Survicate
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Warsaw-based Polish in-product survey and NPS platform on AWS-EU, ISO 27001 + SOC 2 + HIPAA-aligned.
Survicate offers EU hosting in Ireland, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Forms & surveys.
Assessment notes
Warsaw-based Polish survey platform (Survicate S.A., KRS 0001021023, founded 2013 by Kamil Rejent, Polish-investor cap table including PFR Ventures) with strong ISO 27001 + SOC 2 + PCI-DSS + HIPAA attestation, TLS 1.2 / AES-256, SSO and SAML, and a publicly readable DPA at /data-processing-agreement/, but customer data is hosted on Amazon Web Services in the EU region, which is a US-owned hyperscaler at rest, and the published provider list routes survey response text to OpenAI LLC (US) for AI summarisation and to Anthropic PBC (US) for an AI assistant, alongside a further ~15 US recipients; per the strict CLOUD Act stance this is material CLOUD Act exposure despite the EU-owned ownership and enterprise-grade certifications. The DPA itself names no sub-processors and points to a list that is only published inside the Privacy Policy PDF.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Survicate
Survicate is a Warsaw-based Polish in-product feedback and survey platform founded in 2013 by Kamil Rejent. The product covers in-product surveys, NPS / CSAT / CES tracking, website pop-ups, email and link surveys, and a Research Hub for centralised insights, and is used by more than 2,000 digital businesses including Spotify, Automattic, Vercel, and Amplitude. The company has raised approximately US$1M across several investors including Airbridge Equity Partners, ARIA Fund, Di Volio, Newberg Investments, and PFR Ventures (the Polish state-owned venture arm), keeping the cap table firmly Polish and EU-aligned.
The security posture is unusually rich for a vendor at this size: ISO/IEC 27001, SOC 2, PCI-DSS, HIPAA, and GDPR alignment are all attested on the public security page; TLS 1.2 in transit and AES-256 at rest; single sign-on with workspace-level or full-workspace SAML; role-based access controls; workspace isolation; 24/7 monitoring; continuous third-party penetration testing; and an explicit commitment that customer data never trains AI models. That last commitment is narrower than it reads: the sub-processor table inside the privacy policy names OpenAI LLC (USA) for AI-assisted search and text-response summarisation, explicitly covering the text respondents write in surveys, and Anthropic PBC (USA) for an AI text assistant, so response content is processed by US AI vendors even though it is not used to train them. The other red flag for a strict-CLOUD-Act EU buyer is the underlying infrastructure: customer survey data is hosted on Amazon Web Services in the EU region, a US-owned hyperscaler that, under our parent-jurisdiction stance (Schrems II / Microsoft Ireland v US), counts as material CLOUD Act exposure regardless of EU placement. This is material CLOUD Act exposure despite the otherwise enterprise-grade certifications and tooling.
Pricing is quoted in USD and positioned mid-market: Growth starts at US$114/month billed annually, with Pro at US$349/month and Enterprise at US$569/month above it; the sales-only entry tier is no longer shown on the pricing page. A 10-day free trial requires no credit card and allows up to 25 responses plus 100 Research Hub data points. Best fit: mid-market product teams in DACH, France, Poland, and the Nordics that want EU-incorporated ownership, full ISO 27001 + SOC 2 attestation, SSO, and audit logging, and can accept AWS-EU as the underlying hosting layer. Buyers who must avoid US-owned hyperscalers entirely should look at Formdesk (NL), or run LimeSurvey or Formbricks self-hosted on EU infrastructure, all listed in this category.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Survicate
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
SwitzerlandEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Germany · €63/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
Netherlands · €5.42/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
€63/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€5.42/mo |