Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How do remote work and access to the production environment work?Access & authorization
All access to the production environment goes through secured paths and requires multi-factor authentication. There are three ways in: a Corporate Proxy, which is the general path for daily access for most employees; a VPN path for maintenance that requires access to multiple systems or to systems not reachable via the proxy; and a separate out-of-band VPN (OOB VPN) used during disaster recovery. Information handled and stored during remote work is additionally protected by policy and technical security measures.
Responsibility upon terminated or changed employmentAccess & authorization
Information security responsibilities that apply after terminated or changed employment are defined, communicated and enforced. This includes, among other things, that confidentiality and non-disclosure undertakings remain in force, that assets are returned and that access is revoked, so that the protection of information is maintained even after the role has changed or ended.
How are user permissions granted and revoked?Access & authorization
We have a formal process for the entire lifecycle of user accounts. When a person joins, the account is registered and granted the permissions the role requires according to the principle of least privilege. Upon a change of role the permissions are adjusted, and when an employment or contract ends the account is deregistered and access is revoked immediately, including SSH keys and VPN credentials, while confidentiality undertakings remain. The process covers all user types and all systems and services, and permissions are reviewed regularly.
How do you handle privileged (administrative) permissions?Access & authorization
Privileged access rights, that is, elevated administrative permissions, are handled more strictly than ordinary user access. They are granted restrictively and only to named, personal accounts, limited to what the role requires and followed up specifically. Administrative access to the production environment always requires multi-factor authentication.
How is secret authentication information (for example passwords and keys) handled?Access & authorization
The assignment and handling of secret authentication information, such as passwords, API keys and certificates, is governed by a formal process. Such information is distributed securely, stored protected and rotated when needed, and secrets are never stored in plaintext in source code. We use a password management system that maintains good password quality.
Is the environment monitored around the clock?Logging & monitoringNIS2
Yes. We monitor the platform's operation and network traffic around the clock, year-round (24/7/365), with automatic alerts going directly to our engineers. The real-time monitoring tracks platform health, security metrics and network traffic and alerts on anomalies, and central dashboards watch for, among other things, unauthorized access attempts and abnormal traffic patterns. Operational and security logs are collected centrally, and we work continuously to strengthen our ability to detect security events.
Is privileged access to the infrastructure logged?Logging & monitoring
Yes. We keep audit logs for all infrastructure, which includes logins and privileged access to underlying systems. The logs are collected centrally and retained for an extended period, and relevant extracts can be provided on request - for example in connection with a security or personal data incident.
How do you detect capacity shortages before they affect the service?Logging & monitoring
We monitor capacity continuously and have automatic thresholds in the data centers for, among other things, disk, CPU, memory (RAM) and graphics cards (GPU) that create a ticket when exceeded, so that capacity shortages can be addressed in time.
Clock synchronizationLogging & monitoring
The clocks in all relevant systems are synchronized to a common, traceable reference time source. We synchronize to ntp.se, the Swedish standard time service operated by RISE and Netnod, which makes logs comparable across systems and enables accurate forensics.
How do you work with vulnerabilities and patching?Vulnerability management & patchingNIS2
We have a central process and policy for vulnerability management. We carry out regular vulnerability scanning, rank vulnerabilities by risk and track them to remediation according to defined service levels (SLA). Container images are also scanned automatically in the build pipeline, and patching is carried out regularly with priority on high-risk systems.
How do you harden the systems?Vulnerability management & patchingNIS2
We harden physical and logical components (for example servers, virtual machines and service protocols) according to established hardening standards (including CIS Benchmarks), and the configuration is managed as code so that a secure baseline is maintained.
How do I report a vulnerability to you?Vulnerability management & patchingNIS2
We have an established process for responsible vulnerability disclosure. If you or a security researcher discovers a vulnerability, it can be reported confidentially to compliance@elastx.se. We receive, assess and remediate reported vulnerabilities according to our vulnerability and patch management process.
How do you protect against malicious code?Vulnerability management & patchingNIS2
We have multi-layered protection against malicious code at the hypervisor, orchestration and endpoint levels. All company devices have endpoint-level security monitoring (EDR), and in selected environments intrusion detection continuously monitors container runtimes. The protection is combined with recurring security training and awareness among staff.