Managed LimeSurvey hosting

Workflow and dataOn-prem or sovereign site

Surveys and research questionnaires with personal invitations and anonymised responses, run in Switzerland, the EU or your own datacentre so the answers stay in your jurisdiction. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about LimeSurvey

Licence
GPL-2.0-or-later
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.limesurvey.org

Running LimeSurvey in production: what it takes

  1. Pin and deploy on InnoDB

    A LimeSurvey release we have run, on PHP-FPM, with MariaDB on InnoDB rather than the installer's MyISAM default, so a backup taken while responses arrive is consistent.

  2. Publish the surveys, keep the admin private

    Survey pages go out through the Pilae gate on port 443 so respondents can reach them. The administration answers only on your private network, behind Keycloak or your own identity provider.

  3. Send invitations through your relay

    Invitations and reminders leave through your SMTP relay under your domain, in batches the relay accepts, with bounces going to a mailbox somebody reads.

  4. Back up the data, the files and the keys

    The database, the upload directory and the key file go offsite daily, encrypted. Once a month we restore all three into a scratch instance and open a response with a file attached.

  5. Upgrade around your fieldwork

    Releases arrive often and can change the database schema. The Pilae Agent tests each upgrade on a copy with your surveys and theme, waits for your approval and applies it in your window. Major versions are scheduled between fieldwork periods.

What LimeSurvey is, and who runs it

Self-hosted LimeSurvey for research and public-sector surveys

LimeSurvey is an open-source survey platform. It handles branching logic, quotas, many languages in one survey, personal invitation tokens or a public link, and exports to SPSS, R and Stata. It is used in universities, research projects and public administrations, and it covers most of what those teams use SurveyMonkey or Qualtrics for.

We run it where your data-protection assessment says the answers may be kept: on your own hardware, or on a dedicated machine in Zurich, in one of the five EU Pilae Cloud regions or in one of six further afield. For a research project, an ethics application asks where the answers are stored, and the answer is a place you can name.

LimeSurvey in production: sign-on, invitations and encryption keys

Respondents have to reach the survey, and staff have to reach the administration. We publish survey pages through the Pilae gate on port 443 and keep the administration on your private network, where an OpenID Connect proxy signs staff in through Keycloak or Entra ID. Invitations and reminders go out through your own SMTP relay, under your domain.

We switch on LimeSurvey’s encryption for participant names and email addresses, and its keys live in security.php. Lose that file and the fields cannot be read back. It is backed up with the database and the upload directory, daily and encrypted, to an offsite location in your chosen country, and once a month all three are restored into a scratch instance. Probes check the survey pages every 60 seconds, and a failure alerts an engineer. The Pilae Agent rehearses each upgrade on a copy and, once you approve it, applies it in your window and runs the database update itself, rather than leaving that to whoever opens the admin page first.

LimeSurvey licence and editions

LimeSurvey is GPL-2.0-or-later, and the Community Edition has no paid feature tier and no fee per response or per user. LimeSurvey GmbH sells a hosted service and a paid updater, ComfortUpdate. We upgrade from the release packages, so your installation does not need the updater. LimeSurvey GmbH’s trademark policy covers the name and logo, not your use of the software. Pricing for our operation is on request. Talk to us about your next round of fieldwork.

LimeSurvey is GPL-2.0-or-later, and the Community Edition we deploy has no paid feature tier. LimeSurvey GmbH, in Hamburg, sells services around it, including LimeSurvey Cloud, its own hosted service, and ComfortUpdate, a paid in-browser updater. A ComfortUpdate subscription also gives access to older releases and a software bill of materials. We upgrade from the release packages and do not need the updater. If your procurement wants the bill of materials, that subscription is held in your name. The LimeSurvey name and logo are registered trademarks of LimeSurvey GmbH. Its trademark policy asks for written permission before they are used to advertise LimeSurvey hosting or support services, and places no restriction on using the name for the software you run.

LimeSurvey system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 4 GBOur starting size for PHP-FPM and the database together. LimeSurvey wants at least 256 MB per PHP process, and up to 512 MB where PDF exports are used.
Database
MariaDB 10.3.38+, InnoDBUpstream supports MariaDB, MySQL 8+, PostgreSQL 14+ and SQL Server 2019+, and we use MariaDB. Every activated survey gets its own response table with a column per answer field, so we test the longest questionnaire against it before launch.
Mail
SMTP relay, SPF, DKIMInvitations and reminders are sent from your domain. Without SPF and DKIM for it, a large invitation run lands in spam.
File storage
Volume for upload/Holds the files respondents upload, images in questionnaires, your survey theme and plugins. A response that points to a missing file is an incomplete response.
Staff sign-in
OIDC proxy or LDAPThe Community Edition authenticates against its own users, LDAP, or the web server in front of it. An OpenID Connect proxy in front of the administration is how Keycloak or Entra ID reaches it.

Migrating from SurveyMonkey to LimeSurvey

SurveyMonkey exports responses as CSV, XLS or SPSS files. The questionnaire itself downloads as a PDF, and its API returns the design as JSON, but LimeSurvey imports neither, so surveys are rebuilt. That is less work than it sounds: LimeSurvey imports a questionnaire from a tab-separated file, so a long survey can be written in a spreadsheet rather than clicked together. Logic is the real work. Skip logic and piping become LimeSurvey conditions and expressions, and quotas become LimeSurvey quotas. Questions cannot be added or removed once a survey is collecting answers, so every branch is tested before activation. Past results stay in those export files. Benchmarks against other SurveyMonkey customers, and integrations built on its apps, do not come across.

  1. Sort live surveys from finished ones

    Which surveys are running, which recur every year, and which only need their results kept. Finished surveys are exported and archived, not rebuilt.

  2. Rebuild the questionnaires

    Long questionnaires are written in LimeSurvey's tab-separated format and imported. Skip logic becomes conditions, checked with LimeSurvey's logic check before anyone sees the survey.

  3. Bring the participant lists

    Participant lists are imported into each survey from CSV or an LDAP query, with encryption switched on for names and email addresses.

  4. Test every branch, then swap the links

    Test responses go through each branch, quota and email before activation. Links on the intranet and in newsletters are replaced before the old account closes.

What a LimeSurvey restore needs

  • mariadb/limesurveyInnoDB, 6.2 GB
    • lime_surveyssurvey settings
    • lime_responses_482915one table per active survey
    • lime_tokens_482915participants, name and email encrypted
    • lime_timings_482915time per page, if recorded
    • lime_old_responses_317204_20260612093015kept when a survey was deactivated
  • upload/14 GB
    • surveys/482915/filesrespondent uploads
    • surveys/482915/imagesimages in the questionnaire
    • themes/survey/acmehouse survey theme
    • pluginsinstalled from the admin
  • application/config/
    • config.phpdatabase connection and URL format
    • security.phpencryption keys, generated once
  • s3://acme-backupsoffsite, daily, encrypted
An example layout. Each activated survey has its own response and participant tables, respondent uploads sit on disk, and security.php holds the keys to the encrypted fields. All three go into every backup: restored without the key file, participant names and email addresses come back unreadable.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running LimeSurvey

Pricing is on request: a fixed price for onboarding, then a monthly price for LimeSurvey, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

LimeSurvey: common questions

Is LimeSurvey open source?

Yes. It is GPL-2.0-or-later, and the Community Edition we deploy has no paid feature tier and no fee per response or per user. LimeSurvey GmbH sells hosting and a paid updater around it. It also holds the trademark on the name and logo, and its trademark policy places no restriction on running the software for your own organisation.

Where do the responses live?

In each survey's own tables in MariaDB, on a dedicated machine in the place your data-protection assessment names: your own hardware, or a Pilae region in ISO 27001-certified datacentres. Uploaded files sit beside them, and backups go to an offsite location in the country you chose.

Can responses be anonymous?

Yes, per survey, chosen when it is activated. With anonymised responses on, LimeSurvey keeps no link between an answer and the participant who gave it, and it replaces the submission date with a fixed placeholder so a response cannot be matched against access logs. Participant names and email addresses can also be encrypted in the database, and we switch that on for every survey we bring across.

Can LimeSurvey replace Qualtrics?

For most academic and public-sector survey work, yes: questionnaires with branching logic, quotas, invited participants, several languages and exports to SPSS, R or Stata. Qualtrics' experience-management dashboards, text analytics and the respondent panels it sells are not part of LimeSurvey, and we say so before you cancel anything.

Why not use LimeSurvey Cloud?

It is a sound service if its locations suit you: Germany, Finland, the United Kingdom, the United States, Canada and Australia. It has no Swiss location, and single sign-on is on its top plan. With us you run the Community Edition in the region or on the machine you choose, and sign-on through Keycloak or Entra ID is part of the deployment.

Also in workflow and data

Back to apps

Bring us your LimeSurvey. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.