Trust Center
Answers to common questions about security, compliance, operations, and how we handle your data.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Customer data is stored in Swedish data centers.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How do you evaluate that the security measures are effective?Regulatory complianceNIS2
We have documented policies and procedures to regularly evaluate the effectiveness of the measures for cybersecurity risk, with criteria, responsibilities, evidence, reporting and remediation.
Cyber hygiene and trainingRegulatory complianceNIS2
An awareness and training plan ensures that staff and relevant stakeholders have the security knowledge their role requires.
Personnel securityRegulatory complianceNIS2
We ensure that staff who handle sensitive information and critical systems meet high security requirements. Staff are background-checked before employment, and permissions are granted, reviewed and revoked throughout employment according to the principle of least privilege and zero trust, with multi-factor authentication and clearly defined roles and responsibilities.
Access managementRegulatory complianceNIS2
We have a documented plan and governance for, among other things, multi-factor or continuous authentication and secure communication channels, where appropriate.
Do you have cyber insurance?Risk management
Yes. We have cyber insurance that covers, among other things, liability, business interruption, data recovery and costs associated with a cyber or information incident, including forensic investigation, handling of personal data breaches and access to incident response around the clock. The cover applies globally and complements our technical and organisational security measures.
Reporting of weaknessesRisk management
Our risk policy and procedure allow anyone to report risks and weaknesses to risk management, for example via a ticket or directly to W&C. Reporting is encouraged, the cases are captured and remediated where relevant.
Governance of risk controlRisk management
The risk assessment process identifies, assesses and manages risks that affect the organisation's ability to reach its objectives. In practice, this means we carry out contextual risk assessments of technical vulnerabilities based on our unique environment and apply a framework according to ISO 31000 to proactively evaluate and govern risks in our supply chain.
Risk awareness and learningRisk management
The board, management and relevant staff have knowledge of risks and how they are managed, resolved or reduced to an acceptable level. This is ensured through recurring risk reviews, training and by following up risks and remediations in management reviews.
Assessment of information security risksRisk managementNIS2
Information security risks are automatically given higher priority in the process so that resolution or reduction is handled promptly. In our operational work, this means that detected vulnerabilities are immediately risk-assessed based on system exposure and impact on critical services, which triggers timeframes for patching and mitigating measures.
Response to information security risksRisk managementNIS2
Risks relating to information security and integrity are reported according to the standard process. Particularly sensitive risks are reported to a small number of designated individuals. In practice, this means that standard risks are tracked through our internal ticketing systems, while critical or confidential matters are escalated directly to the management team or handled via our protected whistleblower channel to ensure confidentiality and immediate action.
How do you govern access and permissions?Access & authorizationNIS2
We apply the principle of least privilege, so that each employee receives only the rights required for their role, and administrators have unique, personal accounts. Access is protected in several layers, including with multi-factor authentication and hardware-based security keys for sensitive access. Permissions are reviewed regularly and adjusted or removed upon a change in or termination of employment.
Is multi-factor authentication required for administrative access to the production environment?Access & authorizationNIS2
Yes. All administrative access to the production environment goes through secured paths and requires multi-factor authentication. For administrative accounts, hardware-based MFA according to FIDO2/WebAuthn is required, and administrators are equipped with a physical hardware token as the primary factor. We also support time-based one-time passwords (TOTP).
Do you background-check your staff?Access & authorization
Yes. A background check is carried out on all final candidates before an employment decision is made, and the check is repeated annually for all roles with access to customer data. The checks are carried out in cooperation with an external certified partner and include, among other things, verification of identity, criminal records and court judgments, and financial situation, drawn from public registers or from authorised providers.
How are your employees' computers and devices protected?Access & authorization
Company devices are subject to encryption, central device management and endpoint security monitoring (EDR), with a local firewall that blocks inbound traffic and automatic updates. We apply clean desk and clean screen rules as well as mandatory automatic screen locking. Devices that can be used to administer customer environments or access customer data are subject to stricter requirements than other devices. Employees are given access only to the systems they have been explicitly authorised for.
Mobile device policyAccess & authorization
A policy and supporting security measures address the risks that the use of mobile devices entails, for example encryption, screen lock and the ability to wipe a device remotely if it is lost or stolen. Devices are additionally protected with extended endpoint protection (XDR) that continuously monitors and alerts on suspicious activity and behaviour.
How do remote work and access to the production environment work?Access & authorization
All access to the production environment goes through secured paths and requires multi-factor authentication. There are three ways in: a Corporate Proxy, which is the general path for daily access for most employees; a VPN path for maintenance that requires access to multiple systems or to systems not reachable via the proxy; and a separate out-of-band VPN (OOB VPN) used during disaster recovery. Information handled and stored during remote work is additionally protected by policy and technical security measures.
Restriction of software installationAccess & authorization
Rules for which software users may install are established and enforced, so that only approved and secure software runs in the environment and the risk of malicious or insecure code is reduced.
Responsibility upon terminated or changed employmentAccess & authorization
Information security responsibilities that apply after terminated or changed employment are defined, communicated and enforced. This includes, among other things, that confidentiality and non-disclosure undertakings remain in force, that assets are returned and that access is revoked, so that the protection of information is maintained even after the role has changed or ended.
How are user permissions granted and revoked?Access & authorization
We have a formal process for the entire lifecycle of user accounts. When a person joins, the account is registered and granted the permissions the role requires according to the principle of least privilege. Upon a change of role the permissions are adjusted, and when an employment or contract ends the account is deregistered and access is revoked immediately, including SSH keys and VPN credentials, while confidentiality undertakings remain. The process covers all user types and all systems and services, and permissions are reviewed regularly.
How do you handle privileged (administrative) permissions?Access & authorization
Privileged access rights, that is, elevated administrative permissions, are handled more strictly than ordinary user access. They are granted restrictively and only to named, personal accounts, limited to what the role requires and followed up specifically. Administrative access to the production environment always requires multi-factor authentication.