Trust Center
Answers to common questions about security, compliance, operations, and how we handle your data.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Customer data is stored in Swedish data centers.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Support deliveryService delivery & SLA
We provide support to customers where cases are classified by priority and severity. The service levels are described in our support SLA.
How do you inventory your assets?Asset management
Assets linked to information and information processing are identified and entered into an inventory that is kept up to date. This covers, for example, physical equipment such as servers, network equipment and storage, but also information assets such as data stores, configurations, source code and documentation. Each asset has a designated owner responsible for classifying it correctly, protecting it in line with its sensitivity and handling it correctly throughout its lifecycle.
Acceptable use of assetsAsset management
All customers, employees and partners are covered by the Elastx Acceptable Use Policy (AUP), which is a binding part of our general terms. The policy expressly prohibits activities that could jeopardise the platform's stability or network security, for example unauthorised port scanning, vulnerability scanning, network sweeps, spam and operation of open proxy servers. We reserve the right to immediately restrict network services or suspend accounts if the rules are breached. Our full policy is available at Acceptable Use Policy.
Return of assetsAsset management
Employees and external parties return all equipment and other assets belonging to Elastx, for example laptops and access cards, upon terminated employment or contract.
Disposal of mediaAsset management
Media is disposed of securely according to formal procedures when no longer needed. Storage media is encrypted, which enables cryptographic erasure, and media is sanitised or destroyed in a way that prevents data from being reconstructed before equipment is reused or disposed of. This applies to media both in the data center environment and on employees' work computers.
Physical media in transitAsset management
Our principle is that media containing information does not leave the cage in the data center. Sensitive information should not move outside our secure zones, and in the exceptional cases where media does need to be handled, it is encrypted and the transport takes place with traceability and control of who has handled it.
What does the physical security look like in your data centers?Physical security & data centers
Our data centers are Tier 3-equivalent and have several physical security layers. Entry is via manual access control with ID checks, fingerprint and man-traps, and the facilities are CCTV-monitored. All access is logged and controlled. The physical access is covered by our ISO/IEC 27001 certification, and the data center facilities are operated by operators with their own independent audits (SOC 2 Type II) at the operator level.
Do your data centers meet MCF's protection level 3?Physical security & data centers
Yes. Our data centers are built and designed according to the requirements for MCF's protection level 3. The facilities follow the European data center standard SS-EN 50600 and are dimensioned based on Tier III specifications, with several layers of physical perimeter protection, perimeter security and strict access control. The physical security is additionally covered by our ISO/IEC 27001 certification, and the facilities are operated by operators with their own independent audits.
Who has access to the data centers and how is it regulated?Physical security & data centers
Elastx rents locked, video-monitored rooms in high-security data centers (our availability zones). Only background-checked Elastx staff have access, and only after prior notification. Access takes place with individual, personal access cards or badges combined with biometric verification, for example fingerprint, and security personnel monitor and control access to the facilities. Detailed visitor logs are kept of everyone who comes and goes, and all access is logged and controlled. Other access requests to our premises are approved by Elastx in advance.
Are multiple factors required for physical access to the equipment?Physical security & data centers
Yes. Physical access to network equipment and servers requires at least two-factor authentication.
Camera surveillance (CCTV)Physical security & data centers
Data centers, corridors and server halls are monitored around the clock with high-resolution, infrared-capable camera surveillance (CCTV). The system alerts on motion or a person in areas where no one should be, and recordings are stored in encrypted, tamper-resistant archives.
How are the facilities' perimeter and outer protection secured?Physical security & data centers
In our availability zones, the perimeter is protected in several layers: fencing and barriers around the facility, bollards that prevent vehicle access, security lighting at entrances and perimeters, and reinforced doors, locks and splinter-protected glass. Controlled entry and exit points with man-traps prevent unauthorised tailgating, and intrusion alarms watch entrances and sensitive areas, including secure zones such as server rooms.
How are the facilities protected against fire, power outages and environmental threats?Physical security & data centers
Our availability zones are built for operational reliability and protection against environmental threats. Smoke detectors, fire alarms and automatic extinguishing systems handle fire, climate systems maintain optimal temperature and humidity for the equipment, and sensors alert on water leakage or flooding. Power supply is fully redundant and appropriately protected, critical systems are protected by uninterruptible power (UPS), and diesel generators take over during longer outages. Sensitive equipment is protected against electromagnetic interference (EMI).
How are equipment and cables handled in the facilities?Physical security & data centers
Servers and network equipment are placed in locked rooms and, where applicable, in locked cabinets, and network and power cables are protected and concealed to prevent tampering, including at our fiber junction points. Physical equipment is labelled and registered in an asset register so that it can be tracked, linked to an owner and handled securely throughout its lifecycle.
How do you work with physical security on an ongoing basis?Physical security & data centers
Physical security is managed on an ongoing basis. Employees are trained in physical security procedures and reporting paths, physical and environmental protective measures are reviewed regularly, and access permissions are reviewed and revoked when needed, particularly after staff changes. There are documented plans for how physical security incidents are to be handled, for example break-in attempts, unauthorised access, fire or power outage, and the plans are exercised regularly together with the data center operators.
How do you ensure security in your supply chain?Supply chainNIS2
We are part of a supply chain and apply a continuous, documented and risk-based review of our suppliers, in line with the requirements on supply chain security in Cybersäkerhetslagen (NIS2). New suppliers are reviewed and approved before they are taken into use, and our critical and essential suppliers are followed up annually as well as upon noted deviations. A summary or certificate regarding the supplier review can be shared on request.
Can you give concrete examples of how you secure the supply chain?Supply chainNIS2Digital sovereignty
Yes. Our fiber infrastructure is provided in part via Stokab, which is covered by the City of Stockholm's central guidelines and monitored operationally by CERT Stockholm. Our CDN is delivered by Varnish Software as a fully European service with a control plane in France, isolated from foreign legislation such as the CLOUD Act. Throughout, we prioritise suppliers within the EU/EEA and services that are not exposed to foreign jurisdiction.
How do you assess new suppliers before engaging them?Supply chainNIS2
We apply a structured framework for supplier risk assessment in two steps. In the first step we assess the supplier as a whole - security maturity (for example ISO/IEC 27001 certification or an ISAE 3000 report), financial stability and how they in turn manage their own subcontractors. The outcome is approved, escalation for deeper review or a stop. In the second step we assess the specific service's risk according to a likelihood and impact model (ISO 31000), taking into account data protection, availability and business impact. The assessment is carried out and documented before a supplier is taken into use, and critical suppliers are approved by management.
Do you place security requirements on your suppliers in contracts?Supply chainNIS2
Yes. We place security requirements on suppliers in contracts, and the requirements are tightened in step with the risk the service entails, for example requirements on encryption, redundancy and contingency plans. We also require suppliers to have control of their own supply chain and to keep their staff trained in accordance with NIS2. The framework also contains binding rules for data transfer that govern which data may be stored where, regardless of what the other parts of the assessment show.
Have you carried out an actual review of your suppliers, or is it just a policy?Supply chain
We have carried out and documented a due diligence review of our critical and essential suppliers, and we do so continuously, at least annually. The review assesses the suppliers' security maturity against recognised standards such as ISO/IEC 27001 and SOC 2 Type II, seeks evidence of effective processes for incident reporting, vulnerability management and continuity, and analyses financial stability. Where a supplier lacks formal certification, we assess compensating controls and make a documented, risk-based decision.