Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do we as a customer have the right to audit you?NIS2GDPRDORA
Yes, the right to audit follows from your agreements with us and can arise in several ways. If we process personal data on your behalf, our Data Processing Agreement (DPA) gives you the right to conduct annual audits of the processing covered by the agreement, yourself or through a third party you appoint, at your own expense (GDPR Article 28.3(h)). For customers covered by DORA, audit and access rights are regulated in a dedicated contract addendum, and for those of you with supplier oversight requirements under Cybersäkerhetslagen (NIS2), we provide the documentation you need. In many cases, the need can also be met by our certificates and summaries of completed security reviews, which can be shared on request. Contact us and we will help you plan an audit.
How do we dispute an invoice or claim SLA compensation?Service delivery & SLA
If you believe an invoice is incorrect, create a support ticket in our support portal (support.elastx.se) with priority Normal and we will investigate. The same applies if you believe we have not met our support SLA or availability SLA: create a support ticket with priority Normal, and we will investigate the event and handle any compensation in the ticket. The compensation levels are set out in the availability SLA.
Can we get metrics for our own environmental impact?Sustainability & environment
Yes. We can produce metrics for your environmental impact - energy consumption and carbon dioxide emissions - based on your resource usage in our OpenStack IaaS. You request such a data extract via a support ticket, and the data can be used in, for example, your sustainability reporting or supplier follow-up.
Do your staff have access to our data?Data protection & encryptionGDPR
No, not in day-to-day operations. Our staff work on the underlying platform without visibility into your data content, and do not have access to your instances or applications. Access to your environment takes place only if you explicitly request and approve it, for example in a support ticket, and is then limited to the specific need. All privileged access to the infrastructure uses personal accounts, requires multi-factor authentication and is logged.
Who owns our data?Digital sovereignty & independenceDigital sovereignty
You own your data, always. We make no claims to it and do not use it for our own purposes. You can export your data programmatically via open standard APIs at any time, not just ahead of a termination, and we apply no mandatory lock-in periods. When a service is decommissioned, or upon your written request, your data is securely erased.
Which certifications does Elastx hold?Certifications & audits
We are certified toISO/IEC 27001:2022for information security and apply all of the standard's controls across our entire operation. We also hold ISO/IEC 27017 (cloud security) and ISO/IEC 27018 (protection of personal data in the cloud), as well asISO 14001:2015(environmental management). The certificates are available for download.
How often is Elastx audited externally and can we access the reports?Certifications & audits
We carry out an external audit of our ISO/IEC 27001 and ISO 14001 management systems once a year, and security reviews and penetration tests are conducted recurrently throughout the year. Over the past year this has included an external audit of ISO/IEC 27001:2022 as well as security reviews of our Cloud Console with associated APIs. Our certificates are available for download, and summaries can be shared with customers on request.
Do you carry out internal audits?Certifications & audits
Yes. We perform an internal audit once a year according to an audit plan. Management appoints two employees who review evidence and interview the owners of the controls. The outcome is reported to management and any deviations are logged for remediation. Independent assurance of our management system additionally comes from our external ISAE 3000 audit and our ISO certifications.
Do you carry out technical compliance reviews?Certifications & audits
Yes. Information systems are reviewed regularly against our information security policies and standards, both through automated checking of configuration and secure baselines and through recurring technical audits, for example vulnerability assessments and penetration tests. Deviations are documented and tracked to remediation.
What does digital sovereignty mean at Elastx?Digital sovereignty & independenceDigital sovereignty
Our foundation is fully Swedish digital infrastructure under exclusively Swedish and European jurisdiction. Elastx is a Swedish company with Swedish owners and background-checked staff who are EU citizens, and your data on the platform stays within Sweden's borders. We own and operate our own hardware, and only Elastx staff administer the platform. We build on open standards and open source. Because we have no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA or equivalent legislation in other countries. This gives you control over where your data is stored, who can access it, and the ability to move it whenever you want.
Are your services free from foreign legislation such as the CLOUD Act?Digital sovereignty & independenceGDPRDigital sovereignty
Yes. As a Swedish company with no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA nor equivalent legislation in other countries.
The applicability of legislation such as the US CLOUD Act depends on where the service provider is established, not solely on where its data centers are located. Choosing an EU data centre operated by a non-EU provider does not, by itself, remove the legal implications of third-country legislation.
Customer data on the Elastx Cloud Platform is governed by Swedish and EU legislation. Furthermore, GDPR Article 48 states that judgments or administrative decisions from third countries cannot, on their own, serve as a legal basis for transferring personal data unless supported by an applicable international agreement.
Learn more about how we support digital sovereigntyand why Elastx is part of the EuroStack movement.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.
How does Elastx work with compliance on an ongoing basis?Governance & compliance
We have a Compliance team that meets every two weeks and on which management is represented. The work is structured and traceable, from requirement through policy and instruction to how the control works in practice. Each control has a designated owner who is responsible for the entire chain and who is interviewed during internal and external reviews.
How is management involved in information security?Governance & complianceNIS2
Management reviews our management system quarterly to assess that it is relevant and effective. The review is based on any events since the previous occasion, including risks, deviations and incidents. The security work we carry out and our material risks are also reported at board level.
How do you handle deviations?Governance & compliance
Deviations are captured systematically through internal and external audits, technical compliance reviews and continuously in day-to-day work. Each deviation is logged centrally for traceability and evaluated to determine the root cause. It is assigned to a control or process owner who is responsible for developing and implementing a remediation, and progress is followed up regularly and reported to management at the quarterly reviews.
How do you ensure security awareness among staff?Governance & complianceNIS2AI Act
All staff, including management, undergo mandatory and recurring training in information security, data protection and responsible use of AI, and new staff are trained before system access is granted. We reinforce the security culture continuously, including with recurring phishing simulations, external penetration tests and ongoing internal sharing of vulnerability information. We contractually require subcontractors to maintain strict security awareness among their own staff and to comply with relevant regulations and security requirements.
How do you govern the IT strategy?Governance & compliance
The board and management set the IT strategy based on business objectives, security requirements and industry standards, and follow up and reassess it regularly so that services are delivered securely both now and going forward. Customers can influence the prioritization of new services and features through dialogue with us.
How do you separate duties and responsibilities?Governance & compliance
Duties and areas of responsibility that are incompatible, that is, that should not be performed by one and the same person, are kept separate. One example is that the person who performs a sensitive action should not also be able to approve it alone. This reduces the risk of unauthorized or accidental changes and of misuse of assets.
Documented structure for policies, processes and proceduresGovernance & compliance
Policies are defined, documented and communicated to meet business requirements and to clarify responsibility for working methods, processes and procedures. We use a GRC tool to document, structure, communicate and follow up the framework.
How are roles and responsibilities for information security allocated?Governance & compliance
Security work is systematically organized with clearly defined and documented roles and responsibilities. Each control and security area has a designated owner, the work is coordinated by our Compliance group, and ultimate responsibility rests with the CEO. This ensures that tasks do not fall through the cracks and that it is always clear who is accountable for a given matter.
Which information security policies do you have?Governance & compliance
We have a coherent framework of policies that are approved by management and communicated to employees and relevant external parties. It includes, among others, an overarching information security policy, a cloud security policy (ISO/IEC 27017), an access control policy, a vulnerability management policy, a backup and continuity policy, a secure development policy and a policy for AI ethics and AI governance. The public version of the information security policy is available for download.
How often are your information security policies reviewed?Governance & compliance
The policies are reviewed at least once a year and additionally upon material changes, for example new threats, new legislation or major changes in the business. Each policy has an owner responsible for the review, and changes are approved by management before they are published.
What do your documented operating procedures cover?Governance & compliance
Recurring operational activities are documented as procedures and made available to those who need them. This applies, for example, to operation and monitoring of the platform, backup and recovery, patching and change management, and incident handling. The documentation ensures that work is carried out uniformly and securely regardless of individuals.
Management responsibilityGovernance & compliance
Management makes clear the requirements regarding the Code of Conduct, integrity and information security through clear communication, and employees and consultants periodically confirm that they have read and understood applicable policies and procedures. All staff are background-checked, and the check is repeated annually for roles with access to customer data.
Are you covered by Cybersäkerhetslagen (NIS2)?Regulatory complianceNIS2
Yes. We are covered by Cybersäkerhetslagen (the Swedish Cybersecurity Act, 2025:1506), which implements the NIS2 Directive and entered into force on 15 January 2026. We are covered as a provider of essential and critical infrastructure, partly through the transposition of the CER Directive, and as a provider of cloud services, data center services and CDN. PTS (the Swedish Post and Telecom Authority) is the supervisory authority for digital infrastructure, and Myndigheten för Civilt Försvar (MCF, the Swedish Civil Defence Agency) is the national coordinating authority and recipient of incident reports. We meet the law's requirements regarding security measures, management responsibility, training and incident reporting. Oversight of subcontractors and the supply chain is a central part of the requirements.
Can you enter into security protection agreements (SUA)?Regulatory compliance
For security-sensitive customers, for example in the public sector, we can where needed enter into a säkerhetsskyddsavtal (SUA, a Security Protection Agreement) under säkerhetsskyddslagen (the Swedish Protective Security Act, 2018:585). Such an agreement is notified to Säkerhetspolisen (the Swedish Security Service).
Compliance processRegulatory compliance
We have an organization and monitoring in place to stay in control of new or amended regulations, laws and standards relevant to the services. We maintain a legal register that tracks compliance requirements, including GDPR, Swedish security laws, NIS2, DORA and contractual requirements, and we keep our procedures and controls updated against it.
Do you meet accessibility requirements (WCAG and EN 301 549)?Regulatory compliance
We follow the accessibility requirements under the EU Accessibility Directive (in Sweden, lagen om vissa produkters och tjänsters tillgänglighet, 2023:254) for those of our digital interfaces that are in scope, primarily our public websites and self-service interfaces. We work toward the guidelines in WCAG and the European standard EN 301 549.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.
Supply chain securityRegulatory complianceNIS2
We have controls for our direct suppliers and service providers, that is, those with whom we have a contractual relationship, to ensure that their services meet our security requirements. The requirements are adapted to how critical the supplier is to our delivery.
Personnel securityRegulatory complianceNIS2
We ensure that staff who handle sensitive information and critical systems meet high security requirements. Staff are background-checked before employment, and permissions are granted, reviewed and revoked throughout employment according to the principle of least privilege and zero trust, with multi-factor authentication and clearly defined roles and responsibilities.
Do you have cyber insurance?Risk management
Yes. We have cyber insurance that covers, among other things, liability, business interruption, data recovery and costs associated with a cyber or information incident, including forensic investigation, handling of personal data breaches and access to incident response around the clock. The cover applies globally and complements our technical and organizational security measures.
Governance of risk controlRisk management
The risk assessment process identifies, assesses and manages risks that affect the organization's ability to reach its objectives. In practice, this means we carry out contextual risk assessments of technical vulnerabilities based on our unique environment and apply a framework according to ISO 31000 to proactively evaluate and govern risks in our supply chain.
Assessment of information security risksRisk managementNIS2
Information security risks are automatically given higher priority in the process so that resolution or reduction is handled promptly. In our operational work, this means that detected vulnerabilities are immediately risk-assessed based on system exposure and impact on critical services, which triggers timeframes for patching and mitigating measures.
Response to information security risksRisk managementNIS2
Risks relating to information security and integrity are reported according to the standard process. Particularly sensitive risks are reported to a small number of designated individuals. In practice, this means that standard risks are tracked through our internal ticketing systems, while critical or confidential matters are escalated directly to the management team or handled via our protected whistleblower channel to ensure confidentiality and immediate action.
How do you govern access and permissions?Access & authorizationNIS2
We apply the principle of least privilege, so that each employee receives only the rights required for their role, and administrators have unique, personal accounts. Access is protected in several layers, including with multi-factor authentication and hardware-based security keys for sensitive access. Permissions are reviewed regularly and adjusted or removed upon a change in or termination of employment.
Is multi-factor authentication required for administrative access to the production environment?Access & authorizationNIS2
Yes. All administrative access to the production environment goes through secured paths and requires multi-factor authentication. For administrative accounts, hardware-based MFA according to FIDO2/WebAuthn is required, and administrators are equipped with a physical hardware token as the primary factor. We also support time-based one-time passwords (TOTP).
Do you background-check your staff?Access & authorization
Yes. A background check is carried out on all final candidates before an employment decision is made, and the check is repeated annually for all roles with access to customer data. The checks are carried out in cooperation with an external certified partner and include, among other things, verification of identity, criminal records and court judgments, and financial situation, drawn from public registers or from authorized providers.
How are your employees' computers and devices protected?Access & authorization
Company devices are subject to encryption, central device management and endpoint security monitoring (EDR), with a local firewall that blocks inbound traffic and automatic updates. We apply clean desk and clean screen rules as well as mandatory automatic screen locking. Devices that can be used to administer customer environments or access customer data are subject to stricter requirements than other devices. Employees are given access only to the systems they have been explicitly authorized for.
Mobile device policyAccess & authorization
A policy and supporting security measures address the risks that the use of mobile devices entails, for example encryption, screen lock and the ability to wipe a device remotely if it is lost or stolen. Devices are additionally protected with extended endpoint protection (XDR) that continuously monitors and alerts on suspicious activity and behavior.
How do remote work and access to the production environment work?Access & authorization
All access to the production environment goes through secured paths and requires multi-factor authentication. There are three ways in: a Corporate Proxy, which is the general path for daily access for most employees; a VPN path for maintenance that requires access to multiple systems or to systems not reachable via the proxy; and a separate out-of-band VPN (OOB VPN) used during disaster recovery. Information handled and stored during remote work is additionally protected by policy and technical security measures.
Responsibility upon terminated or changed employmentAccess & authorization
Information security responsibilities that apply after terminated or changed employment are defined, communicated and enforced. This includes, among other things, that confidentiality and non-disclosure undertakings remain in force, that assets are returned and that access is revoked, so that the protection of information is maintained even after the role has changed or ended.
How are user permissions granted and revoked?Access & authorization
We have a formal process for the entire lifecycle of user accounts. When a person joins, the account is registered and granted the permissions the role requires according to the principle of least privilege. Upon a change of role the permissions are adjusted, and when an employment or contract ends the account is deregistered and access is revoked immediately, including SSH keys and VPN credentials, while confidentiality undertakings remain. The process covers all user types and all systems and services, and permissions are reviewed regularly.
How do you handle privileged (administrative) permissions?Access & authorization
Privileged access rights, that is, elevated administrative permissions, are handled more strictly than ordinary user access. They are granted restrictively and only to named, personal accounts, limited to what the role requires and followed up specifically. Administrative access to the production environment always requires multi-factor authentication.
How is secret authentication information (for example passwords and keys) handled?Access & authorization
The assignment and handling of secret authentication information, such as passwords, API keys and certificates, is governed by a formal process. Such information is distributed securely, stored protected and rotated when needed, and secrets are never stored in plaintext in source code. We use a password management system that maintains good password quality.
Is the environment monitored around the clock?Logging & monitoringNIS2
Yes. We monitor the platform's operation and network traffic around the clock, year-round (24/7/365), with automatic alerts going directly to our engineers. The real-time monitoring tracks platform health, security metrics and network traffic and alerts on anomalies, and central dashboards watch for, among other things, unauthorized access attempts and abnormal traffic patterns. Operational and security logs are collected centrally, and we work continuously to strengthen our ability to detect security events.
Is privileged access to the infrastructure logged?Logging & monitoring
Yes. We keep audit logs for all infrastructure, which includes logins and privileged access to underlying systems. The logs are collected centrally and retained for an extended period, and relevant extracts can be provided on request - for example in connection with a security or personal data incident.
How do you detect capacity shortages before they affect the service?Logging & monitoring
We monitor capacity continuously and have automatic thresholds in the data centers for, among other things, disk, CPU, memory (RAM) and graphics cards (GPU) that create a ticket when exceeded, so that capacity shortages can be addressed in time.
Clock synchronizationLogging & monitoring
The clocks in all relevant systems are synchronized to a common, traceable reference time source. We synchronize to ntp.se, the Swedish standard time service operated by RISE and Netnod, which makes logs comparable across systems and enables accurate forensics.
How do you work with vulnerabilities and patching?Vulnerability management & patchingNIS2
We have a central process and policy for vulnerability management. We carry out regular vulnerability scanning, rank vulnerabilities by risk and track them to remediation according to defined service levels (SLA). Container images are also scanned automatically in the build pipeline, and patching is carried out regularly with priority on high-risk systems.
How do you harden the systems?Vulnerability management & patchingNIS2
We harden physical and logical components (for example servers, virtual machines and service protocols) according to established hardening standards (including CIS Benchmarks), and the configuration is managed as code so that a secure baseline is maintained.
How do I report a vulnerability to you?Vulnerability management & patchingNIS2
We have an established process for responsible vulnerability disclosure. If you or a security researcher discovers a vulnerability, it can be reported confidentially to compliance@elastx.se. We receive, assess and remediate reported vulnerabilities according to our vulnerability and patch management process.
How do you protect against malicious code?Vulnerability management & patchingNIS2
We have multi-layered protection against malicious code at the hypervisor, orchestration and endpoint levels. All company devices have endpoint-level security monitoring (EDR), and in selected environments intrusion detection continuously monitors container runtimes. The protection is combined with recurring security training and awareness among staff.
How do you keep different customers' environments separate?Network & isolationNIS2
We separate different customers' environments (tenants) logically using, among other things, VLAN, VXLAN and software-defined networking (SDN), and the platform's administration layer is kept strictly isolated from customers' runtime environments. The logical segmentation prevents lateral movement and keeps customer workloads separate.
How do you protect against DDoS and network attacks?Network & isolationNIS2
DDoS protection at the network level (L3/L4) against volumetric attacks is included in the platform service at no extra cost, is always active and requires no configuration. In addition, we offer a web application firewall (WAF) and threat intelligence as options, together with secure network zoning that blocks known malicious sources. We also offer a CDN service that can offload and protect web traffic.
How do you govern and secure your network services?Network & isolation
Networks are managed, monitored and controlled to protect the information in systems and services. Network traffic is segmented and governed on the principle of blocking what is not explicitly allowed, and different security zones are kept separate. For all network services, both in-house and outsourced, security mechanisms, service levels and requirements are defined, and these are included in contracts.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
Our role depends on the personal data processing in question. For your customer data and workloads on the platform, we act as a data processor, and we guarantee technical and organizational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For administrative data relating to our own customer relationship with you, for example contact details and login logs for your contract administration, we act as a data controller. For GDPR matters you can reach us at gdpr@elastx.se.
Is data encrypted at rest?Data protection & encryptionNIS2GDPR
Yes. We have a policy and procedures for encryption, and all disks in our environment are encrypted with strong encryption (AES-256). Physical servers use self-encrypting drives (SED) according to TCG Opal with pre-boot authentication, so that a physically stolen storage medium does not grant access to data.
How is data protected in transit?Data protection & encryptionNIS2GDPR
Data in transit is protected with TLS (versions 1.2 and 1.3) using strong encryption (AES-256) and with SSH key pairs. For managed database services, CA certificates are provided so that you can verify and encrypt your client connections.
Where is our data stored?Data protection & encryptionGDPRDigital sovereignty
As a data processor and an ISO/IEC 27018-certified company, we store data within Sweden. This means the information is kept within the EU/EEA and out of reach of foreign legislation such as the CLOUD Act. Personal data is processed only on a lawful basis and is securely erased when it is no longer needed.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
Do you use sub-processors?Data protection & encryptionGDPR
No, not for your data on the platform. Your data and workloads are stored in Sweden and processed by us as a processor, without the use of sub-processors. The only sub-processors we use relate to administrative support services such as invoicing and dispatch. These concern data about our customer relationship with you, not your data on the platform. Such processing is governed by a Data Processing Agreement (DPA) under GDPR Article 28. We verify that sub-processor agreements are in place and notify you before we add or change a data center or sub-processor. Any access for subcontractors to your data on the platform takes place only after your approval.
What happens to our data when the contract ends?Data protection & encryptionGDPRDigital sovereignty
You can export your data ahead of a termination. Upon decommissioning of a service or virtual machine, or upon written request, your data and associated infrastructure are securely erased. Storage rests on self-encrypting drives, which enables cryptographic erasure in line with recognized standards for data sanitization. Logs linked to the processing of personal data are thereafter retained only for as long as the Data Processing Agreement (DPA) and applicable legal requirements demand.
How do you help us with data subjects' rights?Data protection & encryptionGDPR
As a data processor, we assist you as the data controller in responding to requests from data subjects - for example access, rectification, erasure, restriction and data portability - in accordance with the Data Processing Agreement (DPA). The platform gives you technical means to find, export and erase personal data in your own environments.
Which technical and organisational measures do you apply to protect personal data?Data protection & encryptionGDPR
Our Data Processing Agreement (DPA) specifies the technical and organizational measures we apply. Organizationally, we work according to ISO/IEC 27001 with role-based access, mandatory onboarding and offboarding procedures and personal confidentiality undertakings for all staff. Technically, data is encrypted at rest with AES-256 and in transit with TLS 1.2 and 1.3, and the infrastructure is continuously monitored with vulnerability scanning, DDoS protection and central tamper-resistant logging. More detail is available under the respective topic in the FAQ.
How do you ensure that the Data Processing Agreements (DPA) are up to date?Data protection & encryptionGDPR
Our Data Processing Agreement and associated instructions are kept under continuous version control. Revisions prompted by changed legislation, new regulatory requirements or updated security measures are documented in a change history, so that you can always see what applies and why it was changed.
What does your responsibility as a data processor cover?Data protection & encryptionGDPR
As a data processor, we process personal data solely according to your written instructions and without insight into the actual data content. We are responsible for the security, availability and resilience of the underlying cloud infrastructure, including physical security in the data centers, vulnerability protection at the platform level and support around the clock. You are responsible for your application, your credentials and the configuration of your own backups. A full allocation of responsibility is available in the Data Processing Agreement and in our cloud security policy (ISO/IEC 27017).
How do you develop secure software?Secure developmentNIS2
Our in-house development follows a secure development procedure. Security requirements are defined early, code undergoes mandatory peer review and automatic static security analysis (SAST) of container images, and no secrets or keys are stored in source code. The source code resides in access-controlled repositories with MFA, where permissions are governed by developer role and branch protection is applied. Build and deployment pipelines are automated, and changes are tested in isolated test environments before they reach production. No real customer data or personal data is used in development or test environments.
Do you contribute to the open projects you build on?Secure development
Yes. We are active and contribute continuously to OpenStack and Kubernetes, the projects we ourselves build on and use. Our contributions concern, among other things, OpenStack (compute, identity and networking) and Kubernetes, including Cluster API. Other contributions occur more sporadically. This gives us early insight into security updates and the ability to influence upcoming standards.
How do you govern system changes during development?Secure development
Changes to systems during the development lifecycle are governed by formal change control procedures. This means, for example, that changes are documented and approved, that code is peer reviewed before merging, that automated tests are run and that there are documented procedures to roll back if something goes wrong.
How do you engineer secure systems?Secure development
Our in-house development is based on the principle of Defense in Depth across all technical layers and on established security guidelines, including the OWASP Top 10. We apply secure coding principles, for example parameterized database queries against SQL injection and context-based escaping against scripting attacks (XSS), and the source code is scanned automatically in our build pipelines. Configuration is managed as code from reviewed, immutable baselines, and sessions are protected with secure cookie settings.
Secure development environmentSecure development
Secure development environments for system development and integration are established and protected throughout the development lifecycle. Business-critical applications are reviewed and tested carefully after platform changes, so that changes to operating platforms do not adversely affect the business or security.
Do you support Single Sign-On (SSO)?Access & authorization
Yes. Our platform supports SSO login via the industry standards OpenID Connect (OIDC) and SAML2, allowing you to integrate with your own identity provider (IdP) and manage access centrally according to your own policies. Users are identified by unique user IDs decoupled from their email addresses. Multi-factor authentication is supported, and sessions automatically end after a period of inactivity.
How do you handle changes in the environment?Change management
Every change follows our policies, instructions and SLAs. The greater the risk a change may entail, the higher the requirements we place on risk assessment, planning and approval. Changes are tested before and after implementation and have documented rollback procedures. We inform customers via our status page and announce changes according to our SLAs.
How do you give notice of planned maintenance?Change management
We announce planned maintenance windows at least ten days in advance on our status page, and emergency maintenance as soon as possible, sometimes with shorter notice. Changes affecting a specific service are also published on that service's announcement page in our documentation (docs.elastx.cloud), and for material changes affecting a service you use we may additionally inform your authorized contacts by email. We also notify you in the event of elevated risk. Planned maintenance windows are not covered by the availability SLA.
How do you handle incidents?Incident managementNIS2
We deliver services around the clock and therefore have troubleshooting and incident handling around the clock, year-round, with continuous monitoring of the platform and alarm reception. When an event is identified it is classified and prioritized based on severity and impact on the services, and it is escalated according to defined procedures to the right technical expertise. A serious problem can be escalated to a critical incident, which activates a dedicated crisis management team with a mandate to make rapid decisions. After a remediated incident, a root cause analysis is carried out to capture permanent improvements in the platform and our working methods. Our documented incident management procedure can be shared with customers on request.
How are we informed during an ongoing incident?Incident management
We keep customers informed via our status page during an ongoing problem. When a problem is resolved we send an incident report to affected customers on request. Our procedures include the incident reporting requirements in Cybersäkerhetslagen (NIS2).
How quickly do you inform us of an incident or personal data breach?Incident managementNIS2GDPRDORA
In the event of an incident affecting you, we inform you without undue delay, and at the latest within 24 hours of becoming aware, so that you have time to meet your own obligations. In the event of a significant incident, we follow Cybersäkerhetslagen (NIS2) in reporting to the competent authority (MCF): early warning within 24 hours, an incident report within 72 hours and a final report no later than one month after the incident report.
Responsibility and procedures in the event of incidentsIncident management
Management responsibility and procedures are established for a fast, effective and orderly response to privacy and information security incidents. The incident team works from predefined playbooks for, among other things, ransomware, DDoS and data breaches, and immutable logging secures evidence for forensics.
How are security events and threats reported internally?Incident management
Security events and suspected threats are reported through established internal channels as quickly as possible, so that they can be assessed and, where needed, escalated without delay. All employees and consultants have a responsibility to report, and the procedure is part of our security training.
How do you assess whether an event is an incident?Incident management
Reported security and privacy events are assessed in a structured way and classified according to defined criteria, including impact on confidentiality, integrity and availability (the CIA triad), how many systems or customers are affected, whether personal data is involved and whether the event may trigger a reporting obligation. Based on the assessment, a decision is made on whether the event should be handled as an incident and what severity it is assigned.
Learning from incidentsIncident management
After an incident we conduct a thorough review (retro) and capture lessons that we share internally and translate into improved procedures and controls. How thorough the review is depends on the scope of the incident, and incident reports are shared with customers who request them.
Do you test your continuity capability?Continuity & recoveryNIS2DORA
Yes. We exercise our continuity plan (Business Continuity Plan, BCP) through recurring, full-scale continuity exercises as part of our ISO/IEC 27001 work. The exercises are typically unannounced for the majority of the organization in order to give a realistic result, and they test the crisis management team's decision-making, the technical containment procedures and our communication channels under high pressure.
What did this year's continuity exercise show?Continuity & recovery
Exercises confirm our crisis preparedness and technical resilience. The crisis management team establishes structure quickly, and we can if needed isolate an entire availability zone to protect customer environments in the other zones. Identified areas for improvement are followed up in a structured way and managed over time, including clearer crisis mandates, a dedicated communications lead, more formalized procedures for endurance during prolonged incidents and improved traceability and reporting in line with Cybersäkerhetslagen (NIS2) and DORA.
How is the platform built for redundancy and recovery?Continuity & recoveryNIS2DORA
The platform is distributed across three active availability zones in the Stockholm area (STO1, STO2 and STO3), geographically separated so that a physical or environmental disruption in one zone does not take down the service. Services are replicated between the zones for automatic redundancy. For critical backups and logs we offer The Vault- an immutable, ransomware-resistant storage that additionally sits in a separate region around 350 km from the Stockholm area, in a protected underground facility. It is based on Object Lock (WORM - Write Once, Read Many), which means data cannot be changed or deleted during the configured lock period, even if permissions are compromised.
Do you back up our data?Continuity & recoveryNIS2
We back up our own platform, for example configuration and system images, and these backups are created and tested according to a defined backup policy. Backup and any replication of your data is configured and governed by you, with tools in the platform or external tools, based on your wishes and what your contract covers - this gives you full control over what is saved, where and for how long. For immutable storage of critical copies and logs we offer The Vault. Our object storage service stores three copies by default, distributed across three availability zones.
How are the continuity processes implemented and maintained?Continuity & recovery
Procedures and controls to maintain continuity during a disruption are established, documented, implemented and maintained. The continuity and disaster recovery plan contains controls that are verified regularly to ensure that it is valid and effective.
What training does staff receive in crisis management?Continuity & recovery
Staff who are part of the crisis organization receive recurring training and exercises in crisis management, for example in roles and mandates, decision-making under pressure, internal and external communication and the technical containment and recovery procedures. Other staff receive training at an overview level so that everyone knows how to act and where to turn in a crisis.
Which availability levels (SLA) do you offer?Service delivery & SLA
We publish clear availability SLAs per service. Elastx-managed services across multiple availability zones have 99.95% monthly uptime, and compute and storage built redundantly across multiple zones have 99.99%. Redundant services within a single zone have at least 99.9%, single instances without redundancy at least 99.5% and non-redundant connectivity at least 99%. If a level is not met, you may be entitled to financial compensation on your next invoice (10, 30 or 100% depending on the size of the deviation). Planned maintenance windows and force majeure are excluded. Full terms are available in our availability SLA.
What support and response time do you offer?Service delivery & SLA
Support around the clock (24x7) is included in all our services, and we monitor our platform and our services 24x7. The response time is governed by the severity of the case: 15 minutes for business-critical cases (around the clock), 1 hour for high impact, 4 hours during office hours for normal cases and next business day for low priority. Cases are logged and tracked in our support portal, and current operational status is published continuously on our status page. Full terms are available in our support SLA.
Do we receive reports on quality and delivery?Service delivery & SLA
Customer contracts can contain terms on reporting of quality and delivery. Current operational status and availability are published continuously on our status page, and follow-up of service levels (SLA) can be compiled and shared with you according to the contract.
Support deliveryService delivery & SLA
We provide support to customers where cases are classified by priority and severity. The service levels are described in our support SLA.
How do you inventory your assets?Asset management
Assets linked to information and information processing are identified and entered into an inventory that is kept up to date. This covers, for example, physical equipment such as servers, network equipment and storage, but also information assets such as data stores, configurations, source code and documentation. Each asset has a designated owner responsible for classifying it correctly, protecting it in line with its sensitivity and handling it correctly throughout its lifecycle.
Acceptable use of assetsAsset management
All customers, employees and partners are covered by the Elastx Acceptable Use Policy (AUP), which is a binding part of our general terms. The policy expressly prohibits activities that could jeopardise the platform's stability or network security, for example unauthorized port scanning, vulnerability scanning, network sweeps, spam and operation of open proxy servers. We reserve the right to immediately restrict network services or suspend accounts if the rules are breached. Our full policy is available at Acceptable Use Policy.
Disposal of mediaAsset management
Media is disposed of securely according to formal procedures when no longer needed. Storage media is encrypted, which enables cryptographic erasure, and media is sanitized or destroyed in a way that prevents data from being reconstructed before equipment is reused or disposed of. This applies to media both in the data center environment and on employees' work computers.
Physical media in transitAsset management
Our principle is that media containing information does not leave the cage in the data center. Sensitive information should not move outside our secure zones, and in the exceptional cases where media does need to be handled, it is encrypted and the transport takes place with traceability and control of who has handled it.
How is the physical security of your data centers designed?Physical security & data centers
Our data centers are protected in multiple layers based on a risk-based assessment: reinforced building construction, perimeter protection and detection, around-the-clock guarding and CCTV surveillance, and strict access control. External walls, ceilings and floors are of reinforced concrete. Where such an assessment has been made, data halls have been independently assessed to the Swedish Theft Prevention Association's SSF 200 protection class 3. Parts of our data center capacity are classified as protected installations (skyddsobjekt) and staffed with certified protection guards. Physical security at the facility level is independently audited and certified to ISO/IEC 27001 and SOC 2 Type II. Many customers base their procurement on MCF's guidance on physical information security for IT spaces (protection level 3); the facilities are designed and operated so that, on a risk-based assessment, they meet or exceed that guidance. Documentation on individual standards can be shared with customers on request as part of a vendor assessment.
Who has access to the data centers and how is it regulated?Physical security & data centers
Elastx rents locked, video-monitored rooms in high-security data centers (our availability zones). Only background-checked Elastx staff have access, and only after prior notification. Access takes place following manual identity verification, using individual, personal access cards or badges combined with biometric verification, for example fingerprint, and security personnel monitor and control access to the facilities. Detailed visitor logs are kept of everyone who comes and goes, and all access is logged and controlled. Other access requests to our premises are approved by Elastx in advance.
Camera surveillance (CCTV)Physical security & data centers
Data centers, corridors and server halls are monitored around the clock with high-resolution, infrared-capable camera surveillance (CCTV). The system alerts on motion or a person in areas where no one should be, and recordings are stored in encrypted, tamper-resistant archives.
How are the facilities' perimeter and outer protection secured?Physical security & data centers
In our availability zones, the perimeter is protected in several layers: fencing and barriers around the facility, bollards that prevent vehicle access, security lighting at entrances and perimeters, and reinforced doors, locks and splinter-protected glass. Controlled entry and exit points with man-traps prevent unauthorized tailgating, and intrusion alarms watch entrances and sensitive areas, including secure zones such as server rooms.
How are the facilities protected against fire, power outages and environmental threats?Physical security & data centers
Our availability zones are built for operational reliability and protection against environmental threats. Smoke detectors, fire alarms and automatic extinguishing systems handle fire, climate systems maintain optimal temperature and humidity for the equipment, and sensors alert on water leakage or flooding. Power supply is fully redundant and appropriately protected, critical systems are protected by uninterruptible power (UPS), and diesel generators take over during longer outages. Sensitive equipment is protected against electromagnetic interference (EMI).
How are equipment and cables handled in the facilities?Physical security & data centers
Servers and network equipment are placed in locked rooms and, where applicable, in locked cabinets, and network and power cables are protected and concealed to prevent tampering, including at our fiber junction points. Physical equipment is labeled and registered in an asset register so that it can be tracked, linked to an owner and handled securely throughout its lifecycle.
How do you work with physical security on an ongoing basis?Physical security & data centers
Physical security is managed on an ongoing basis. Employees are trained in physical security procedures and reporting paths, physical and environmental protective measures are reviewed regularly, and access permissions are reviewed and revoked when needed, particularly after staff changes. There are documented plans for how physical security incidents are to be handled, for example break-in attempts, unauthorized access, fire or power outage, and the plans are exercised regularly together with the data center operators.
How do you ensure security in your supply chain?Supply chainNIS2
We are part of a supply chain and apply a continuous, documented and risk-based review of our suppliers, in line with the requirements on supply chain security in Cybersäkerhetslagen (NIS2). New suppliers are reviewed and approved before they are taken into use, and our critical and essential suppliers are followed up annually as well as upon noted deviations. A summary or certificate regarding the supplier review can be shared on request.
Can you give concrete examples of how you secure the supply chain?Supply chainNIS2Digital sovereignty
Yes. Our fiber infrastructure is provided in part via Stokab, which is covered by the City of Stockholm's central guidelines and monitored operationally by CERT Stockholm. Our CDN is delivered by Varnish Software as a fully European service with a control plane in France, isolated from foreign legislation such as the CLOUD Act. Throughout, we prioritize suppliers within the EU/EEA and services that are not exposed to foreign jurisdiction.
How do you assess new suppliers before engaging them?Supply chainNIS2
We apply a structured framework for supplier risk assessment in two steps. In the first step we assess the supplier as a whole - security maturity (for example ISO/IEC 27001 certification or an ISAE 3000 report), financial stability and how they in turn manage their own subcontractors. The outcome is approved, escalation for deeper review or a stop. In the second step we assess the specific service's risk according to a likelihood and impact model (ISO 31000), taking into account data protection, availability and business impact. The assessment is carried out and documented before a supplier is taken into use, and critical suppliers are approved by management.
Do you place security requirements on your suppliers in contracts?Supply chainNIS2
Yes. We place security requirements on suppliers in contracts, and the requirements are tightened in step with the risk the service entails, for example requirements on encryption, redundancy and contingency plans. We also require suppliers to have control of their own supply chain and to keep their staff trained in accordance with NIS2. The framework also contains binding rules for data transfer that govern which data may be stored where, regardless of what the other parts of the assessment show.
Have you carried out an actual review of your suppliers, or is it just a policy?Supply chain
We have carried out and documented a due diligence review of our critical and essential suppliers, and we do so continuously, at least annually. The review assesses the suppliers' security maturity against recognized standards such as ISO/IEC 27001 and SOC 2 Type II, seeks evidence of effective processes for incident reporting, vulnerability management and continuity, and analyzes financial stability. Where a supplier lacks formal certification, we assess compensating controls and make a documented, risk-based decision.
Do you take into account where data is stored and which jurisdiction applies?Supply chainNIS2GDPR
Yes. When we assess and select suppliers, we take into account where data is stored physically and which jurisdiction the supplier is subject to, including exposure to foreign legislation such as the CLOUD Act. Where relevant, we prioritize storage within the EU/EEA and suppliers that offer European data sovereignty.
Do you have a Code of Conduct?Business ethics & responsibility
Yes. Our Code of Conduct guides how we act and is based on respect for human rights and international labor standards. We do not accept any form of child labour, forced labour, discrimination or harassment, and we apply zero tolerance toward bribery and corruption as well as clear rules on conflicts of interest. The code also covers our business partners and subcontractors, and compliance is followed up on an ongoing basis.
Do you have a whistleblower function?Business ethics & responsibility
Yes. We have a whistleblower service via an external, approved platform with a secure channel for anonymously reporting suspected irregularities, ethical breaches or other serious misconduct. Cases received are taken by an independent recipient at board level, handled confidentially and investigated promptly, and anyone who reports in good faith is protected against reprisals. The service is open to employees, consultants and others who work with us.
How do you work as a responsible employer?Business ethics & responsibility
We work for an inclusive and respectful workplace with equal rights, opportunities and pay regardless of, among other things, sex, gender identity, ethnicity, religion, disability, sexual orientation or age, and we have zero tolerance toward discrimination, harassment and victimization. We carry out systematic work environment management for a safe and healthy work environment.
How do you govern your use of AI?Responsible AIAI Act
We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).
Can we build and run AI applications securely with you?Responsible AIDigital sovereignty
Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaSand Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.
Can our data be used to train AI models?Responsible AIAI Act
No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.
How do you relate to the EU AI Act?Responsible AIAI Act
The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.
What electricity powers your data centers?Sustainability & environment
Our data centers and our offices are powered exclusively by 100% renewable electricity, and this has been a fundamental prerequisite for our delivery since the start. Through our environmental management system, certified to ISO 14001:2015, we place requirements on our data center suppliers to ensure renewable electricity supply.
Are you a verified green cloud provider?Sustainability & environment
Yes. We are verified as a green cloud provider by The Green Web Foundation, which means that the electricity powering our platform comes from renewable energy sources. The verification confirms that our infrastructure runs without fossil energy.
How do you help us build energy-efficiently?Sustainability & environment
Where we can have the most influence is your choice of architecture and products - energy consumption can differ tenfold or more depending on how a solution is built. We build the platform to share resources efficiently and are happy to help design your solution energy-efficiently.
What energy and sustainability metrics do your data centers have?Sustainability & environment
We measure and follow up energy efficiency and environmental impact in our data centers in the Stockholm region according to ISO/IEC 30134. PUE (Power Usage Effectiveness) averages 1.45 for our three data centers, which is in line with industry practice for established data centers. REF (Renewable Energy Factor) is 100%, all electricity powering the facilities comes from renewable energy sources. One of our three data centers recovers surplus heat into district heating. WUE (Water Usage Effectiveness) is 0.95 for two of the data centers, and the third is assessed to be at a corresponding level.