Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Survicate

VERIFIED
Forms & surveys · Poland
Founded 2013 · survicate.com ↗

Warsaw-based Polish in-product survey and NPS platform on AWS-EU, ISO 27001 + SOC 2 + HIPAA-aligned.

Why this score?

Warsaw-based Polish survey platform (founded 2013 by Kamil Rejent, Polish-investor cap table including PFR Ventures) with strong ISO 27001 + SOC 2 + PCI-DSS + HIPAA attestation, TLS 1.2 / AES-256, SSO and SAML — but customer data is hosted on Amazon Web Services in the EU region, which is a US-owned hyperscaler at rest; per the strict CLOUD Act stance this caps the score at 3/5 despite the otherwise enterprise-grade posture.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Survicate

Survicate is a Warsaw-based Polish in-product feedback and survey platform founded in 2013 by Kamil Rejent. The product covers in-product surveys, NPS / CSAT / CES tracking, website pop-ups, email and link surveys, and a Research Hub for centralised insights, and is used by more than 2,000 digital businesses including Spotify, Automattic, Vercel, and Amplitude. The company has raised approximately US$1M across several investors including Airbridge Equity Partners, ARIA Fund, Di Volio, Newberg Investments, and PFR Ventures (the Polish state-owned venture arm) — keeping the cap table firmly Polish and EU-aligned. The security posture is unusually rich for a vendor at this size: ISO/IEC 27001, SOC 2, PCI-DSS, HIPAA, and GDPR alignment are all attested on the public security page; TLS 1.2 in transit and AES-256 at rest; single sign-on with workspace-level or full-workspace SAML; role-based access controls; workspace isolation; 24/7 monitoring; continuous third-party penetration testing; and an explicit commitment that customer data never trains AI models. The remaining red flag for a strict-CLOUD-Act EU buyer is the underlying infrastructure: customer survey data is hosted on Amazon Web Services in the EU region — a US-owned hyperscaler that, under our parent-jurisdiction stance (Schrems II / Microsoft Ireland v US), counts as material CLOUD Act exposure regardless of EU placement. The score therefore sits at 3/5 despite the otherwise enterprise-grade certifications and tooling. Pricing in EUR/USD is positioned mid-market: the Starter tier is sales-only; the Growth tier starts at US$114/month (~€105) with annual billing; Scale and Enterprise above. A 10-day free trial requires no credit card and allows up to 25 responses plus 100 Research Hub data points. Best fit: mid-market product teams in DACH, France, Poland, and the Nordics that want EU-incorporated ownership, full ISO 27001 + SOC 2 attestation, SSO, and audit logging — and can accept AWS-EU as the underlying hosting layer. Buyers who must avoid US-owned hyperscalers entirely should look at Tally (BE) for forms or use the on-premise Matomo for survey-style polling.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
SOC 2
ACTIVE
Informational · US framework
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €105/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    survicate.com/terms…
    Open ↗
ALTERNATIVES

Alternatives in this category