FlexiSurvey ships continuously; this page digests the changes into monthly notes, most recent first. Feature availability follows the plan tiers shown on the pricing page, and anything labelled beta or early access is marked as such. This page begins in June 2026; if you need the history of an earlier change, ask support@flexisurvey.net.
July 2026
Field-level encryption of personal data. Names, phone numbers, email addresses, and survey answer values are now encrypted at the application level (AES-256-GCM) before they reach the database, on top of the existing storage encryption and row-level tenant isolation. Existing data was encrypted in place. This applies automatically on every plan; no configuration is needed.
Customer-managed encryption keys (early access, Enterprise). Bring your own AWS KMS key: your organisation's data keys are wrapped by a key you control, every use appears in your own CloudTrail, and revoking the key grant makes your data cryptographically inaccessible to anyone, including us. Set up under Settings → Security → Encryption.
End-to-end encrypted surveys (early access, Enterprise). For the most sensitive collection, a survey can be sealed to a keypair generated in your browser: answers are encrypted on the respondent's device, FlexiSurvey stores only ciphertext it cannot read, and you decrypt exports on your own machines with the flexisurvey-e2e tool. Web collection first; this deliberately trades away server-side analytics for that survey.
A permanent free plan. The Community plan is a real, forever-free tier for small teams and community organisations: 5 surveys, 500 responses a month, 2 seats, all question types, skip logic, templates, and CSV export. Choose it explicitly at sign-up from the pricing page. Every paid plan helps keep it free.
The field-data engine grew up. This month closed the gap between FlexiSurvey and the long-standing field-research tools, in one coordinated wave:
- Repeat groups and rosters. Household members, farm plots, livestock: build repeating question groups with fixed, calculated, or respondent-controlled counts. Skip logic evaluates per instance, computed totals work across instances, and exports offer both wide and long formats. Web capture now; the mobile apps follow.
- XLSForm import. Bring instruments from ODK, Kobo, or SurveyCTO. Every row of the workbook lands in an explicit compatibility report (imported, degraded, or skipped, each with a reason); nothing is dropped silently.
- External datasets. Upload facility registers, commodity lists, or administrative areas once (CSV or Excel, up to 50,000 rows) and use them as searchable choice lists across surveys, with versions pinned when a survey is published.
- Form version lineage. Every response now records exactly which version of the survey it answered. Editing a live survey goes through a governed "publish revision" step that classifies each change as compatible or breaking, with a deployment note and a version timeline.
- A complete review pipeline. Reviewers can correct answers with a mandatory reason and a full before-and-after history (the original submission is never overwritten), return a submission to the field with a note, or quarantine it out of analytics pending a decision. Five review events can notify your systems by webhook.
- Case and visit management. Assign named respondents to enumerators as cases, record visit attempts with dispositions (unavailable, callback, refused, moved), schedule revisits, and let the system close or exhaust cases against an attempt budget.
- Back-checks and interview forensics. Sample completed interviews per enumerator for verification (risk-weighted), review per-question timing forensics, and set survey-specific speed rules that flag suspiciously fast interviews.
- Device fleet management. Enrol field devices by printable QR code (a pre-bound code signs the enumerator in with no typed credentials), and track the fleet's last-seen status and pending uploads from the dashboard.
Field apps hardened (beta). The iOS and Android apps gained interview drafts with autosave and resume, per-response sync states in the Offline screen, and storage safeguards that warn at low disk space and block media capture before data is at risk. Session expiry now never touches the offline queue. The apps remain in beta while the published hardening criteria are completed.
For developers and data teams. The interactive API reference is now public by default with a committed, drift-checked OpenAPI document; a new Developer Guide covers authentication, webhook signature verification, and incremental data pulls; saved export configurations make recurring extracts one click; and exports can include review status and quality-flag columns. Fine-grained personal-data masking now enforces the "view PII" permission across screens and every export format.
Documentation. This help centre gained the Technical Limits page (the platform's enforced ceilings, published honestly), the Logic & Formula Reference, the Offline Collection Reference, and the Troubleshooting catalogue.
Earlier in July. Evidence-first onboarding turned assessments into a guided path from survey findings to a designed project; the Project Design Studio walks a programme design from theory of change to indicators to instruments; the dashboard was redesigned around your actual work queue; and surveys can be imported from a Word document with a pre-flight report.
June 2026
Ask the data to explain itself. "Explain results" arrived across analytics: executive summaries, key drivers, statistical tests, and cluster analyses can each generate a grounded narrative that cites only the numbers on screen, with independent validation that rejects anything the evidence does not support.
Design-based inference. Survey-weighted estimation (weighted means and proportions, survey-weighted regression, corrected tests) landed for research users, validated against R to six decimal places.
Exploratory analysis, rebuilt. The Explore section gained semantic typing (it will not compute a mean of a nominal question), skip-logic-aware missingness, data-quality flags such as digit heaping and straightlining, relationship exploration between any two questions, and distribution diagnostics.
MEAL, deeper. Programmes above projects, donors as first-class records with funding links, SDG tags on indicators and results-framework nodes, project activities with milestones and quantified delivery tracking, and activity-sourced indicators that measure delivery automatically.
Pricing, clearer. The plan ladder was re-cut to four tiers with cumulative features ($99 / $199 / $399 / custom), and the pricing page's comparison matrix now derives every cell from the live plan catalog so it cannot drift from what plans actually grant.
Also in June: a redesigned marketing site and navigation, project blueprints for one-click programme setup (including new sector packs), custom domains for white-label tenants (early access), and a public status vocabulary (generally available, beta, early access, planned) applied across every surface that names a capability.