Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • How do you work with physical security on an ongoing basis?Physical security & data centers

    Physical security is managed on an ongoing basis. Employees are trained in physical security procedures and reporting paths, physical and environmental protective measures are reviewed regularly, and access permissions are reviewed and revoked when needed, particularly after staff changes. There are documented plans for how physical security incidents are to be handled, for example break-in attempts, unauthorized access, fire or power outage, and the plans are exercised regularly together with the data center operators.

  • How do you ensure security in your supply chain?Supply chainNIS2

    We are part of a supply chain and apply a continuous, documented and risk-based review of our suppliers, in line with the requirements on supply chain security in Cybersäkerhetslagen (NIS2). New suppliers are reviewed and approved before they are taken into use, and our critical and essential suppliers are followed up annually as well as upon noted deviations. A summary or certificate regarding the supplier review can be shared on request.

  • Can you give concrete examples of how you secure the supply chain?Supply chainNIS2Digital sovereignty

    Yes. Our fiber infrastructure is provided in part via Stokab, which is covered by the City of Stockholm's central guidelines and monitored operationally by CERT Stockholm. Our CDN is delivered by Varnish Software as a fully European service with a control plane in France, isolated from foreign legislation such as the CLOUD Act. Throughout, we prioritize suppliers within the EU/EEA and services that are not exposed to foreign jurisdiction.

  • How do you assess new suppliers before engaging them?Supply chainNIS2

    We apply a structured framework for supplier risk assessment in two steps. In the first step we assess the supplier as a whole - security maturity (for example ISO/IEC 27001 certification or an ISAE 3000 report), financial stability and how they in turn manage their own subcontractors. The outcome is approved, escalation for deeper review or a stop. In the second step we assess the specific service's risk according to a likelihood and impact model (ISO 31000), taking into account data protection, availability and business impact. The assessment is carried out and documented before a supplier is taken into use, and critical suppliers are approved by management.

  • Do you place security requirements on your suppliers in contracts?Supply chainNIS2

    Yes. We place security requirements on suppliers in contracts, and the requirements are tightened in step with the risk the service entails, for example requirements on encryption, redundancy and contingency plans. We also require suppliers to have control of their own supply chain and to keep their staff trained in accordance with NIS2. The framework also contains binding rules for data transfer that govern which data may be stored where, regardless of what the other parts of the assessment show.

  • Have you carried out an actual review of your suppliers, or is it just a policy?Supply chain

    We have carried out and documented a due diligence review of our critical and essential suppliers, and we do so continuously, at least annually. The review assesses the suppliers' security maturity against recognized standards such as ISO/IEC 27001 and SOC 2 Type II, seeks evidence of effective processes for incident reporting, vulnerability management and continuity, and analyzes financial stability. Where a supplier lacks formal certification, we assess compensating controls and make a documented, risk-based decision.

  • Do you take into account where data is stored and which jurisdiction applies?Supply chainNIS2GDPR

    Yes. When we assess and select suppliers, we take into account where data is stored physically and which jurisdiction the supplier is subject to, including exposure to foreign legislation such as the CLOUD Act. Where relevant, we prioritize storage within the EU/EEA and suppliers that offer European data sovereignty.

  • Governance of suppliers' service deliverySupply chain

    We have service level agreements with suppliers and measure the fulfillment of their services.

  • Management of changes in third-party servicesSupply chain

    Changes in supplier services are handled based on how critical the affected systems and processes are, and form the basis for reassessment of risks.

  • Independent review of subcontractorsSupply chain

    Controls, policies and procedures for information security are reviewed independently at planned intervals or upon material changes, with a focus on critical and essential suppliers.

  • Do you have a Code of Conduct?Business ethics & responsibility

    Yes. Our Code of Conduct guides how we act and is based on respect for human rights and international labor standards. We do not accept any form of child labour, forced labour, discrimination or harassment, and we apply zero tolerance toward bribery and corruption as well as clear rules on conflicts of interest. The code also covers our business partners and subcontractors, and compliance is followed up on an ongoing basis.

  • Do you have a whistleblower function?Business ethics & responsibility

    Yes. We have a whistleblower service via an external, approved platform with a secure channel for anonymously reporting suspected irregularities, ethical breaches or other serious misconduct. Cases received are taken by an independent recipient at board level, handled confidentially and investigated promptly, and anyone who reports in good faith is protected against reprisals. The service is open to employees, consultants and others who work with us.

  • How do you work as a responsible employer?Business ethics & responsibility

    We work for an inclusive and respectful workplace with equal rights, opportunities and pay regardless of, among other things, sex, gender identity, ethnicity, religion, disability, sexual orientation or age, and we have zero tolerance toward discrimination, harassment and victimization. We carry out systematic work environment management for a safe and healthy work environment.

  • Confidentiality agreementsBusiness ethics & responsibility

    The need for confidentiality and non-disclosure agreements is determined and documented regularly based on the organization's need for information protection, and agreements are entered into where required.

  • Terms of employmentBusiness ethics & responsibility

    Agreements with employees and consultants state their and the organization's responsibility for integrity, information security and confidentiality.

  • Disciplinary processBusiness ethics & responsibility

    There is a formal and communicated disciplinary process to take action against employees who have committed a breach.

  • How do you govern your use of AI?Responsible AIAI Act

    We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).

  • Can we build and run AI applications securely with you?Responsible AIDigital sovereignty

    Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaSand Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.

  • Can our data be used to train AI models?Responsible AIAI Act

    No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.

  • How do you relate to the EU AI Act?Responsible AIAI Act

    The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.