Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
What does digital sovereignty mean at Elastx?Digital sovereignty & independenceDigital sovereignty
Our foundation is fully Swedish digital infrastructure under exclusively Swedish and European jurisdiction. Elastx is a Swedish company with Swedish owners and background-checked staff who are EU citizens, and your data on the platform stays within Sweden's borders. We own and operate our own hardware, and only Elastx staff administer the platform. We build on open standards and open source. Because we have no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA or equivalent legislation in other countries. This gives you control over where your data is stored, who can access it, and the ability to move it whenever you want.
Are your services free from foreign legislation such as the CLOUD Act?Digital sovereignty & independenceGDPRDigital sovereignty
Yes. As a Swedish company with no corporate ties outside Sweden, we are not subject to third-country legislation, neither the US CLOUD Act and FISA nor equivalent legislation in other countries. Your data is therefore not subject to foreign compelled disclosure. Furthermore, under GDPR Article 48, a judgment or an authority decision from a third country may not be recognised as grounds for disclosing personal data except on the basis of an international agreement.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
For personal data we act as a data processor. We guarantee technical and organisational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For GDPR matters you can reach us at gdpr@elastx.se.
Where is our data stored?Data protection & encryptionGDPRDigital sovereignty
As a data processor and an ISO/IEC 27018-certified company, we store data within Sweden. This means the information is kept within the EU/EEA and out of reach of foreign legislation such as the CLOUD Act. Personal data is processed only on a lawful basis and is securely erased when it is no longer needed.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
How do you handle requests to disclose data, for example from authorities?Data protection & encryptionGDPRDigital sovereignty
We do not disclose data to parties outside our delivery other than following a legally binding request. Each such disclosure is documented (what was disclosed, by whom, to whom, when and on what legal basis), and where the law permits we inform the affected customer. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, neither the US CLOUD Act and FISA nor equivalent legislation in other countries. Your data is therefore not subject to foreign compelled disclosure. Furthermore, under GDPR Article 48, a judgment or an authority decision from a third country may not be recognised as grounds for disclosing personal data except on the basis of an international agreement.
What happens to our data when the contract ends?Data protection & encryptionGDPRDigital sovereignty
You can export your data ahead of a termination. Upon decommissioning of a service or virtual machine, or upon written request, your data and associated infrastructure are securely erased. Storage rests on self-encrypting drives, which enables cryptographic erasure in line with recognised standards for data sanitisation. Logs linked to the processing of personal data are thereafter retained only for as long as the Data Processing Agreement (DPA) and applicable legal requirements demand.
Can you give concrete examples of how you secure the supply chain?Supply chainNIS2Digital sovereignty
Yes. Our fiber infrastructure is provided in part via Stokab, which is covered by the City of Stockholm's central guidelines and monitored operationally by CERT Stockholm. Our CDN is delivered by Varnish Software as a fully European service with a control plane in France, isolated from foreign legislation such as the CLOUD Act. Throughout, we prioritise suppliers within the EU/EEA and services that are not exposed to foreign jurisdiction.
Can we build and run AI applications securely with you?Responsible AIDigital sovereignty
Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.