Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How do you keep different customers' environments separate?Network & isolationNIS2
We separate different customers' environments (tenants) logically using, among other things, VLAN, VXLAN and software-defined networking (SDN), and the platform's administration layer is kept strictly isolated from customers' runtime environments. The logical segmentation prevents lateral movement and keeps customer workloads separate.
How do you protect against DDoS and network attacks?Network & isolationNIS2
DDoS protection at the network level (L3/L4) against volumetric attacks is included in the platform service at no extra cost, is always active and requires no configuration. In addition, we offer a web application firewall (WAF) and threat intelligence as options, together with secure network zoning that blocks known malicious sources. We also offer a CDN service that can offload and protect web traffic.
How do you govern and secure your network services?Network & isolation
Networks are managed, monitored and controlled to protect the information in systems and services. Network traffic is segmented and governed on the principle of blocking what is not explicitly allowed, and different security zones are kept separate. For all network services, both in-house and outsourced, security mechanisms, service levels and requirements are defined, and these are included in contracts.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
Our role depends on the personal data processing in question. For your customer data and workloads on the platform, we act as a data processor, and we guarantee technical and organizational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For administrative data relating to our own customer relationship with you, for example contact details and login logs for your contract administration, we act as a data controller. For GDPR matters you can reach us at gdpr@elastx.se.
Is data encrypted at rest?Data protection & encryptionNIS2GDPR
Yes. We have a policy and procedures for encryption, and all disks in our environment are encrypted with strong encryption (AES-256). Physical servers use self-encrypting drives (SED) according to TCG Opal with pre-boot authentication, so that a physically stolen storage medium does not grant access to data.
How is data protected in transit?Data protection & encryptionNIS2GDPR
Data in transit is protected with TLS (versions 1.2 and 1.3) using strong encryption (AES-256) and with SSH key pairs. For managed database services, CA certificates are provided so that you can verify and encrypt your client connections.
Where is our data stored?Data protection & encryptionGDPRDigital sovereignty
As a data processor and an ISO/IEC 27018-certified company, we store data within Sweden. This means the information is kept within the EU/EEA and out of reach of foreign legislation such as the CLOUD Act. Personal data is processed only on a lawful basis and is securely erased when it is no longer needed.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
Do you use sub-processors?Data protection & encryptionGDPR
It is uncommon for us to use sub-processors. Your data on the platform is stored in Sweden and processed by us as a processor. For certain support services, for example invoicing and dispatch, we may use sub-processors, and the processing is then governed by a Data Processing Agreement (DPA) under GDPR Article 28. We verify that sub-processor agreements are in place, and we notify you before we add or change a data center or sub-processor. Any access for subcontractors to your data on the platform takes place only after your approval.
What happens to our data when the contract ends?Data protection & encryptionGDPRDigital sovereignty
You can export your data ahead of a termination. Upon decommissioning of a service or virtual machine, or upon written request, your data and associated infrastructure are securely erased. Storage rests on self-encrypting drives, which enables cryptographic erasure in line with recognized standards for data sanitization. Logs linked to the processing of personal data are thereafter retained only for as long as the Data Processing Agreement (DPA) and applicable legal requirements demand.
How do you help us with data subjects' rights?Data protection & encryptionGDPR
As a data processor, we assist you as the data controller in responding to requests from data subjects - for example access, rectification, erasure, restriction and data portability - in accordance with the Data Processing Agreement (DPA). The platform gives you technical means to find, export and erase personal data in your own environments.
Which technical and organisational measures do you apply to protect personal data?Data protection & encryptionGDPR
Our Data Processing Agreement (DPA) specifies the technical and organizational measures we apply. Organizationally, we work according to ISO/IEC 27001 with role-based access, mandatory onboarding and offboarding procedures and personal confidentiality undertakings for all staff. Technically, data is encrypted at rest with AES-256 and in transit with TLS 1.2 and 1.3, and the infrastructure is continuously monitored with vulnerability scanning, DDoS protection and central tamper-resistant logging. More detail is available under the respective topic in the FAQ.
How do you ensure that the Data Processing Agreements (DPA) are up to date?Data protection & encryptionGDPR
Our Data Processing Agreement and associated instructions are kept under continuous version control. Revisions prompted by changed legislation, new regulatory requirements or updated security measures are documented in a change history, so that you can always see what applies and why it was changed.
What does your responsibility as a data processor cover?Data protection & encryptionGDPR
As a data processor, we process personal data solely according to your written instructions and without insight into the actual data content. We are responsible for the security, availability and resilience of the underlying cloud infrastructure, including physical security in the data centers, vulnerability protection at the platform level and support around the clock. You are responsible for your application, your credentials and the configuration of your own backups. A full allocation of responsibility is available in the Data Processing Agreement and in our cloud security policy (ISO/IEC 27017).
How do you develop secure software?Secure developmentNIS2
Our in-house development follows a secure development procedure. Security requirements are defined early, code undergoes mandatory peer review and automatic static security analysis (SAST) of container images, and no secrets or keys are stored in source code. The source code resides in access-controlled repositories with MFA, where permissions are governed by developer role and branch protection is applied. Build and deployment pipelines are automated, and changes are tested in isolated test environments before they reach production. No real customer data or personal data is used in development or test environments.
Do you contribute to the open projects you build on?Secure development
Yes. We are active and contribute continuously to OpenStack and Kubernetes, the projects we ourselves build on and use. Our contributions concern, among other things, OpenStack (compute, identity and networking) and Kubernetes, including Cluster API. Other contributions occur more sporadically. This gives us early insight into security updates and the ability to influence upcoming standards.