All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Immuta is the policy engine access decisions run through, its strength and its limit alike. It compiles plain-language attribute-based policy that enforces natively at query time inside Snowflake, Databricks, Postgres, and BigQuery, and Immuta's write-up of a GigaOm comparison puts it at 75 times fewer policy changes than role-based Apache Ranger. Leaving means re- homing the consolidated policies, a cost the cited record does not size. The limits are plain: it enforces inside platforms it does not own, its SOC 2 and ISO attestations are commercial table-stakes, and no proprietary cross-customer dataset appears in public sources, so a funded rival could rebuild its classification and policy work. The hardest part to copy is the enforcement depth, a head start, not a durable lead.
| Description | Immuta is a data security platform that discovers data, enforces access policies at the data layer, and monitors usage for AI and RAG workloads across platforms such as Snowflake and Databricks. | [f1] |
|---|---|---|
| Founded | 2015 | [f2] |
| HQ | Boston, United States | [f2] |
| Funding | $267M total | [f3] |
| Latest funding | Series E, $100M (June 2022) | [f2] |
| Deployment | SaaS | [f4] |
| Product | What it does |
|---|---|
| Immuta | Data security platform that discovers and classifies sensitive data, enforces attribute-based access policies and masking at the data layer for AI and RAG workloads, and monitors data usage for risk. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Immuta is a data security platform that discovers and classifies sensitive data, enforces attribute-based access policies and masking at the data layer for AI and RAG workloads, and monitors data usage for risk. It is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Immuta names data governance and security teams as the buyer and ties the pain to a 75 percent policy cut and a 400-page manual reduced to 56 rules, but that figure comes from the CEO quoted in SiliconANGLE, so the specific pain is vendor-asserted even though the category pain is independently real. [s10, s4, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Immuta documents a multi-module platform of Discover, Secure, and Detect with native enforcement inside Snowflake and Databricks, and VentureBeat independently reported the architecture while a GigaOm test sized its attribute-based model against Apache Ranger. That external validation places it at 4 rather than the category-leader level a 5 requires. [s3, s11, s12, s16] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Data access governance is an established budget line, and the enterprise move to RAG and AI agents gives the problem a present trigger Immuta now sells against with its agentic data access launch, with GigaOm framing data access control as its own category. That places it at 4, short of the named-category signal a 5 requires. [s8, s4, s12] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | TechCrunch confirms Carroll co-founded Immuta in 2015 after a U.S. Army intelligence career, and NightDragon's Dave DeWalt, formerly CEO of FireEye and McAfee, led the round and sits on the board, but Carroll has no prior in-domain exit or sustained publication record. [s9, s5, s10] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | TechCrunch independently names S&P Global, Mercedes-Benz Group, and the U.S. Army, SiliconANGLE adds Roche and IAG with revenue up more than 130 percent and a doubled customer base, and the agentic launch names JPMorgan Chase, Booking.com, and Cigna. Named references across independent and vendor sources match a 4, short of the independent revenue scale or exit a 5 requires. [s9, s10, s8] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | The 267 million dollars raised and one-billion-dollar valuation date to 2022, the reviewed record carries no later priced round, and Carroll declined to disclose recurring revenue to TechCrunch, so this reads as a stale raise past a normal cycle with no confirmed step-change. [s9, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Immuta anchors the data access governance and ABAC slot buyers place without coaching, and GigaOm framed data access control as its own category and named Immuta a leader within it. That fits an established category cleanly. [s12, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Native enforcement embedded in Snowflake and Databricks raises switching effort, but the access-control capability overlaps what those platforms increasingly bundle, with Snowflake shipping Horizon Catalog governance and Databricks Unity Catalog even as Snowflake invested in Immuta. With no cross-customer data flywheel visible. [s6, s14, s15] |
Immuta sells governed data access to the teams that must let people and systems use sensitive data without exposing it. The company frames the buyer as data governance and security teams reconciling fast access with compliance, and it ties the pain to a concrete cost rather than a generality. SiliconANGLE quotes CEO Matthew Carroll saying customers typically cut the number of data access policies they enforce by 75 percent, and that one customer reduced a 400-page policy manual to 56 rules.
Independent reporting grounds the category demand. TechCrunch reported Carroll positioning Immuta against the access-control complexity that GDPR and CCPA drive, cited third-party surveys on the barriers organizations face setting data policy, and named S&P Global and Mercedes-Benz Group among Immuta's customers, evidence that regulated enterprises were already organizing budget around governed data access.
The problem now extends to AI. Immuta positions retrieval-augmented generation and AI agents as a fast-growing class of data consumer and sells policy enforcement plus usage monitoring as the way to scale those workloads without exposing unauthorized data. That reframes a long-standing access problem around the workload pulling hardest on enterprise data today. [s10, s9, s4]
The Immuta platform runs as a unified data access layer rather than a single point feature. The product overview pairs a data marketplace, where teams request and provision access against data-use agreements, with a data access governance module that authors policy in plain language and enforces it across platforms. VentureBeat independently reported the architecture as three modules, Discover, Secure, and Detect, spanning sensitive-data discovery, access control, and activity monitoring.
Attribute-based access control is the technical core. Immuta lets a governor consolidate hundreds of role-based policies into one dynamic ABAC policy, and a GigaOm head-to-head test found its model needed 75 times fewer policy changes than Apache Ranger's RBAC to meet the same objectives. That benchmark is the external validation point that lifts capability above marketing claims, though Immuta commissioned and promotes it.
Enforcement runs natively inside the data platforms. Immuta's chief product officer describes native integrations with Snowflake, Databricks, and Postgres that control access without proxying, which both deepens the technical claim and binds the product to the platforms it sits on. [s11, s3, s12, s16]
Immuta competes in data access governance against both independent data-security platforms and the data clouds moving to bundle the capability. TechCrunch placed BigID and OneTrust among the rivals in this space. The cluster pattern is consolidation, with the data clouds extending native governance into the access-control layer Immuta sells.
Immuta's stated differentiator is cross-platform policy on one engine. The company positions write-once, enforce-everywhere ABAC across Snowflake, Databricks, and Postgres as a tighter alternative to per-platform role-based controls, a claim the GigaOm comparison against Apache Ranger supports for one rival approach.
The structural question is whether the platforms underneath keep ceding the layer. Snowflake invested in Immuta, Snowflake ships native governance through Horizon Catalog and Databricks through Unity Catalog, and Immuta enforces inside both, so the deepest source of Immuta's stickiness is also the relationship that can commoditize it. [s12, s14, s15, s6, s9]
Immuta shows named customer proof across both independent and vendor sources. TechCrunch named S&P Global, Mercedes-Benz Group, and the U.S. Army, SiliconANGLE added Roche and International Consolidated Airlines Group, and the agentic launch blog names JPMorgan Chase, Booking.com, Cigna, and General Motors. That breadth of named references sits at the upper end of what this cluster typically shows.
Independent reporting also carries a growth signal. SiliconANGLE reported Immuta doubled its customer base and grew revenue by more than 130 percent in 2021, and distribution runs through the data platforms, with native integrations on Snowflake and Databricks and Snowflake Ventures investing in the Series E round.
What the public record lacks is recent independent scale confirmation. Carroll declined to disclose recurring revenue or customer count to TechCrunch, and no analyst-audited growth ranking or acquisition price has corroborated momentum since 2022, so the traction read rests on named logos and a dated growth figure rather than current verified scale. [s9, s10, s8]
Immuta's leadership pairs a founder-CEO with a product executive drawn from developer tooling. TechCrunch reports that Matthew Carroll co-founded Immuta in 2015 with Steven Touw and Mike Schiller, after a career that began as a U.S. Army intelligence officer, and the about page lists him on both the leadership team and the board. Chief Product Officer Mo Plassnig is the public voice on the native-enforcement architecture.
The investor signal reinforces the team's standing. The 2022 round was led by NightDragon, whose founder Dave DeWalt was previously CEO of FireEye and McAfee, with Snowflake Ventures joining and existing backers Dell Technologies Capital and Intel Capital participating, validation from firms that fund and operate security and infrastructure companies.
The credibility comes from the build itself rather than a prior exit. Carroll's record is the decade he has spent scaling Immuta into a unicorn, not an earlier company sold into a larger platform, and the public record reviewed did not surface a sustained research or publication program of the kind that lifts the strongest teams in the category. [s9, s5, s10]
Immuta sells into regulated enterprises and government, which sets a high bar for assurance evidence. The homepage logo wall and independent reporting name buyers including JPMorgan Chase, Swedbank, Roche, and the U.S. Army, whose procurement requires security attestations and data-handling terms before the platform touches sensitive data.
The trust portal documents an inspectable posture. Immuta lists an AICPA SOC 2 Type 2 attestation, ISO 27001 and ISO 27701 certifications, and A-Lign PCI DSS, and states that its security measures are audited annually by an independent external party, with the SOC 2 report available on request through an account manager. These are enterprise-grade procurement assurance rather than a moat.
The product's position raises the assurance stakes regardless of the badges. Because Immuta inspects an organization's data, classifies sensitive fields, and enforces access inside the data platforms, a review will examine how Immuta handles the metadata and audit records it generates, terms that sit beyond what the published attestations cover. [s7, s1, s8, s10]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| BigID | competes with | Data security and governance platform spanning discovery, classification, and access, contesting the same enterprise data-security buyer. | |
| Securiti | competes with | Data command center pairing discovery, DSPM, and AI governance, acquired by Veeam, overlapping Immuta's data-security positioning. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cyera | competes with | Data security platform unifying discovery, DLP, and access governance for AI, sold into the same enterprise data team. | |
| Sentra | competes with | Cloud-native data security platform spanning discovery and posture, contesting the same data-security budget line. | |
| Snowflake | adjacent | Data cloud, Immuta investor, and native-enforcement host that ships its own Horizon Catalog governance and could absorb the access-control layer. | |
| Databricks | adjacent | Data and AI platform and native-enforcement host with its own Unity Catalog governance overlapping Immuta's core access-control layer. | N/ADatabricks is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Immuta.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Immuta is the policy engine access decisions run through, its strength and its limit alike. It compiles plain-language attribute-based policy that enforces natively at query time inside Snowflake, Databricks, Postgres, and BigQuery, and Immuta's write-up of a GigaOm comparison puts it at 75 times fewer policy changes than role-based Apache Ranger. Leaving means re-homing the consolidated policies, a cost the cited record does not size. The limits are plain: it enforces inside platforms it does not own, its SOC 2 and ISO attestations are commercial table-stakes, and no proprietary cross-customer dataset appears in public sources, so a funded rival could rebuild its classification and policy work. The hardest part to copy is the enforcement depth, a head start, not a durable lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy a software platform for discovery, classification, policy enforcement, and monitoring and configure and run it themselves. The automated classification and attribute-based policy are software output, with no managed service or accountability layer in the public offer. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Immuta consolidates hundreds of role-based policies into one attribute-based engine that enforces natively inside Snowflake, Databricks, and Postgres, so leaving means re-implementing those policies on another engine or per platform. The cited record documents the mechanism but does not size the exit, so the documented case is meaningful friction, not a genuinely expensive migration. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Immuta holds commercial attestations, SOC 2 Type 2, ISO 27001 and ISO 27701, and PCI DSS, via an inspectable trust portal, but these are table-stakes assurance that ease procurement without blocking a substitute, and the cited record identifies no authorization or mandate that would make this product class required. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Compiling plain-language attribute-based policy and masking that enforce natively at query time across Snowflake, Databricks, Postgres, and BigQuery, with discovery, classification, and real-time monitoring at enterprise scale, is distributed-data and policy-engine engineering that takes years of specialized work. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Customers span financial services, pharma, and federal government, including JPMorgan Chase and Roche on the homepage and agentic-launch rosters and the U.S. Army among the names TechCrunch cited at the 2022 round. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Immuta is the policy layer other access decisions run through, but it enforces inside data platforms it does not own and the consoles that consume its governance belong to other vendors, so it is not yet infrastructure others depend on to function. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The classification models, policy library, and attribute-based engine are accumulated intellectual property a funded rival could rebuild, the patented discovery method is technique rather than a dataset, the GigaOm benchmark is vendor-commissioned, and no named non-public cross-customer dataset appears in fetched sources to compound the advantage with usage. |
Immuta sells to the data governance and security teams inside large regulated enterprises and government agencies. Immuta's customers page names General Motors, Swedbank, Thomson Reuters, Roche, IAG, and JPMorgan Chase, and its agentic-access launch adds Booking.com and Cigna, the buyers whose data exposure carries regulatory and contractual cost. TechCrunch independently named S&P Global, Mercedes-Benz Group, and the U.S. Army when it covered the 2022 round.
The buyer is the team that must reconcile fast data access with compliance. Immuta frames the persona as governors and stewards who define access policy once and enforce it across every platform, and it ties the pain to a concrete cost. SiliconANGLE quotes the chief executive on customers cutting enforced policies by 75 percent, with one reducing a 400-page policy manual to 56 rules.
The segment now extends to a new consumer of enterprise data. Immuta positions retrieval-augmented generation and AI agents as a fast-growing class of data consumer and sells policy enforcement plus usage monitoring as the way to scale those workloads without exposing unauthorized data.
Attribute-based access control is the technical core. Immuta lets a governor consolidate hundreds of role-based policies into one dynamic attribute-based policy authored in plain language, and Immuta's own page describing a GigaOm head-to-head comparison reports that model needing 75 times fewer policy changes than Apache Ranger's role-based approach, a vendor-hosted account of the result rather than the report itself. The engine discovers, tags, and classifies sensitive data, then compiles policy and masking that the monitoring layer reports against.
The claimed advantage is where enforcement happens. The chief executive describes writing code natively into each compute layer so policies run inside Snowflake, Databricks, and Postgres rather than through a proxy. VentureBeat independently reported the same native-enforcement design and a patented sensitive-data discovery approach that classifies data without it leaving the database.
What holds up is engineering depth rather than a data moat. The classification models and the policy library are accumulated intellectual property a funded rival could rebuild from the same public techniques, and the GigaOm result is a comparison Immuta commissioned and promotes. No named non-public cross-customer dataset appears in fetched sources to compound the advantage with usage.
Immuta runs an enterprise sales motion distributed through the data platforms its customers already buy. Native integrations with Snowflake and Databricks put it inside the ecosystems its buyers already run, and Snowflake Ventures invested in the 2022 Series E, coupling go-to-market to the Snowflake relationship. The reviewed pages document the integrations and the investment but no marketplace listing or partner-led sales channel.
Named customer proof spans independent and vendor sources. TechCrunch named S&P Global, Mercedes-Benz Group, and the U.S. Army, SiliconANGLE added Roche and IAG, and the agentic launch names JPMorgan Chase, Booking.com, Cigna, and General Motors. SiliconANGLE also reported Immuta doubled its customer base and grew revenue by more than 130 percent in 2021.
What the public record withholds is recent independent scale confirmation. Carroll declined to disclose recurring revenue to TechCrunch, and no analyst-audited growth ranking or acquisition price has corroborated momentum since 2022, so the traction read rests on named logos and a dated growth figure rather than current verified scale.
Public sources reviewed do not disclose Immuta's price or contract unit. Unpublished pricing alongside a roster of large enterprises and the U.S. Army points to negotiated enterprise deals, an inference rather than a stated fact. The absence withholds the budget-anchoring signal some data-security peers publish.
The platform's framing suggests the value meter is policy reach rather than seats or scans. Immuta sells write-once, enforce-everywhere policy across Snowflake, Databricks, and Postgres, so the natural unit is the number of platforms and the volume of governed data under one policy engine, though the public record does not state which Immuta actually charges by.
The economic pitch is the cost the policy model removes. The GigaOm comparison frames the 75-times policy reduction as raising cloud return on investment, so Immuta sells against the labor of writing and maintaining per-platform role-based policies rather than against a rival's list price. Confirming the contract unit would require a sales conversation.
Immuta delivers as software the customer configures and operates, enforcing inside the data platform rather than proxying traffic through its own infrastructure. The chief executive describes embedding code natively into each compute layer so the governance team authors policy and enforcement happens on the data without rerouting queries. Native connectors cover Snowflake, Databricks, Postgres, and BigQuery.
The platform pairs three operating pieces. A data marketplace lets teams request and provision access against data-use agreements, a data access governance module authors and enforces policy across platforms, and a monitoring layer reports query histories, sensitive-data indicators, and classification changes, closing the loop from policy to audit.
The public trust page lists the controls and attestations openly, while the SOC 2 report itself is obtained through an account manager. The portal documents an annual external audit, and the customer obtains the underlying SOC 2 report through an account manager, so a buyer evaluates data-handling and retention terms in a formal review rather than from a published service-level commitment.
Immuta maintains a real, inspectable trust posture for a product that classifies and governs sensitive enterprise data. The trust portal lists an AICPA SOC 2 Type 2 attestation, ISO 27001 and ISO 27701 certifications, and A-Lign PCI DSS, and states a role as both data processor and data controller under the GDPR.
The attestations are enterprise-grade procurement assurance rather than a moat. Security measures are audited annually by an external party, and the SOC 2 report is available on request through an account manager rather than open download. That breadth eases the security review that government and regulated buyers run before the platform touches sensitive data.
The product's position raises the assurance stakes regardless of the badges. Because Immuta inspects an organization's data, classifies sensitive fields, and enforces access inside the data platforms, a review will examine how Immuta handles the metadata and audit records it generates, terms that sit beyond what the published attestations cover.
Immuta positions itself as the policy and governance layer that sits inside the modern data stack rather than a console that replaces it. The platform operates natively inside cloud data platforms, and its connectors span Snowflake, Databricks, Postgres, and BigQuery, so the platform claim rests on being the one place a governor authors policy that every connected platform then enforces.
That ownership is a sharper position than tools that sit beside the data, and it is also the dependency. Immuta enforces inside platforms it does not own, so its reach is bounded by the connectors it builds and the cooperation of the platforms underneath. The native depth that makes policy run at query time is the same depth that ties Immuta's reach to those vendors' roadmaps.
The exposure is that the hosts ship competing governance. Snowflake invested in Immuta yet ships native governance through Horizon Catalog, and Databricks ships Unity Catalog, so the platforms Immuta embeds in can extend their own access controls and absorb the layer Immuta sells at its deepest point of integration.
Immuta's credibility comes from a founder who has run the company for a decade. TechCrunch reports that Matthew Carroll co-founded Immuta in 2015 with Steven Touw and Mike Schiller, after a career that began as a U.S. Army intelligence officer, and built it into a data-access company that reached a one-billion-dollar valuation in 2022. The about page lists him on both the leadership team and the board.
The investor bench reinforces the founder signal. The 2022 Series E was led by NightDragon, whose founder Dave DeWalt was previously CEO of FireEye and McAfee, with Snowflake Ventures joining and existing backers Dell Technologies Capital and Intel Capital participating, validation from firms that fund and operate security and infrastructure companies.
The credibility comes from the sustained build rather than a prior exit. Carroll's record is the decade he has spent scaling Immuta into a unicorn, not an earlier company sold into a larger platform, and the reviewed sources do not establish a sustained research or publication program of the kind that lifts the strongest teams in the category.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Immuta: Data Security for AI | official | 2026-07-09 |
| f2 | Immuta Raises $100 Million in Series E Funding | press | 2026-06-14 |
| f3 | TechCrunch: Immuta lands $100M Series E ($267M total funding, $1B valuation) | press | 2026-06-28 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Immuta homepage (The Data Provisioning Company, customer logo wall) “As humans and AI agents consume data at ever-increasing speed and scale, Immuta provisions it in real time, with full control, across your entire data ecosystem. Logo wall (logos): Booking.com, General Motors, Swedbank, Thomson Reuters, Roche, IAG, JPMorgan Chase.” | official | 2026-06-28 |
| s2 | Immuta platform overview (data marketplace and data access governance) “Power your data marketplace initiatives and data access governance projects with a unified platform that brings all your data assets and people together.” | official | 2026-06-28 |
| s3 | Immuta Data Access Governance (govern once, enforce everywhere, ABAC) “Immuta empowers data governors and stewards to define global access policies across any platform, without code or tickets.” | official | 2026-06-28 |
| s4 | Immuta Data Security for AI (RAG policy enforcement and monitoring) “Immuta allows you to automatically enforce policy and monitor usage, so you can scale the production of RAG-based generative AI applications while managing risk and maintaining compliance.” | official | 2026-06-28 |
| s5 | Immuta company and leadership (CEO and founder Matthew Carroll, board) “Our mission is to enable safe, instant access to data for humans and AI. Matthew Carroll, Chief Executive Officer, Founder.” | official | 2026-06-28 |
| s6 | Immuta customer resources (native enforcement without proxying) “Through Immuta native integrations with data platforms like Snowflake, Databricks, and Postgres, you're able to control access without proxying” | official | 2026-06-28 |
| s7 | Immuta Trust page (SOC 2 Type 2, ISO 27001, ISO 27701, PCI DSS, annual audit) “AICPA SOC 2 Type 2. ISO 27001, ISO 27701. A-Lign PCI DSS. Our security measures are audited annually by an independent and external party.” | official | 2026-06-28 |
| s8 | Immuta Introducing Agentic Data Access (Matt Carroll, 2026) “Immuta provisions temporary access directly in the underlying data platform, such as Snowflake, Databricks, or BigQuery, granting only the access required for that task. Immuta does this with J.P. Morgan, Booking.com, Cigna, Roche, General Motors, and more.” | official | 2026-06-28 |
| s9 | TechCrunch: Immuta lands $100M Series E (Kyle Wiggers, June 8, 2022) “it closed a $100 million Series E round at a $1 billion valuation, bringing the company's total funding to $267 million.” | press | 2026-06-28 |
| s10 | SiliconANGLE: Immuta data-level security, customers, and growth (Paul Gillin, June 2022) “Immuta counts Roche Holding AG, Mercedes-Benz Group AG, International Consolidated Airlines Group SA and the U.S. Army among its customers. Carroll said the company doubled its customer base last year and grew revenue by more than 130%.” | press | 2026-06-28 |
| s11 | VentureBeat: Immuta Discover, Secure, Detect modules and DSPM (Victor Dey, June 2023) “The company said it distinguishes itself from competitors by offering a comprehensive platform instead of a mere point solution. This platform comprises three main product modules: Discover, Secure and Detect.” | press | 2026-06-28 |
| s12 | GigaOm case study on Immuta automated data access control (summarizes Radar leader and fast-mover positioning) “GigaOm named Immuta a leader and “fast mover” in data governance, highlighting its automated data access control.” | research | 2026-06-28 |
| s13 | SEC EDGAR record for Immuta, Inc. (CIK 0001645903, Delaware, Form D 2015 and 2016) “"name":"Immuta, Inc."” | regulatory | 2026-06-28 |
| s14 | Snowflake Horizon Catalog (native governance, masking, and access controls) “Convert intent into active Horizon Catalog policies for masking, access controls, data quality and more.” | official | 2026-06-28 |
| s15 | Databricks Unity Catalog (unified governance for data, apps, and AI agents) “Unified governance for data, apps and AI agents” | official | 2026-06-28 |
| s16 | Immuta resource page on the GigaOm Immuta ABAC versus Apache Ranger RBAC report “In a head-to-head comparison by GigaOm, Immuta's attribute-based access control (ABAC) required 75X fewer policy changes than Ranger's role-based access control (RBAC) to accomplish the same security objectives.” | official | 2026-06-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Immuta homepage (customer logo wall) “As humans and AI agents consume data at ever-increasing speed and scale, Immuta provisions it in real time, with full control, across your entire data ecosystem. Logo wall (logos): Booking.com, General Motors, Swedbank, Thomson Reuters, Roche, IAG, JPMorgan Chase.” | official | 2026-06-28 |
| s2 | Immuta platform overview (data marketplace and data access governance) “Power your data marketplace initiatives and data access governance projects with a unified platform that brings all your data assets and people together.” | official | 2026-06-28 |
| s3 | Immuta Data Access Governance (govern once, enforce everywhere) “Immuta empowers data governors and stewards to define global access policies across any platform, without code or tickets.” | official | 2026-06-28 |
| s4 | Immuta Data Security for AI (RAG policy enforcement and monitoring) “Immuta allows you to automatically enforce policy and monitor usage, so you can scale the production of RAG-based generative AI applications while managing risk and maintaining compliance.” | official | 2026-06-28 |
| s5 | Immuta company and leadership (CEO and founder Matthew Carroll, board) “Our mission is to enable safe, instant access to data for humans and AI. Matthew Carroll, Chief Executive Officer, Founder.” | official | 2026-06-28 |
| s6 | Immuta customer resources (native enforcement without proxying) “Through Immuta native integrations with data platforms like Snowflake, Databricks, and Postgres, you're able to control access without proxying” | official | 2026-06-28 |
| s7 | Immuta Trust page (SOC 2 Type 2, ISO 27001, ISO 27701, PCI DSS, annual audit) “AICPA SOC 2 Type 2. ISO 27001, ISO 27701. A-Lign PCI DSS. Our security measures are audited annually by an independent and external party.” | official | 2026-06-28 |
| s8 | Immuta Introducing Agentic Data Access (Matt Carroll, 2026) “Immuta provisions temporary access directly in the underlying data platform, such as Snowflake, Databricks, or BigQuery, granting only the access required for that task. Immuta does this with J.P. Morgan, Booking.com, Cigna, Roche, General Motors, and more.” | official | 2026-06-28 |
| s9 | TechCrunch: Immuta 100M Series E, founders, and customers (Kyle Wiggers, June 2022) “Immuta was co-founded in 2015 by Steven Touw, Mike Schiller and Carroll, who began his career as a U.S. Army intelligence officer in Baghdad.” | press | 2026-06-28 |
| s10 | SiliconANGLE: Immuta native compute-layer enforcement and policy reduction (Paul Gillin, June 2022) “We wrote code natively to embed into each compute layer so your governance team can author policies and enforce them natively on the data but the customers never see it.” | press | 2026-06-28 |
| s11 | VentureBeat: Immuta Discover, Secure, Detect modules, DSPM, and patented SDD (Victor Dey, June 2023) “Our patented approach to sensitive data discovery allows data to be classified for security purposes without leaving the database, ultimately creating more effective data policies to meet stringent data localization regulations.” | press | 2026-06-28 |
| s12 | GigaOm case study on Immuta automated data access control (summarizes Radar leader and fast-mover positioning) “GigaOm named Immuta a leader and “fast mover” in data governance, highlighting its automated data access control.” | research | 2026-06-28 |
| s13 | SEC EDGAR record for Immuta, Inc. (CIK 0001645903, Delaware, Form D 2015 and 2016) “"name":"Immuta, Inc."” | regulatory | 2026-06-28 |
| s14 | Snowflake Horizon Catalog (native governance, masking, access controls) “Convert intent into active Horizon Catalog policies for masking, access controls, data quality and more.” | official | 2026-06-28 |
| s15 | Databricks Unity Catalog (unified governance for data, apps, and AI agents) “Unified governance for data, apps and AI agents” | official | 2026-06-28 |
| s16 | Immuta resource page on the GigaOm Immuta ABAC versus Apache Ranger RBAC report “In a head-to-head comparison by GigaOm, Immuta's attribute-based access control (ABAC) required 75X fewer policy changes than Ranger's role-based access control (RBAC) to accomplish the same security objectives.” | official | 2026-06-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.