Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do you back up our data?Continuity & recoveryNIS2
We back up our own platform, for example configuration and system images, and these backups are created and tested according to a defined backup policy. Backup and any replication of your data is configured and governed by you, with tools in the platform or external tools, based on your wishes and what your contract covers - this gives you full control over what is saved, where and for how long. For immutable storage of critical copies and logs we offer The Vault. Our object storage service stores three copies by default, distributed across three availability zones.
How are the continuity processes implemented and maintained?Continuity & recovery
Procedures and controls to maintain continuity during a disruption are established, documented, implemented and maintained. The continuity and disaster recovery plan contains controls that are verified regularly to ensure that it is valid and effective.
What training does staff receive in crisis management?Continuity & recovery
Staff who are part of the crisis organization receive recurring training and exercises in crisis management, for example in roles and mandates, decision-making under pressure, internal and external communication and the technical containment and recovery procedures. Other staff receive training at an overview level so that everyone knows how to act and where to turn in a crisis.
Which availability levels (SLA) do you offer?Service delivery & SLA
We publish clear availability SLAs per service. Elastx-managed services across multiple availability zones have 99.95% monthly uptime, and compute and storage built redundantly across multiple zones have 99.99%. Redundant services within a single zone have at least 99.9%, single instances without redundancy at least 99.5% and non-redundant connectivity at least 99%. If a level is not met, you may be entitled to financial compensation on your next invoice (10, 30 or 100% depending on the size of the deviation). Planned maintenance windows and force majeure are excluded. Full terms are available in our availability SLA.
What support and response time do you offer?Service delivery & SLA
Support around the clock (24x7) is included in all our services, and we monitor our platform and our services 24x7. The response time is governed by the severity of the case: 15 minutes for business-critical cases (around the clock), 1 hour for high impact, 4 hours during office hours for normal cases and next business day for low priority. Cases are logged and tracked in our support portal, and current operational status is published continuously on our status page. Full terms are available in our support SLA.
Do we receive reports on quality and delivery?Service delivery & SLA
Customer contracts can contain terms on reporting of quality and delivery. Current operational status and availability are published continuously on our status page, and follow-up of service levels (SLA) can be compiled and shared with you according to the contract.
Support deliveryService delivery & SLA
We provide support to customers where cases are classified by priority and severity. The service levels are described in our support SLA.
How do you inventory your assets?Asset management
Assets linked to information and information processing are identified and entered into an inventory that is kept up to date. This covers, for example, physical equipment such as servers, network equipment and storage, but also information assets such as data stores, configurations, source code and documentation. Each asset has a designated owner responsible for classifying it correctly, protecting it in line with its sensitivity and handling it correctly throughout its lifecycle.
Acceptable use of assetsAsset management
All customers, employees and partners are covered by the Elastx Acceptable Use Policy (AUP), which is a binding part of our general terms. The policy expressly prohibits activities that could jeopardise the platform's stability or network security, for example unauthorized port scanning, vulnerability scanning, network sweeps, spam and operation of open proxy servers. We reserve the right to immediately restrict network services or suspend accounts if the rules are breached. Our full policy is available at Acceptable Use Policy.
Disposal of mediaAsset management
Media is disposed of securely according to formal procedures when no longer needed. Storage media is encrypted, which enables cryptographic erasure, and media is sanitized or destroyed in a way that prevents data from being reconstructed before equipment is reused or disposed of. This applies to media both in the data center environment and on employees' work computers.
Physical media in transitAsset management
Our principle is that media containing information does not leave the cage in the data center. Sensitive information should not move outside our secure zones, and in the exceptional cases where media does need to be handled, it is encrypted and the transport takes place with traceability and control of who has handled it.
What does the physical security look like in your data centers?Physical security & data centers
Our data centers are Tier 3-equivalent and have several physical security layers. Entry is via manual access control with ID checks, fingerprint and man-traps, and the facilities are CCTV-monitored. All access is logged and controlled. The physical access is covered by our ISO/IEC 27001 certification, and the data center facilities are operated by operators with their own independent audits (SOC 2 Type II) at the operator level.
How is the physical security of your data centers designed?Physical security & data centers
Our data centers are protected in multiple layers based on a risk-based assessment: reinforced building construction, perimeter protection and detection, around-the-clock guarding and CCTV surveillance, and strict access control. External walls, ceilings and floors are of reinforced concrete. Where such an assessment has been made, data halls have been independently assessed to the Swedish Theft Prevention Association's SSF 200 protection class 3. Parts of our data center capacity are classified as protected installations (skyddsobjekt) and staffed with certified protection guards. Physical security at the facility level is independently audited and certified to ISO/IEC 27001 and SOC 2 Type II. Many customers base their procurement on MCF's guidance on physical information security for IT spaces (protection level 3); the facilities are designed and operated so that, on a risk-based assessment, they meet or exceed that guidance. Documentation on individual standards can be shared with customers on request as part of a vendor assessment.
Who has access to the data centers and how is it regulated?Physical security & data centers
Elastx rents locked, video-monitored rooms in high-security data centers (our availability zones). Only background-checked Elastx staff have access, and only after prior notification. Access takes place with individual, personal access cards or badges combined with biometric verification, for example fingerprint, and security personnel monitor and control access to the facilities. Detailed visitor logs are kept of everyone who comes and goes, and all access is logged and controlled. Other access requests to our premises are approved by Elastx in advance.
Camera surveillance (CCTV)Physical security & data centers
Data centers, corridors and server halls are monitored around the clock with high-resolution, infrared-capable camera surveillance (CCTV). The system alerts on motion or a person in areas where no one should be, and recordings are stored in encrypted, tamper-resistant archives.
How are the facilities' perimeter and outer protection secured?Physical security & data centers
In our availability zones, the perimeter is protected in several layers: fencing and barriers around the facility, bollards that prevent vehicle access, security lighting at entrances and perimeters, and reinforced doors, locks and splinter-protected glass. Controlled entry and exit points with man-traps prevent unauthorized tailgating, and intrusion alarms watch entrances and sensitive areas, including secure zones such as server rooms.
How are the facilities protected against fire, power outages and environmental threats?Physical security & data centers
Our availability zones are built for operational reliability and protection against environmental threats. Smoke detectors, fire alarms and automatic extinguishing systems handle fire, climate systems maintain optimal temperature and humidity for the equipment, and sensors alert on water leakage or flooding. Power supply is fully redundant and appropriately protected, critical systems are protected by uninterruptible power (UPS), and diesel generators take over during longer outages. Sensitive equipment is protected against electromagnetic interference (EMI).
How are equipment and cables handled in the facilities?Physical security & data centers
Servers and network equipment are placed in locked rooms and, where applicable, in locked cabinets, and network and power cables are protected and concealed to prevent tampering, including at our fiber junction points. Physical equipment is labeled and registered in an asset register so that it can be tracked, linked to an owner and handled securely throughout its lifecycle.