that charges the same for eight very different APIs is pricing by seat or by risk rather than by engineering effort, which is a reasonable hint that these numbers are negotiable in a bundle.
Structured data is a different business. Snowflake at $30,000 and the Universal Database Connector at $15,000 sit two orders of magnitude above the SaaS line. If your sensitive data lives in the warehouse rather than on file shares, Varonis stops being the cheap option very quickly, and the warehouse-native tools in the next section become the more sensible comparison.
Side by side
Data access governance tools compared
| Tool | Best for | Lane | How it enforces | Estate it covers | Published price |
|---|---|---|---|---|---|
| Immuta | Warehouse access policy at query time, enforced natively | Access policy | Native pushdown | Warehouses and lakehouses | $96,000 / yr list |
| Privacera, now Trust3 AI | Teams already standardized on Apache Ranger policy | Access policy | Native pushdown | Cloud analytics plus legacy Hadoop | $100,000 / yr list |
| Satori, now part of Commvault | Fast deployment and database activity monitoring | Access policy | In-path proxy | Databases and warehouses | $0 to $150,000 / yr |
| Varonis | Permissions and overexposure across files, email and SaaS | Security-led DAG | Permission remediation | Files, M365, SaaS, some warehouses | $310 to $30,000 per unit |
| BigID | Finding sensitive data you cannot locate, at scale | Security-led DAG | Discovery and workflow | Everything, structured and unstructured | $175,000 / yr list |
| Microsoft Purview | Microsoft-centric estates that want one bill | Security-led DAG | Labels, DLP and policy | Microsoft 365, Azure, some third party | Published metered rates |
| Securiti | Privacy operations and subject-rights automation | Security-led DAG | Policy and privacy workflow | Multicloud and SaaS | $100,000 / yr list |
| Cyera and Sentra | Cloud-native DSPM: finding and scoring cloud data risk | Security-led DAG | Risk scoring, limited enforcement | Cloud stores and SaaS | $50,000 to $500,000 / yr |
| Netwrix | Mid-market file and Active Directory access reviews | Security-led DAG | Permission remediation | File servers, AD, M365 | No published rate card |
| Snowflake Horizon | Snowflake-only estates that want zero extra vendors | Native control | Built into the warehouse | Snowflake only | Included in the platform |
| Databricks Unity Catalog | Databricks-only estates, including the old Okera team | Native control | Built into the lakehouse | Databricks only | Governance sits in the Premium tier |
| Collibra | A formal, audited governance program around the policy | Governance program | Workflow and attestation | Enterprise-wide | $170,000 / yr list |
| Datatrail | Knowing where the sensitive column actually went | Lineage and impact | Does not enforce policy | Snowflake, BigQuery, Redshift, Databricks, Postgres | Planned, self-serve |
Capabilities reflect each vendor's own documentation as checked on 1 September 2026. Only figures a vendor publishes itself, or that are returned by its own price API or Marketplace rate card, appear anywhere on this page.
Shortlist by question
The three lanes, and why the shortlists barely overlap
Most bad purchases in this category come from comparing tools that were never competing for the same job. Every vendor here describes itself as data access governance, and they mean three different things by it. Work out which question you are answering before you take a demo.
Warehouse policy engines
Immuta, Privacera, Satori, plus native Snowflake Horizon and Unity Catalog
Answer the question "may this analyst read this column right now." They classify columns, express rules as policy, and enforce at query time through masking, row filters and attribute-based access control. This is the lane to shortlist when your sensitive data lives in a warehouse and the driver is an engineering or platform team. They are close to useless on file shares and mailboxes.
Security-led platforms
Varonis, BigID, Netwrix, Microsoft Purview, Securiti
Answer the question "who currently has access to everything, and where is it." They lead with discovery, classification and effective-permissions mapping across files, email, SharePoint and SaaS, then remediate overexposure. This is the lane when the honest answer to where your regulated data lives is that nobody knows, and when most of it is not in a warehouse.
Posture and risk scoring
Cyera, Sentra, and the DSPM modules inside the platforms above
Answer the question "what is our exposure." They connect to cloud accounts, build an identity-to-data graph, and rank dangerous combinations. What they generally do not do is stop a named user reading a named column. Buying posture when you wrote enforcement requirements is the single most common way one of these projects stalls after six months.
The tools
What each data access governance tool is actually good at
Immuta
Access policyImmuta is the reference implementation of warehouse access policy. It discovers and classifies columns, then compiles policy-as-code into the native controls of Snowflake, Databricks, BigQuery and Starburst rather than proxying your queries, so nothing new sits in the data path and there is no new failure point at 3am. Attribute-based access control, dynamic masking and purpose-based restrictions are all first class. Its AWS Marketplace listing sells 960 Immuta Units for $96,000.00 on a 12-month contract, which is exactly $100.00 per Unit, and the listing never defines what a Unit entitles you to. It will not tell you what a column means or where it came from, which is why it is usually bought next to a catalog rather than instead of one. Full breakdown on our Immuta comparison.
Privacera, now Trust3 AI
Access policyPrivacera was founded in 2016 by the people who built the software that became Apache Ranger, and that heritage is the whole product thesis: it extends a Ranger policy model most large Hadoop estates already have off-premises into Snowflake, Databricks, AWS and Azure. Like Immuta it pushes enforcement down into each source rather than intercepting queries, so there is no proxy and no single point of failure in the query path. That makes it the natural choice when you are migrating a Hadoop estate and want to carry existing Ranger policies with you instead of rewriting them. Two things to know before you shortlist it. Its AWS Marketplace listing, titled PrivaceraCloud - SaaS Data Access Governance, sells a dimension named Data Access Governance Starter pack for $100,000.00 a year. And the company is moving to a new identity: privacera.com now redirects to trust3.ai, where the product is positioned as purpose-based access for AI agents across Snowflake, Databricks, Iceberg, Anthropic and OpenAI.
Satori, now part of Commvault
Access policySatori takes the opposite architectural bet to Immuta and Privacera: it sits in the data path as an agentless layer in front of your databases, which is why it deploys in hours rather than weeks and why it can do database activity monitoring that pushdown tools structurally cannot. The trade is that something new is now between your analysts and your data, and that is a real conversation with an infrastructure team. Its Marketplace listing is the most transparent in the category, with three named tiers: Starter at $0.00, Base at $70,000.00 and Business at $150,000.00, 12 months only. The strategic caveat is ownership. Commvault announced its intent to acquire Satori Cyber on 24 July 2025 and closed in December 2025, and satoricyber.com/platform now redirects to commvault.com. If you shortlist Satori in 2026 you are buying from a backup and cyber-resilience company, and you should ask directly about the standalone roadmap.
Varonis
Security-led DAGVaronis is the oldest and largest company on this page and it solves a genuinely different problem from the warehouse tools: who currently has access to the twelve million files, mailboxes and SharePoint sites nobody has audited since 2019. Effective-permissions mapping, blast-radius analysis and automated remediation of overexposed data are what it is actually good at, and no warehouse-native tool comes close on unstructured data. It is priced completely differently too. Rather than one platform fee, its Marketplace listing publishes a rate card of seventeen separate per-connector unit prices, which makes it the only vendor here where you can build a bottom-up estimate before you ever speak to sales. Treat it as complementary to a warehouse policy engine, not as an alternative to one.
BigID
Security-led DAGBigID leads with discovery and classification rather than enforcement, and it is the strongest option here when the honest answer to "where is our regulated data" is that nobody knows. Its correlation approach links records back to an identity across systems, which is what privacy and subject-rights work actually requires. Access control exists but is not the center of gravity. Its BigID Next Marketplace listing carries the highest 12-month list price we have found anywhere in this category, $175,000.00, and the vendor description attached to that very price reads "Please contact BigID for custom pricing." Both facts are true at once. See our BigID comparison for the full pricing table.
Microsoft Purview
Security-led DAGPurview is the only platform on this page that publishes exact metered rates you can query from a public API before a sales call, which is a real advantage when you have to build a business case. Sensitivity labels, DLP and access policy are strong inside Microsoft 365 and Azure, and weaker the further you get from them. The trap is naming, because three different products carry the Purview label and the classic Data Catalog is in customer support mode. Microsoft also marks Amazon Redshift as unsupported for lineage entirely. We break the meters down in our guide to Microsoft Purview pricing.
Securiti
Security-led DAGSecuriti sells a broad data command center covering discovery, DSPM, privacy operations, consent and access intelligence, and it is a credible single-vendor answer when your driver is a privacy regulation rather than an engineering problem. It overlaps heavily with BigID and increasingly with the AI-governance positioning everyone in this category adopted in 2025 and 2026. If your buying committee is led by a privacy office or general counsel it belongs on the shortlist. If it is led by a data platform team, the warehouse-native tools will fit your workflow far better. On pricing, its AWS Marketplace listing sells a single dimension named Platform Fee at $100,000.00 for 12 months, read on 2 September 2026. The dimension is one Unit and the listing does not define what a Unit entitles you to.
Cyera and Sentra
Security-led DAGThese two are data security posture management rather than access governance, and the distinction matters when you are writing requirements. They connect to your cloud accounts, find sensitive data, build an identity-to-data graph and tell you which combinations are dangerous. What they largely do not do is enforce a policy at query time on a specific column for a specific analyst. Buy DSPM to answer "what is our exposure," buy an access policy engine to answer "who may see this row." A surprising number of stalled projects come from buying the first and having written requirements for the second. Both publish real rate cards, read on 2 September 2026: Cyera lists three packages at $50,000, $100,000 and $250,000 against stated ceilings of 25TB, 100TB and 250TB, and Sentra lists four tiers at $50,000, $100,000, $250,000 and $500,000 without stating any entitlement. We break both down in our comparison of data classification tools.
Netwrix
Security-led DAGNetwrix is the pragmatic mid-market answer to the same problem Varonis solves at the top of the market: stale permissions, over-privileged groups, and access reviews that currently happen in a spreadsheet once a year. It is more approachable and materially cheaper than the enterprise DSPM platforms, and for an organization whose sensitive data genuinely lives on Windows file shares and in Microsoft 365 rather than in a warehouse, it is often the correct purchase. It is not a warehouse policy engine and does not claim to be.
Snowflake Horizon
Native controlBefore you buy anything on this page, check what you already own. Snowflake Horizon includes tagging, classification, row access policies, dynamic masking and column-level lineage at no extra license cost, with lineage requiring Enterprise Edition or higher. For a single-warehouse estate with a manageable number of policies this is genuinely sufficient, and buying a third-party policy engine to sit on top of it is a common and expensive mistake. Add a vendor when policy has to be consistent across two warehouses, or across the warehouse and the file estate, because Horizon stops at the Snowflake boundary.
Databricks Unity Catalog
Native controlThe same argument applies on the lakehouse side. Unity Catalog covers grants, row filters, column masks, attribute-based access control and lineage across workspaces. It is also where a competitor went: Databricks acquired Okera on 3 May 2023 and folded its access-governance technology into Unity Catalog, so a vendor that appears on older shortlists is now a feature of the platform. The cost nuance most articles miss is that Unity Catalog is not free in the way people repeat, because the governance tier is Premium, and Premium Jobs Compute runs at exactly double the Standard rate per DBU-hour. Our Unity Catalog lineage guide has the meter detail.
Collibra
Governance programCollibra is not an access enforcement engine and is frequently miscast as one on comparison lists. What it provides is the program around the policy: who approved this access rule, against which written policy, reviewed on what date, and the evidence pack an auditor will accept. It acquired Raito in June 2025 specifically to strengthen the access side. Buy it when a regulator holds a named person in your organization accountable, and pair it with one of the enforcement tools above. Its Marketplace listing is $170,000.00 for 12 months, re-verified on 1 September 2026 and unchanged since August. Details on our Collibra comparison.
Datatrail
Lineage and impactWe should be clear about what we are, because pretending otherwise would waste your time: Datatrail is not a data access governance tool and does not enforce a single policy. There is no policy engine, no masking, no access review workflow. What we do is the job that sits immediately underneath one. You connect a read-only role, we parse query history alongside your dbt manifest into a column-level lineage graph, and that graph answers the question every access policy silently depends on: this column is classified sensitive, so which other tables, models and dashboards inherit values derived from it, and are they protected too? Masking a column in the source table while an unmasked copy sits in a downstream mart is one of the most common findings in a real access audit, and no policy engine on this page will show it to you, because they enforce at the point of access rather than tracing propagation. Buy an enforcement tool for who may see what. Use lineage to find out where it already went.
Check the ownership before the demo
Three of the vendors on your shortlist no longer exist as you know them
This category consolidated hard between 2023 and 2026, and most published comparison lists have not caught up. If your shortlist came from an article, check who owns each vendor before you book anything, because two of the pure-play access governance companies have changed hands and a third was absorbed into a warehouse.
Satori is now Commvault. Commvault announced its intent to acquire Satori Cyber on 24 July 2025 and closed in December 2025. The product is still listed and transactable on AWS Marketplace with all three tiers intact, so this is not a discontinuation, but satoricyber.com/platform now redirects to commvault.com and you would be contracting with a backup and cyber-resilience company.
Privacera is becoming Trust3 AI. Checked on 1 September 2026, privacera.com/why-privacera redirects to privacera.com/why-trust3-ai, which redirects again to trust3.ai. The positioning there is purpose-based access control for AI agents across Snowflake, Databricks, Iceberg, Anthropic and OpenAI, which is a meaningfully different pitch from the Apache Ranger continuity story that made Privacera worth shortlisting. The AWS listing still carries the Privacera name.
Okera is inside Databricks. Databricks acquired Okera on 3 May 2023 and folded its access governance technology into Unity Catalog. Okera still appears on comparison lists as an independent option. It is not one, and its only remaining Marketplace presence is a professional services listing.
The pattern is worth naming, because it changes how you should buy. Standalone data access governance is being absorbed into three larger things: the warehouse itself, the security platform, and the backup and resilience stack. That does not make a point solution the wrong choice today, but it does mean a three-year commitment carries roadmap risk that a one-year commitment does not, which is a useful thing to know given that no vendor here offers a multi-year discount at list anyway.
The gap none of them close
Every access policy silently assumes something it cannot see
Here is the failure mode that shows up in almost every real access audit, and that no tool on this page will catch for you.
Someone classifies a column as sensitive, say customers.ssn, and applies a masking policy. The policy works exactly as designed: analysts querying that table see masked values. Six months earlier, though, a pipeline selected that column into a staging table, a dbt model joined the staging table into a customer mart, and a dashboard reads the mart. The copy in the mart carries no tag, no policy and no mask, and every access check on it passes, because from the policy engine's point of view it is simply a different column in a different table.
Policy engines enforce at the point of access. They do not trace propagation, and that is an architectural property rather than an oversight: enforcing a rule on an object and knowing which other objects were derived from that object are genuinely different computations. Answering the second one requires parsing the SQL that created every table in the warehouse and building a column-level graph from it.
That is the part we build. Datatrail connects to Snowflake, BigQuery, Redshift, Databricks or Postgres with a read-only role, parses query history alongside your dbt manifest, and produces a column-level lineage graph of the whole estate. Point it at a classified column and it lists every downstream table, model and dashboard that inherits values derived from it, which is the coverage check your masking policy needs and cannot perform on itself. It is also what makes root cause analysis tractable when a number is wrong rather than merely exposed.
We are not selling you an alternative to Immuta or Varonis. Buy one of those to decide who may see what. Use lineage to find out where it already went. If you want the wider picture of how these categories fit together, our data governance tools guide covers the program layer, data catalog tools covers inventory and search, and data lineage tools covers this layer in depth.
Straight answers
Data access governance questions buyers actually ask
What is data access governance?
Data access governance is the practice of controlling and proving who can reach which data, under what conditions, and for how long. In software terms it combines four capabilities: discovery and classification of sensitive data, a policy model that expresses the rules, enforcement that applies those rules at the moment of access, and an audit trail that proves it happened. The category splits into warehouse-native policy engines such as Immuta and Privacera, security-led platforms such as Varonis and BigID that lead with permissions and discovery across files and SaaS, and the native controls already built into Snowflake and Databricks.
What is the difference between data governance and data access governance?
Data governance decides the rules and data access governance enforces one specific rule: who may see this. Governance covers definitions, ownership, quality standards, stewardship and the audit program, and it is where Collibra and Informatica compete. Access governance is narrower and more technical, concerned with entitlements, masking, row filters and access reviews. The practical consequence is that they are usually different purchases with different buyers. Governance is bought by a compliance or data office, access governance by security or the data platform team, and the shortlists barely overlap.
How much does data access governance software cost?
More than published guidance suggests. Several widely cited articles put departmental deployments at $5,000 to $25,000 a year, but the transactable AWS Marketplace listings tell a different story. Read on 1 September 2026, Privacera lists a dimension literally named Data Access Governance Starter pack at $100,000 a year, Satori lists Base at $70,000 and Business at $150,000, Immuta lists $96,000, and BigID lists $175,000. Varonis is the exception that lets you estimate from the bottom up, publishing per-connector unit prices from $310 for a SaaS application to $30,000 for Snowflake coverage.
Which data access governance tools publish their pricing?
Almost none publish on their own website, but a transactable AWS Marketplace listing has to carry a real dollar figure, and that is where the prices are. Privacera, Satori, Varonis, Immuta, BigID and Collibra all have live rate cards with real US list prices, and Satori is the most transparent with three named tiers including a genuine $0 Starter. Microsoft Purview publishes metered rates through a public price API. Securiti, Cyera and Sentra also publish real rate cards, read on 2 September 2026: Securiti lists a $100,000 platform fee, Cyera runs $50,000 to $250,000 against stated terabyte ceilings, and Sentra runs $50,000 to $500,000. Netwrix is the only vendor here with no transactable listing we could find. Treat any figure on a review site with suspicion, because those numbers contradict each other badly and none of them cite a source.
Do you get a discount for a multi-year data access governance contract?
Not at list price, and this is now a consistent pattern rather than an anomaly. Across five vendors and more than twenty separate pricing dimensions, every multi-year term we have read is exactly two times or three times the annual figure. Collibra is $170,000, $340,000 and $510,000. Privacera is $100,000, $200,000 and $300,000. All seventeen Varonis connector dimensions scale linearly. So a longer commitment buys you nothing on the published rate card, which means any multi-year discount you receive is a concession you negotiated, not a standard rate. Buyers routinely assume the opposite and open the conversation from a weaker position.
What is the difference between data access governance and DSPM?
Data security posture management finds and scores risk, and data access governance enforces a decision. A DSPM tool such as Cyera or Sentra connects to your cloud accounts, discovers sensitive data, maps which identities can reach it, and ranks the dangerous combinations. It generally will not stop a specific analyst from reading a specific column at query time. An access governance tool such as Immuta or Privacera will. Many projects stall because the team wrote enforcement requirements and then bought a posture tool, so decide which of the two questions you are actually answering before you take demos.
Do I need data access governance software if I only use Snowflake?
Probably not at first. Snowflake Horizon already includes classification, tagging, row access policies, dynamic masking and column-level lineage with Enterprise Edition or higher, at no additional license cost. For a single warehouse with a manageable set of policies that is genuinely sufficient, and buying a third-party engine to sit on top of native controls is a common and expensive mistake. The case for a vendor appears when policy has to stay consistent across two warehouses, across the warehouse and the file estate, or when you need centralized authoring and evidence that Horizon does not produce.
Is Satori still an independent company?
No. Commvault announced its intent to acquire Satori Cyber on 24 July 2025 and closed the deal in December 2025, and satoricyber.com/platform now redirects to commvault.com. The Satori Data Security Platform is still listed and transactable on AWS Marketplace with its three tiers intact, so the product is being sold, but you are buying from a cyber-resilience and backup company rather than a data security startup. Ask directly about the standalone roadmap and support model before you sign a multi-year term.
Is Privacera the same company as Trust3 AI?
They appear to be the same company under a new identity. Checked on 1 September 2026, privacera.com/why-privacera redirects to privacera.com/why-trust3-ai, which in turn redirects to trust3.ai, where the product is positioned as purpose-based access control for AI agents across Snowflake, Databricks, Iceberg, Anthropic and OpenAI. The PrivaceraCloud listing on AWS Marketplace still carries the Privacera name and the Data Access Governance description. If you are evaluating it, confirm which entity the contract will name and whether the Apache Ranger enforcement model you are buying is still the roadmap.
Does data access governance software show where sensitive data went downstream?
Generally no, and this is the most common gap in a real access audit. Policy engines enforce at the point of access, so they answer whether a given user may read a given object right now. They do not trace propagation, which means masking a column in the source table while an unmasked copy sits in a downstream mart passes every policy check and still leaks. Answering that requires column-level lineage across the whole warehouse, which is a different tool. Datatrail connects read-only and parses query history to produce exactly that graph.
See where your sensitive columns actually went
Connect a read-only role and get a column-level map of your warehouse in an afternoon. No agent, no proxy in the query path, and nothing to install.