Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
What does digital sovereignty mean at Elastx?Digital sovereignty & independenceDigital sovereignty
Our foundation is fully Swedish digital infrastructure under exclusively Swedish and European jurisdiction. Elastx is a Swedish company with Swedish owners and background-checked staff who are EU citizens, and your data on the platform stays within Sweden's borders. We own and operate our own hardware, and only Elastx staff administer the platform. We build on open standards and open source. Because we have no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA or equivalent legislation in other countries. This gives you control over where your data is stored, who can access it, and the ability to move it whenever you want.
Are your services free from foreign legislation such as the CLOUD Act?Digital sovereignty & independenceGDPRDigital sovereignty
Yes. As a Swedish company with no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA nor equivalent legislation in other countries.
The applicability of legislation such as the US CLOUD Act depends on where the service provider is established, not solely on where its data centers are located. Choosing an EU data centre operated by a non-EU provider does not, by itself, remove the legal implications of third-country legislation.
Customer data on the Elastx Cloud Platform is governed by Swedish and EU legislation. Furthermore, GDPR Article 48 states that judgments or administrative decisions from third countries cannot, on their own, serve as a legal basis for transferring personal data unless supported by an applicable international agreement.
Learn more about how we support digital sovereignty and why Elastx is part of the EuroStack movement.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.