Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

Immuta vs Thales CipherTrust

Check differences in scope, deployment and cost. Use the evaluation questions to resolve what the sources leave open.

Read each action with its limits. General capability and environment marks do not establish a specific workflow. Unconfirmed means support was not established in our research.

Capabilities, coverage, deployment, pricing and evaluation questions for Immuta and Thales CipherTrust
CompareImmutaUpdated Thales CipherTrustUpdated
ApproachImmuta manages access policies in supported analytics platforms. Enforcement differs by integration, so a Snowflake masking policy should not be assumed to work identically in BigQuery or S3. [1]CipherTrust combines data discovery with separately configured encryption and key-management components. Cloud key support does not establish content scanning or access governance for the same service. [1] [2]
Classify Snowflake data

Immuta runs regex and dictionary identification queries in Snowflake, returning column names and matching identifiers without raw values. Column-name identification uses metadata held in Immuta. [5]

Content identification generally covers text columns, with documented date and time exceptions. Competitive identifiers require a 90% sample match and queries time out after 15 minutes by default. Test sparse sensitive values and complex views. [5]

This workflow has not been established in our research.

Mask sensitive columns in Snowflake

Immuta administers native Snowflake column-masking and row-access policies on registered objects. Users query Snowflake directly and receive policy-controlled results. [4]

The integration requires Snowflake Enterprise. User mapping and policy sync must be configured. Listed excepted users and roles bypass Immuta policies. Include those identities and views in the acceptance test. [4]

This workflow has not been established in our research.

Discovery & classificationDocumented [1]Documented [1]
Access governanceDocumented [1]Unconfirmed
Data loss preventionUnconfirmedUnconfirmed
Detection & responseUnconfirmedUnconfirmed
Encryption & tokenizationUnconfirmedDocumented [2]
Microsoft 365? Unconfirmed◐ Partial

Data Discovery and Classification lists Exchange Online and SharePoint Online. Confirm OneDrive and permissions-analysis scope. [1]

AWS◐ Partial

Redshift uses policy-enforced views. S3 supports subscription policies but the comparison table does not list data-policy enforcement. [1]

◐ Partial

S3 discovery and AWS key-management integrations are documented. These are different components. [1] [2]

Google Cloud◐ Partial

BigQuery uses policy-enforced views. The integration matrix limits sensitive-data discovery to column-name identification. [1]

◐ Partial

Cloud Key Manager supports GCP key-management options. Content discovery across GCP stores is unconfirmed in these sources. [2]

Snowflake / Databricks● Full

Snowflake and Databricks integrations support native access policies. Verify feature parity for your integration mode. [1]

? Unconfirmed
On-prem shares? Unconfirmed● Full

Discovery supports Windows/CIFS/SMB and Unix/NFS network storage. [1]

SaaS apps? Unconfirmed◐ Partial

Discovery includes Google Workspace. Key-management integrations include Salesforce, with different controls. [1] [2]

Deployment and data handling

In Snowflake, Immuta administers native row-access and column-masking policies on tables. [2] [3] [4]

Query path
Users query Snowflake directly while those policies are enforced.
Connection setup
The integration requires Snowflake Enterprise. An Immuta application administrator registers the connection. The Snowflake setup user needs CREATE DATABASE, CREATE ROLE and MANAGE GRANTS with grant option.
Retained system access
The generated script grants the system account CREATE ROLE, MANAGE GRANTS, APPLY MASKING POLICY and APPLY ROW ACCESS POLICY with grant option. Scope source USAGE and REFERENCES to the registered objects.
Content access
SELECT is required for identification or specialized masking that uses fingerprinting. Iceberg and external tables need grants for their own object types.

Cloud Key Manager is a licensed component of the CipherTrust Manager appliance. [2]

Scope
Cloud key management and sensitive-data discovery use separate configurations.
Pricing

Pricing was not established in the reviewed sources.

Pricing was not established in the reviewed sources.

Test in the evaluation
  1. Show masking and row filtering through every query path used by your applications.
  2. What privileges remain after initial integration and how are policies removed safely?
  3. Measure warehouse compute and query latency with your actual policy set.
  1. Map each store to discovery, encryption and key-management components and quote them separately.
  2. Test application behavior, recovery and key rotation before enabling encryption in production.
  3. Which components and keys can remain entirely under your administrative control?

Full refers to the documented scope above. It does not establish every control in every store. How coverage is assessed. Turn a coverage claim into an evaluation test.

Change platforms