Skip to content

Immuta

Data access governance platform that enforces fine-grained, attribute-based access policies dynamically across data warehouses and lakes like Snowflake and Databricks.

Visit Website ↗
63/100Incremental Innovator

Overview

Immuta is a data access governance platform that enforces fine-grained, attribute-based access control policies dynamically at query time against data warehouses and lakes such as Snowflake and Databricks, rather than provisioning static role-based permissions in advance. Founded in 2015 by Matthew Carroll and Steve Touw and headquartered in Boston, its platform spans policy enforcement (“Govern”), self-service access requests (“Provision”), compliance reporting (“Comply”), and newer agentic data-access features for AI systems.

Both Snowflake and Databricks are strategic investors and integration partners, and Immuta’s disclosed enterprise customer base includes ADP, GM, NVIDIA, Merck, Novartis, and the U.S. Department of Veterans Affairs. The company has raised roughly $267 million and reached a $1 billion valuation in its 2022 Series E round.

Its architectural differentiator — dynamic, query-time policy enforcement woven into the analytics engine itself — remains distinct from static permissioning, though funding momentum has visibly slowed since the 2022 unicorn round.

Innovation Matrix Assessment

Innovation Velocity 6/10

Steady additions including agentic data-access features for AI systems in late 2025.

Operational Value 7/10

Dynamic, attribute-based access control materially reduces the manual data-access request bottleneck at large data-driven enterprises.

Market Momentum 5/10

Valuation has remained static at $1B since 2022, with no larger round found since — funding momentum has plateaued.

Category Disruption 7/10

Attribute-based, query-time dynamic access control is a meaningfully different architecture from static, pre-provisioned role-based permissioning.

Real-World Efficacy 6/10

A verifiable, named enterprise customer roster (NVIDIA, Merck, Novartis, GM, U.S. VA) is a real, though vendor-published, adoption signal.

Enduring Relevance 7/10

Data access governance is increasingly critical as AI agents query enterprise data directly.

Why CISOs Should Care

Lets data teams grant access to sensitive datasets automatically under policy rather than having CISOs' teams manually review and approve every access request, a real operational bottleneck at data-driven enterprises.

What Makes It Different

Immuta enforces policy dynamically at query time using attribute-based access control woven into the warehouse or lake engine itself, instead of provisioning static, role-based permissions ahead of time.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

A well-established, enterprise-validated access-governance specialist with a genuinely different architecture (dynamic, query-time policy) than static permissioning; funding momentum has cooled since its 2022 unicorn round, keeping it mid-tier.

Editorial Note: Claims vs. Verified Findings

The named customer list (NVIDIA, Merck, Novartis, GM, ADP, U.S. VA) appears on Immuta's own site and was not independently cross-verified with those customers; funding total and 2022 valuation are independently reported by multiple trackers.

Sources