Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • Risk analysis and system securityRegulatory complianceNIS2

    Risk-based analyses and risk-reducing measures are carried out in accordance with applicable law and recognized standards, primarily ISO/IEC 27001 and ISO 31000.

  • Incident managementRegulatory complianceNIS2GDPR

    For security and personal data incidents we have a documented incident management procedure to detect, handle and report incidents in accordance with applicable law, including Cybersäkerhetslagen (NIS2) and, for personal data breaches, GDPR.

  • Continuity and crisis managementRegulatory complianceNIS2

    We have plans for, among other things, backup, disaster recovery and crisis management to secure uninterrupted delivery in accordance with laws and contracts.

  • Supply chain securityRegulatory complianceNIS2

    We have controls for our direct suppliers and service providers, that is, those with whom we have a contractual relationship, to ensure that their services meet our security requirements. The requirements are adapted to how critical the supplier is to our delivery.

  • Security in the acquisition, development and maintenance of networks and IT systemsRegulatory complianceNIS2

    Security is integrated into the acquisition, development and maintenance of networks and information systems, including the handling and reporting of vulnerabilities.

  • How do you evaluate that the security measures are effective?Regulatory complianceNIS2

    We have documented policies and procedures to regularly evaluate the effectiveness of the measures for cybersecurity risk, with criteria, responsibilities, evidence, reporting and remediation.

  • Cyber hygiene and trainingRegulatory complianceNIS2

    An awareness and training plan ensures that staff and relevant stakeholders have the security knowledge their role requires.

  • Personnel securityRegulatory complianceNIS2

    We ensure that staff who handle sensitive information and critical systems meet high security requirements. Staff are background-checked before employment, and permissions are granted, reviewed and revoked throughout employment according to the principle of least privilege and zero trust, with multi-factor authentication and clearly defined roles and responsibilities.

  • Access managementRegulatory complianceNIS2

    We have a documented plan and governance for, among other things, multi-factor or continuous authentication and secure communication channels, where appropriate.

  • Do you have cyber insurance?Risk management

    Yes. We have cyber insurance that covers, among other things, liability, business interruption, data recovery and costs associated with a cyber or information incident, including forensic investigation, handling of personal data breaches and access to incident response around the clock. The cover applies globally and complements our technical and organizational security measures.

  • Reporting of weaknessesRisk management

    Our risk policy and procedure allow anyone to report risks and weaknesses to risk management, for example via a ticket or directly to W&C. Reporting is encouraged, the cases are captured and remediated where relevant.

  • Governance of risk controlRisk management

    The risk assessment process identifies, assesses and manages risks that affect the organization's ability to reach its objectives. In practice, this means we carry out contextual risk assessments of technical vulnerabilities based on our unique environment and apply a framework according to ISO 31000 to proactively evaluate and govern risks in our supply chain.

  • Risk awareness and learningRisk management

    The board, management and relevant staff have knowledge of risks and how they are managed, resolved or reduced to an acceptable level. This is ensured through recurring risk reviews, training and by following up risks and remediations in management reviews.

  • Assessment of information security risksRisk managementNIS2

    Information security risks are automatically given higher priority in the process so that resolution or reduction is handled promptly. In our operational work, this means that detected vulnerabilities are immediately risk-assessed based on system exposure and impact on critical services, which triggers timeframes for patching and mitigating measures.

  • Response to information security risksRisk managementNIS2

    Risks relating to information security and integrity are reported according to the standard process. Particularly sensitive risks are reported to a small number of designated individuals. In practice, this means that standard risks are tracked through our internal ticketing systems, while critical or confidential matters are escalated directly to the management team or handled via our protected whistleblower channel to ensure confidentiality and immediate action.

  • How do you govern access and permissions?Access & authorizationNIS2

    We apply the principle of least privilege, so that each employee receives only the rights required for their role, and administrators have unique, personal accounts. Access is protected in several layers, including with multi-factor authentication and hardware-based security keys for sensitive access. Permissions are reviewed regularly and adjusted or removed upon a change in or termination of employment.

  • Is multi-factor authentication required for administrative access to the production environment?Access & authorizationNIS2

    Yes. All administrative access to the production environment goes through secured paths and requires multi-factor authentication. For administrative accounts, hardware-based MFA according to FIDO2/WebAuthn is required, and administrators are equipped with a physical hardware token as the primary factor. We also support time-based one-time passwords (TOTP).

  • Do you background-check your staff?Access & authorization

    Yes. A background check is carried out on all final candidates before an employment decision is made, and the check is repeated annually for all roles with access to customer data. The checks are carried out in cooperation with an external certified partner and include, among other things, verification of identity, criminal records and court judgments, and financial situation, drawn from public registers or from authorized providers.

  • How are your employees' computers and devices protected?Access & authorization

    Company devices are subject to encryption, central device management and endpoint security monitoring (EDR), with a local firewall that blocks inbound traffic and automatic updates. We apply clean desk and clean screen rules as well as mandatory automatic screen locking. Devices that can be used to administer customer environments or access customer data are subject to stricter requirements than other devices. Employees are given access only to the systems they have been explicitly authorized for.

  • Mobile device policyAccess & authorization

    A policy and supporting security measures address the risks that the use of mobile devices entails, for example encryption, screen lock and the ability to wipe a device remotely if it is lost or stolen. Devices are additionally protected with extended endpoint protection (XDR) that continuously monitors and alerts on suspicious activity and behavior.