ALTR
Compare with…ALTR applies access policies, masking and tokenization to connected databases. Snowflake enforcement and classification can take different processing paths, so check which data leaves the account. [2]
Updated 6 sources
Store and control evidence
Read each documented action together with its limits.
Classify Snowflake data
ALTR offers hosted classification of Snowflake samples and an In-Warehouse mode that keeps sampled values in Snowflake and returns classification results. [5]
In-Warehouse mode does not evaluate Column Content, Google DLP or Amazon Comprehend conditions. A skipped condition can change a combined rule result. Validate the configured rules, sample size and warehouse cost. [5]
Mask sensitive columns in Snowflake
ALTR supports native Snowflake masking through tag connections. Its default masking uses an external function to request a policy decision from ALTR at query time. [6]
Native masking requires policy redeployment after rule changes and does not produce ALTR Database Activity Monitoring records. Direct column connections use an external-function protection type. Test the required query paths and audit evidence. [6]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Unconfirmed
- Google Cloud
- Unconfirmed
- Snowflake and Databricks
- Full
Snowflake and Databricks are documented integrations. Protection features differ by store. [1]
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
Snowflake policy evaluation depends on the protection type. [2] [3] [4]
- Enforcement
- Native masking evaluates inside Snowflake. Other documented protection types call ALTR.
- Classification
- ALTR-hosted jobs sample data externally. In-Warehouse classification uses customer warehouse compute.
- Snowflake setup
- ALTR requires Snowflake Enterprise Edition or higher and ACCOUNTADMIN for connection setup. ALTR states that ACCOUNTADMIN is not needed after setup. Accounts with network policies must allow ALTR IP addresses.
- Ongoing privileges
- The documented service role includes account-level APPLY MASKING POLICY, APPLY ROW ACCESS POLICY, APPLY TAG and MANAGE GRANTS, plus source access. Review the full grant list before connecting production data.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- Which protection types require an external call, and where will classification run?
- Demonstrate the audit evidence for native and external-function masking, including the activity each mode does not record.
- Review setup and retained service-user grants separately. Demonstrate credential rotation and policy removal on a test database.