Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do your staff have access to our data?Data protection & encryptionGDPR
No, not in day-to-day operations. Our staff work on the underlying platform without visibility into your data content, and do not have access to your instances or applications. Access to your environment takes place only if you explicitly request and approve it, for example in a support ticket, and is then limited to the specific need. All privileged access to the infrastructure uses personal accounts, requires multi-factor authentication and is logged.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
Our role depends on the personal data processing in question. For your customer data and workloads on the platform, we act as a data processor, and we guarantee technical and organizational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For administrative data relating to our own customer relationship with you, for example contact details and login logs for your contract administration, we act as a data controller. For GDPR matters you can reach us at gdpr@elastx.se.
Is data encrypted at rest?Data protection & encryptionNIS2GDPR
Yes. We have a policy and procedures for encryption, and all disks in our environment are encrypted with strong encryption (AES-256). Physical servers use self-encrypting drives (SED) according to TCG Opal with pre-boot authentication, so that a physically stolen storage medium does not grant access to data.
How is data protected in transit?Data protection & encryptionNIS2GDPR
Data in transit is protected with TLS (versions 1.2 and 1.3) using strong encryption (AES-256) and with SSH key pairs. For managed database services, CA certificates are provided so that you can verify and encrypt your client connections.
Where is our data stored?Data protection & encryptionGDPRDigital sovereignty
As a data processor and an ISO/IEC 27018-certified company, we store data within Sweden. This means the information is kept within the EU/EEA and out of reach of foreign legislation such as the CLOUD Act. Personal data is processed only on a lawful basis and is securely erased when it is no longer needed.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
Do you use sub-processors?Data protection & encryptionGDPR
It is uncommon for us to use sub-processors. Your data on the platform is stored in Sweden and processed by us as a processor. For certain support services, for example invoicing and dispatch, we may use sub-processors, and the processing is then governed by a Data Processing Agreement (DPA) under GDPR Article 28. We verify that sub-processor agreements are in place, and we notify you before we add or change a data center or sub-processor. Any access for subcontractors to your data on the platform takes place only after your approval.
What happens to our data when the contract ends?Data protection & encryptionGDPRDigital sovereignty
You can export your data ahead of a termination. Upon decommissioning of a service or virtual machine, or upon written request, your data and associated infrastructure are securely erased. Storage rests on self-encrypting drives, which enables cryptographic erasure in line with recognized standards for data sanitization. Logs linked to the processing of personal data are thereafter retained only for as long as the Data Processing Agreement (DPA) and applicable legal requirements demand.
How do you help us with data subjects' rights?Data protection & encryptionGDPR
As a data processor, we assist you as the data controller in responding to requests from data subjects - for example access, rectification, erasure, restriction and data portability - in accordance with the Data Processing Agreement (DPA). The platform gives you technical means to find, export and erase personal data in your own environments.
Which technical and organisational measures do you apply to protect personal data?Data protection & encryptionGDPR
Our Data Processing Agreement (DPA) specifies the technical and organizational measures we apply. Organizationally, we work according to ISO/IEC 27001 with role-based access, mandatory onboarding and offboarding procedures and personal confidentiality undertakings for all staff. Technically, data is encrypted at rest with AES-256 and in transit with TLS 1.2 and 1.3, and the infrastructure is continuously monitored with vulnerability scanning, DDoS protection and central tamper-resistant logging. More detail is available under the respective topic in the FAQ.
How do you ensure that the Data Processing Agreements (DPA) are up to date?Data protection & encryptionGDPR
Our Data Processing Agreement and associated instructions are kept under continuous version control. Revisions prompted by changed legislation, new regulatory requirements or updated security measures are documented in a change history, so that you can always see what applies and why it was changed.
What does your responsibility as a data processor cover?Data protection & encryptionGDPR
As a data processor, we process personal data solely according to your written instructions and without insight into the actual data content. We are responsible for the security, availability and resilience of the underlying cloud infrastructure, including physical security in the data centers, vulnerability protection at the platform level and support around the clock. You are responsible for your application, your credentials and the configuration of your own backups. A full allocation of responsibility is available in the Data Processing Agreement and in our cloud security policy (ISO/IEC 27017).