Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Formbricks

VERIFIED
Forms & surveys · Germany
Founded 2022 · formbricks.com ↗

German open-source experience-management platform (Formbricks GmbH, Kiel) for link, website and in-product surveys; AGPLv3, self-hostable.

Why this score?

German GmbH (Kiel) shipping an AGPLv3 open-source survey/forms platform with a publicly-downloadable DPA (sub-processors in Annex IV) and SOC 2 Type II, but the managed Formbricks Cloud runs on AWS in Germany for database + email at rest, with Stripe/Google Cloud/Sentry/PostHog/Chatwoot alongside it and US VC (OSS Capital) on the cap table — material CLOUD Act exposure caps the managed-cloud score at 3/5; self-hosting the AGPLv3 build on EU infrastructure delivers 5/5 with no exposure.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Formbricks

Formbricks is a German open-source experience-management platform operated by Formbricks GmbH (Kuhnkestr. 6, 24118 Kiel), founded in 2022 by Johannes Dancker and Matti Nannt. It positions itself as the open-source Qualtrics alternative and covers link surveys, website and in-product (in-app) surveys, and email-embedded feedback forms, with event-triggered targeting, user segmentation, conditional logic, multi-language surveys, file uploads, webhooks, and SDKs. The full core application is licensed under AGPLv3 on GitHub and is fully self-hostable. For an EU-sovereignty audit the ownership tier is eu_hq_us_funded: Formbricks is a German GmbH but is backed by OSS Capital (a US open-source-focused VC), Flex Capital, and the GitHub Accelerator, with angels including Tom Preston-Werner (GitHub) and Peer Richelsen (Cal.com). The managed Formbricks Cloud (app.formbricks.com) is hosted in Germany on Amazon Web Services, which handles the database and email at rest. The DPA is publicly downloadable without signup and lists its Annex IV sub-processors: AWS (DE region), PostHog (DE region), Stripe (US), Sentry (DE region), Brevo (FR), Google Cloud (EU), and Chatwoot (US). The company holds SOC 2 Type II and states ISO 27001 is in progress. Per the directory's strict CLOUD Act stance — provider parent jurisdiction matters more than data-centre region — AWS at rest plus the US sub-processors plus US-VC ownership make this material exposure, capping the managed-cloud score at 3/5. Self-hosting the AGPLv3 build on EU-incorporated infrastructure (Hetzner, OVHcloud, Scaleway) delivers an effective 5/5 with no exposure. Pricing: a free Hobby tier (250 responses/month, 1 workspace); Pro at US$89/month (~€82); Scale at US$390/month — note "USA hosting" is an opt-in add-on, so the default cloud is Germany. Self-hosting is free under AGPLv3. Best fit: privacy-conscious product teams and EU developers replacing Qualtrics or Qualaroo for in-product surveys, or wanting a GDPR-compliant, self-hostable feedback layer — the self-host path is the procurement-grade option.
SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications

SOC 2
ACTIVE
Informational · US framework
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
from €82/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

  • Data Processing Addendum (DPA)
    formbricks.com/dpa…
    Open ↗
  • Sub-processors list
    formbricks.com/dpa…
    Open ↗
  • Terms of Service
    formbricks.com/terms…
    Open ↗
ALTERNATIVES

Alternatives in this category