Survey and feedback software built for compliance
Formbricks is SOC 2 Type II and ISO 27001 compliant, GDPR and CCPA compliant, and hosted in Germany. Or self-host it and keep every response inside your own perimeter.
10,000+ teams at the world's best companies trust Formbricks










































Certifications
Information security in every response
Formbricks is private by design. Independent audits verify our controls, so your security review goes faster.

GDPR Compliant
- Description
- Formbricks is fully compliant with the European General Data Protection Regulation, ensuring data protection by design and default.

CCPA Compliant
- Description
- Formbricks adheres to the California Consumer Privacy Act, providing robust data protection for California residents.
SOC 2 Type II
- Description
- We are SOC 2 Type II compliant, demonstrating our commitment to rigorous security controls and processes.
ISO 27001
- Description
- We are ISO 27001 compliant, further strengthening our information security management practices.
Security
Security controls that run every day
Compliance is the result of what we do every day: encryption, testing, monitoring, and secure development.
Encryption Everywhere
- Description
- All data is encrypted in transit with TLS 1.3 and at rest with AES-256, including backups.
Annual Penetration Tests
- Description
- Independent penetration tests run every year. Critical findings are fixed immediately, and the latest report is available on request.
Backups & Monitoring
- Description
- Daily encrypted backups, a tested disaster recovery plan, continuous monitoring, and DDoS protection.
Secure Development
- Description
- Every change is peer-reviewed and scanned by SonarQube and Dependabot. Code with critical issues can't be merged.
Access Control
Enterprise Auth, Built In
Keep control of who can see what. Formbricks connects to your identity provider and enforces the access controls enterprise and regulated teams expect.
Single Sign-On (SSO)
- Description
- Authenticate through your existing identity provider with SSO via OIDC (Okta) and SAML, no separate credentials to manage or offboard.
Workspace-Level Isolation
- Description
- Every team, department, or business unit gets its own workspace, so surveys and responses stay siloed to exactly the people who should see them.
MFA, RBAC & Audit Logging
- Description
- Enforce multi-factor authentication, role-based access controls, and full audit logging to meet your security and governance requirements.
Cloud in Germany or fully self-hosted
Formbricks Cloud stores all data in Germany (EU). If your requirements go further, for example HIPAA, air-gapped networks, or strict data residency, self-host Formbricks on your own infrastructure with Docker or Kubernetes. The same codebase, fully under your control.
Read self-hosting docs
Industries
Trusted in regulated industries
Teams that handle sensitive data use Formbricks to collect feedback without adding compliance risk.
- 1
Healthcare
- Description
- Collect patient and staff feedback while keeping sensitive health data on infrastructure you control.
- 2
Government & Public Sector
- Description
- Run citizen surveys with full data sovereignty, on premise or in an air-gapped environment.
- 3
Banking & Finance
- Description
- Meet strict audit and data residency requirements with SSO, RBAC, and audit logging.
Trust resources
Everything your security review needs
Reports, policies, and legal documents in one place.
Trust Center
Request the SOC 2 Type II report, ISO 27001 certificate, penetration test results, and security policies.
Security Practices
How we encrypt, host, test, and monitor Formbricks, explained for technical and non-technical readers.
Data Processing Agreement
Our standard DPA under Art. 28 GDPR, including the full list of subprocessors.
SOC 2 Type II
What our SOC 2 Type II audit covers and how to request the report.
GDPR FAQ
Data residency, controller and processor roles, and how to run GDPR-compliant surveys.
Service Level Agreement
Uptime commitments and support response times for Enterprise customers.
Request our compliance documents
Get our SOC 2 Type II report, ISO 27001 certificate, penetration test results, and security policies from the Trust Center. Questions? Email [email protected].
FAQ
