Trust Center
Answers to common questions about security, compliance, operations, and how we handle your data.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Customer data is stored in Swedish data centers.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do you take into account where data is stored and which jurisdiction applies?Supply chainNIS2GDPR
Yes. When we assess and select suppliers, we take into account where data is stored physically and which jurisdiction the supplier is subject to, including exposure to foreign legislation such as the CLOUD Act. Where relevant, we prioritise storage within the EU/EEA and suppliers that offer European data sovereignty.
Governance of suppliers' service deliverySupply chain
We have service level agreements with suppliers and measure the fulfilment of their services.
Management of changes in third-party servicesSupply chain
Changes in supplier services are handled based on how critical the affected systems and processes are, and form the basis for reassessment of risks.
Independent review of subcontractorsSupply chain
Controls, policies and procedures for information security are reviewed independently at planned intervals or upon material changes, with a focus on critical and essential suppliers.
Do you have a Code of Conduct?Business ethics & responsibility
Yes. Our Code of Conduct guides how we act and is based on respect for human rights and international labour standards. We do not accept any form of child labour, forced labour, discrimination or harassment, and we apply zero tolerance towards bribery and corruption as well as clear rules on conflicts of interest. The code also covers our business partners and subcontractors, and compliance is followed up on an ongoing basis.
Do you have a whistleblower function?Business ethics & responsibility
Yes. We have a whistleblower service via an external, approved platform with a secure channel for anonymously reporting suspected irregularities, ethical breaches or other serious misconduct. Cases received are taken by an independent recipient at board level, handled confidentially and investigated promptly, and anyone who reports in good faith is protected against reprisals. The service is open to employees, consultants and others who work with us.
How do you work as a responsible employer?Business ethics & responsibility
We work for an inclusive and respectful workplace with equal rights, opportunities and pay regardless of, among other things, sex, gender identity, ethnicity, religion, disability, sexual orientation or age, and we have zero tolerance towards discrimination, harassment and victimisation. We carry out systematic work environment management for a safe and healthy work environment.
Confidentiality agreementsBusiness ethics & responsibility
The need for confidentiality and non-disclosure agreements is determined and documented regularly based on the organisation's need for information protection, and agreements are entered into where required.
Terms of employmentBusiness ethics & responsibility
Agreements with employees and consultants state their and the organisation's responsibility for integrity, information security and confidentiality.
Disciplinary processBusiness ethics & responsibility
There is a formal and communicated disciplinary process to take action against employees who have committed a breach.
How do you govern your use of AI?Responsible AIAI Act
We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).
Can we build and run AI applications securely with you?Responsible AIDigital sovereignty
Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.
Can our data be used to train AI models?Responsible AIAI Act
No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localisation, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.
How do you relate to the EU AI Act?Responsible AIAI Act
The EU AI Act (2024/1689) sets a harmonised framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.
Are you environmentally certified?Sustainability & environment
Yes. We are certified to ISO 14001:2015 and work systematically to reduce our environmental impact, with recurring external audits of the environmental management system.
What electricity powers your data centers?Sustainability & environment
Our data centers and our offices are powered exclusively by 100% renewable electricity, and this has been a fundamental prerequisite for our delivery since the start. Through our environmental management system, certified to ISO 14001:2015, we place requirements on our data center suppliers to ensure renewable electricity supply.
Are you a verified green cloud provider?Sustainability & environment
Yes. We are verified as a green cloud provider by The Green Web Foundation, which means that the electricity powering our platform comes from renewable energy sources. The verification confirms that our infrastructure runs without fossil energy.
How do you help us build energy-efficiently?Sustainability & environment
Where we can have the most influence is your choice of architecture and products - energy consumption can differ tenfold or more depending on how a solution is built. We build the platform to share resources efficiently and are happy to help design your solution energy-efficiently.
What happens to end-of-life hardware?Sustainability & environment
End-of-life hardware is handled securely. Hard drives and other storage media are sanitised or destroyed so that data cannot be reconstructed, and other equipment is recycled or reused where possible and security-wise justifiable.
What energy and sustainability metrics do your data centers have?Sustainability & environment
We measure and follow up energy efficiency and environmental impact in our data centers in the Stockholm region according to ISO/IEC 30134. PUE (Power Usage Effectiveness) averages 1.45 for our three data centers, which is in line with industry practice for established data centers. REF (Renewable Energy Factor) is 100%, all electricity powering the facilities comes from renewable energy sources. One of our three data centers recovers surplus heat into district heating. WUE (Water Usage Effectiveness) is 0.95 for two of the data centers, and the third is assessed to be at a corresponding level.