Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How do you separate duties and responsibilities?Governance & compliance
Duties and areas of responsibility that are incompatible, that is, that should not be performed by one and the same person, are kept separate. One example is that the person who performs a sensitive action should not also be able to approve it alone. This reduces the risk of unauthorized or accidental changes and of misuse of assets.
Documented structure for policies, processes and proceduresGovernance & compliance
Policies are defined, documented and communicated to meet business requirements and to clarify responsibility for working methods, processes and procedures. We use a GRC tool to document, structure, communicate and follow up the framework.
How are roles and responsibilities for information security allocated?Governance & compliance
Security work is systematically organized with clearly defined and documented roles and responsibilities. Each control and security area has a designated owner, the work is coordinated by our Compliance group, and ultimate responsibility rests with the CEO. This ensures that tasks do not fall through the cracks and that it is always clear who is accountable for a given matter.
Which information security policies do you have?Governance & compliance
We have a coherent framework of policies that are approved by management and communicated to employees and relevant external parties. It includes, among others, an overarching information security policy, a cloud security policy (ISO/IEC 27017), an access control policy, a vulnerability management policy, a backup and continuity policy, a secure development policy and a policy for AI ethics and AI governance. The public version of the information security policy is available for download.
How often are your information security policies reviewed?Governance & compliance
The policies are reviewed at least once a year and additionally upon material changes, for example new threats, new legislation or major changes in the business. Each policy has an owner responsible for the review, and changes are approved by management before they are published.
What do your documented operating procedures cover?Governance & compliance
Recurring operational activities are documented as procedures and made available to those who need them. This applies, for example, to operation and monitoring of the platform, backup and recovery, patching and change management, and incident handling. The documentation ensures that work is carried out uniformly and securely regardless of individuals.
Management responsibilityGovernance & compliance
Management makes clear the requirements regarding the Code of Conduct, integrity and information security through clear communication, and employees and consultants periodically confirm that they have read and understood applicable policies and procedures. All staff are background-checked, and the check is repeated annually for roles with access to customer data.
Are you covered by Cybersäkerhetslagen (NIS2)?Regulatory complianceNIS2
Yes. We are covered by Cybersäkerhetslagen (the Swedish Cybersecurity Act, 2025:1506), which implements the NIS2 Directive and entered into force on 15 January 2026. We are covered as a provider of essential and critical infrastructure, partly through the transposition of the CER Directive, and as a provider of cloud services, data center services and CDN. PTS (the Swedish Post and Telecom Authority) is the supervisory authority for digital infrastructure, and Myndigheten för Civilt Försvar (MCF, the Swedish Civil Defence Agency) is the national coordinating authority and recipient of incident reports. We meet the law's requirements regarding security measures, management responsibility, training and incident reporting. Oversight of subcontractors and the supply chain is a central part of the requirements.
Can you enter into security protection agreements (SUA)?Regulatory compliance
For security-sensitive customers, for example in the public sector, we can where needed enter into a säkerhetsskyddsavtal (SUA, a Security Protection Agreement) under säkerhetsskyddslagen (the Swedish Protective Security Act, 2018:585). Such an agreement is notified to Säkerhetspolisen (the Swedish Security Service).
Compliance processRegulatory compliance
We have an organization and monitoring in place to stay in control of new or amended regulations, laws and standards relevant to the services. We maintain a legal register that tracks compliance requirements, including GDPR, Swedish security laws, NIS2, DORA and contractual requirements, and we keep our procedures and controls updated against it.
Do you meet accessibility requirements (WCAG and EN 301 549)?Regulatory compliance
We follow the accessibility requirements under the EU Accessibility Directive (in Sweden, lagen om vissa produkters och tjänsters tillgänglighet, 2023:254) for those of our digital interfaces that are in scope, primarily our public websites and self-service interfaces. We work toward the guidelines in WCAG and the European standard EN 301 549.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.