Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

ALTR applies access policies, masking and tokenization to connected databases. Snowflake enforcement and classification can take different processing paths, so check which data leaves the account. [2]

Capabilities

Discovery & classification, Access governance and Encryption & tokenization [1] [2]

Updated 6 sources

Store and control evidence

Read each documented action together with its limits.

Classify Snowflake data

ALTR offers hosted classification of Snowflake samples and an In-Warehouse mode that keeps sampled values in Snowflake and returns classification results. [5]

In-Warehouse mode does not evaluate Column Content, Google DLP or Amazon Comprehend conditions. A skipped condition can change a combined rule result. Validate the configured rules, sample size and warehouse cost. [5]

Mask sensitive columns in Snowflake

ALTR supports native Snowflake masking through tag connections. Its default masking uses an external function to request a policy decision from ALTR at query time. [6]

Native masking requires policy redeployment after rule changes and does not produce ALTR Database Activity Monitoring records. Direct column connections use an external-function protection type. Test the required query paths and audit evidence. [6]

Build an evaluation test from these claims

Data coverage

Read the scope beside each mark. Support for an environment does not establish every capability in every store.

Microsoft 365
Unconfirmed
AWS
Unconfirmed
Google Cloud
Unconfirmed
Snowflake and Databricks
Full

Snowflake and Databricks are documented integrations. Protection features differ by store. [1]

On-prem shares
Unconfirmed
SaaS apps
Unconfirmed

Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed

Deployment and cost

How it runs

Snowflake policy evaluation depends on the protection type. [2] [3] [4]

Enforcement
Native masking evaluates inside Snowflake. Other documented protection types call ALTR.
Classification
ALTR-hosted jobs sample data externally. In-Warehouse classification uses customer warehouse compute.
Snowflake setup
ALTR requires Snowflake Enterprise Edition or higher and ACCOUNTADMIN for connection setup. ALTR states that ACCOUNTADMIN is not needed after setup. Accounts with network policies must allow ALTR IP addresses.
Ongoing privileges
The documented service role includes account-level APPLY MASKING POLICY, APPLY ROW ACCESS POLICY, APPLY TAG and MANAGE GRANTS, plus source access. Review the full grant list before connecting production data.

Pricing and operating workload are not published in the reviewed sources.

Questions for the vendor

  1. Which protection types require an external call, and where will classification run?
  2. Demonstrate the audit evidence for native and external-function masking, including the activity each mode does not record.
  3. Review setup and retained service-user grants separately. Demonstrate credential rotation and policy removal on a test database.

Sources

  1. docs.altr.comReviewed
  2. docs.altr.comReviewed
  3. docs.altr.comReviewed
  4. docs.altr.comReviewed
  5. docs.altr.comReviewed
  6. docs.altr.comReviewed