Trust Center
Answers to common questions about security, compliance, operations, and how we handle your data.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Customer data is stored in Swedish data centers.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How is secret authentication information (for example passwords and keys) handled?Access & authorization
The assignment and handling of secret authentication information, such as passwords, API keys and certificates, is governed by a formal process. Such information is distributed securely, stored protected and rotated when needed, and secrets are never stored in plaintext in source code. We use a password management system that maintains good password quality.
What is expected of users regarding secret authentication information?Access & authorization
Users follow the organisation's procedures for protecting passwords and other secret authentication information, including not sharing login credentials and handling them securely.
Is the environment monitored around the clock?Logging & monitoringNIS2
Yes. We monitor the platform's operation and network traffic around the clock, year-round (24/7/365), with automatic alerts going directly to our engineers. The real-time monitoring tracks platform health, security metrics and network traffic and alerts on anomalies, and central dashboards watch for, among other things, unauthorised access attempts and abnormal traffic patterns. Operational and security logs are collected centrally, and we work continuously to strengthen our ability to detect security events.
Is privileged access to the infrastructure logged?Logging & monitoring
Yes. We keep audit logs for all infrastructure, which includes logins and privileged access to underlying systems. The logs are collected centrally and retained for an extended period, and relevant extracts can be provided on request - for example in connection with a security or personal data incident.
How do you detect capacity shortages before they affect the service?Logging & monitoring
We monitor capacity continuously and have automatic thresholds in the data centers for, among other things, disk, CPU, memory (RAM) and graphics cards (GPU) that create a ticket when exceeded, so that capacity shortages can be addressed in time.
Can we access our own logs and monitor the service?Logging & monitoring
Yes. You can access logs for your own services and make endpoints available for monitoring with the tool of your choice. Access is limited to log data relating to your own services.
How long is monitoring data retained?Logging & monitoring
Metrics from the platform's monitoring are retained for at least 90 days. Audit logs are retained for an extended period, and relevant extracts can be provided on request.
Capacity managementLogging & monitoring
Resource usage is monitored continuously and reviewed at set intervals, and future capacity needs are planned for to maintain the required performance.
Event loggingLogging & monitoring
Logs of user activities, errors and security events are created, retained and reviewed regularly.
Protection of log informationLogging & monitoring
Logging facilities and log information are protected against tampering and unauthorised access. Logs are collected centrally and tamper-resistantly, sent in real time to access-controlled archives and retained as forensic evidence.
Clock synchronisationLogging & monitoring
The clocks in all relevant systems are synchronised to a common, traceable reference time source. We synchronise to ntp.se, the Swedish standard time service operated by RISE and Netnod, which makes logs comparable across systems and enables accurate forensics.
How do you work with vulnerabilities and patching?Vulnerability management & patchingNIS2
We have a central process and policy for vulnerability management. We carry out regular vulnerability scanning, rank vulnerabilities by risk and track them to remediation according to defined service levels (SLA). Container images are also scanned automatically in the build pipeline, and patching is carried out regularly with priority on high-risk systems.
How do you harden the systems?Vulnerability management & patchingNIS2
We harden physical and logical components (for example servers, virtual machines and service protocols) according to established hardening standards (including CIS Benchmarks), and the configuration is managed as code so that a secure baseline is maintained.
How do I report a vulnerability to you?Vulnerability management & patchingNIS2
We have an established process for responsible vulnerability disclosure. If you or a security researcher discovers a vulnerability, it can be reported confidentially to compliance@elastx.se. We receive, assess and remediate reported vulnerabilities according to our vulnerability and patch management process.
How do you protect against malicious code?Vulnerability management & patchingNIS2
We have multi-layered protection against malicious code at the hypervisor, orchestration and endpoint levels. All company devices have endpoint-level security monitoring (EDR), and in selected environments intrusion detection continuously monitors container runtimes. The protection is combined with recurring security training and awareness among staff.
How do you keep different customers' environments separate?Network & isolationNIS2
We separate different customers' environments (tenants) logically using, among other things, VLAN, VXLAN and software-defined networking (SDN), and the platform's administration layer is kept strictly isolated from customers' runtime environments. The logical segmentation prevents lateral movement and keeps customer workloads separate.
How do you protect against DDoS and network attacks?Network & isolationNIS2
DDoS protection at the network level (L3/L4) against volumetric attacks is included in the platform service at no extra cost, is always active and requires no configuration. In addition, we offer a web application firewall (WAF) and threat intelligence as options, together with secure network zoning that blocks known malicious sources. We also offer a CDN service that can offload and protect web traffic.
How do you govern and secure your network services?Network & isolation
Networks are managed, monitored and controlled to protect the information in systems and services. Network traffic is segmented and governed on the principle of blocking what is not explicitly allowed, and different security zones are kept separate. For all network services, both in-house and outsourced, security mechanisms, service levels and requirements are defined, and these are included in contracts.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
For personal data we act as a data processor. We guarantee technical and organisational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For GDPR matters you can reach us at gdpr@elastx.se.
Is data encrypted at rest?Data protection & encryptionNIS2GDPR
Yes. We have a policy and procedures for encryption, and all disks in our environment are encrypted with strong encryption (AES-256). Physical servers use self-encrypting drives (SED) according to TCG Opal with pre-boot authentication, so that a physically stolen storage medium does not grant access to data.