Immuta
Data access governance platform that enforces fine-grained, attribute-based access policies dynamically across data warehouses and lakes like Snowflake and Databricks.
Visit Website ↗Overview
Immuta is a data access governance platform that enforces fine-grained, attribute-based access control policies dynamically at query time against data warehouses and lakes such as Snowflake and Databricks, rather than provisioning static role-based permissions in advance. Founded in 2015 by Matthew Carroll and Steve Touw and headquartered in Boston, its platform spans policy enforcement (“Govern”), self-service access requests (“Provision”), compliance reporting (“Comply”), and newer agentic data-access features for AI systems.
Both Snowflake and Databricks are strategic investors and integration partners, and Immuta’s disclosed enterprise customer base includes ADP, GM, NVIDIA, Merck, Novartis, and the U.S. Department of Veterans Affairs. The company has raised roughly $267 million and reached a $1 billion valuation in its 2022 Series E round.
Its architectural differentiator — dynamic, query-time policy enforcement woven into the analytics engine itself — remains distinct from static permissioning, though funding momentum has visibly slowed since the 2022 unicorn round.
Innovation Matrix Assessment
Steady additions including agentic data-access features for AI systems in late 2025.
Dynamic, attribute-based access control materially reduces the manual data-access request bottleneck at large data-driven enterprises.
Valuation has remained static at $1B since 2022, with no larger round found since — funding momentum has plateaued.
Attribute-based, query-time dynamic access control is a meaningfully different architecture from static, pre-provisioned role-based permissioning.
A verifiable, named enterprise customer roster (NVIDIA, Merck, Novartis, GM, U.S. VA) is a real, though vendor-published, adoption signal.
Data access governance is increasingly critical as AI agents query enterprise data directly.
Why CISOs Should Care
Lets data teams grant access to sensitive datasets automatically under policy rather than having CISOs' teams manually review and approve every access request, a real operational bottleneck at data-driven enterprises.
What Makes It Different
Immuta enforces policy dynamically at query time using attribute-based access control woven into the warehouse or lake engine itself, instead of provisioning static, role-based permissions ahead of time.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A well-established, enterprise-validated access-governance specialist with a genuinely different architecture (dynamic, query-time policy) than static permissioning; funding momentum has cooled since its 2022 unicorn round, keeping it mid-tier.
Editorial Note: Claims vs. Verified Findings
The named customer list (NVIDIA, Merck, Novartis, GM, ADP, U.S. VA) appears on Immuta's own site and was not independently cross-verified with those customers; funding total and 2022 valuation are independently reported by multiple trackers.
Sources
Alternatives to Immuta
Cyera
AI-powered, agentless data security platform combining DSPM, DLP, and AI-activity monitoring, and one of the fastest-funded startups in…
Securiti.ai
Unified 'Data Command Center' platform combining data security, privacy, governance, and AI compliance across hybrid multicloud environments, now…
Varonis
Data-centric security platform that monitors file, email, and cloud activity to detect insider threats and ransomware before data…
Rubrik
Cloud data security company providing immutable backup, ransomware recovery, and cyber resilience across enterprise, cloud, and SaaS workloads.
Sentra
Cloud-native DSPM vendor evolving into a broader data security platform, focused on data hygiene and identity/access controls at…
Cyberhaven
AI-native data security platform that traces the full lifecycle of data to power DLP, insider-risk management, and shadow-AI…