Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Customer data is stored in Swedish data centers.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • Which certifications does Elastx hold?Certifications & audits

    We are certified to ISO/IEC 27001:2022 for information security and apply all of the standard's controls across our entire operation. We also hold ISO/IEC 27017 (cloud security) and ISO/IEC 27018 (protection of personal data in the cloud), as well as ISO 14001:2015 (environmental management). The certificates are available for download.

  • Do you undergo an independent SOC 2 type audit?Certifications & audits

    ISO/IEC 27001 is our primary framework for information security. We also undergo an independent ISAE 3000 Type II audit, which is the international equivalent of SOC 2 Type II.

  • How often is Elastx audited externally, and can we access the reports?Certifications & audits

    We carry out an external audit of our ISO/IEC 27001 and ISO 14001 management systems once a year, and security reviews and penetration tests are conducted recurrently throughout the year. Over the past year this has included an external audit of ISO/IEC 27001:2022 as well as security reviews of our Cloud Console with associated APIs. Our certificates are available for download, and summaries can be shared with customers on request.

  • Do you carry out internal audits?Certifications & audits

    Yes. We perform an internal audit once a year according to an audit plan. Management appoints two employees who review evidence and interview the owners of the controls. The outcome is reported to management and any deviations are logged for remediation. Independent assurance of our management system additionally comes from our external ISAE 3000 audit and our ISO certifications.

  • Do you carry out technical compliance reviews?Certifications & audits

    Yes. Information systems are reviewed regularly against our information security policies and standards, both through automated checking of configuration and secure baselines and through recurring technical audits, for example vulnerability assessments and penetration tests. Deviations are documented and tracked to remediation.