Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do we as a customer have the right to audit you?NIS2GDPRDORA
Yes, the right to audit follows from your agreements with us and can arise in several ways. If we process personal data on your behalf, our Data Processing Agreement (DPA) gives you the right to conduct annual audits of the processing covered by the agreement, yourself or through a third party you appoint, at your own expense (GDPR Article 28.3(h)). For customers covered by DORA, audit and access rights are regulated in a dedicated contract addendum, and for those of you with supplier oversight requirements under Cybersäkerhetslagen (NIS2), we provide the documentation you need. In many cases, the need can also be met by our certificates and summaries of completed security reviews, which can be shared on request. Contact us and we will help you plan an audit.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.
ICT risk managementRegulatory complianceDORA
We ensure and maintain an adequate level of digital operational resilience, and risks within information and communication technology (ICT) are managed within our risk management process.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
How do you share information about threats and vulnerabilities?Regulatory complianceDORA
We continuously monitor and identify cyber threats and vulnerabilities via established sources and have a procedure for sharing relevant threat information, both internally and with affected customers and collaboration partners where appropriate. The aim is to be able to act quickly on new threats and to contribute to stronger shared resilience.
Management of ICT third-party riskRegulatory complianceDORA
Appropriate controls are applied at procurement and on an ongoing basis throughout the contract term to reduce risks linked to critical subcontractors.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.
How do you govern access and permissions?Access & authorizationNIS2
We apply the principle of least privilege, so that each employee receives only the rights required for their role, and administrators have unique, personal accounts. Access is protected in several layers, including with multi-factor authentication and hardware-based security keys for sensitive access. Permissions are reviewed regularly and adjusted or removed upon a change in or termination of employment.
Is multi-factor authentication required for administrative access to the production environment?Access & authorizationNIS2
Yes. All administrative access to the production environment goes through secured paths and requires multi-factor authentication. For administrative accounts, hardware-based MFA according to FIDO2/WebAuthn is required, and administrators are equipped with a physical hardware token as the primary factor. We also support time-based one-time passwords (TOTP).
Do you background-check your staff?Access & authorization
Yes. A background check is carried out on all final candidates before an employment decision is made, and the check is repeated annually for all roles with access to customer data. The checks are carried out in cooperation with an external certified partner and include, among other things, verification of identity, criminal records and court judgments, and financial situation, drawn from public registers or from authorized providers.
How are your employees' computers and devices protected?Access & authorization
Company devices are subject to encryption, central device management and endpoint security monitoring (EDR), with a local firewall that blocks inbound traffic and automatic updates. We apply clean desk and clean screen rules as well as mandatory automatic screen locking. Devices that can be used to administer customer environments or access customer data are subject to stricter requirements than other devices. Employees are given access only to the systems they have been explicitly authorized for.
Mobile device policyAccess & authorization
A policy and supporting security measures address the risks that the use of mobile devices entails, for example encryption, screen lock and the ability to wipe a device remotely if it is lost or stolen. Devices are additionally protected with extended endpoint protection (XDR) that continuously monitors and alerts on suspicious activity and behavior.
How do remote work and access to the production environment work?Access & authorization
All access to the production environment goes through secured paths and requires multi-factor authentication. There are three ways in: a Corporate Proxy, which is the general path for daily access for most employees; a VPN path for maintenance that requires access to multiple systems or to systems not reachable via the proxy; and a separate out-of-band VPN (OOB VPN) used during disaster recovery. Information handled and stored during remote work is additionally protected by policy and technical security measures.
Restriction of software installationAccess & authorization
Rules for which software users may install are established and enforced, so that only approved and secure software runs in the environment and the risk of malicious or insecure code is reduced.
Responsibility upon terminated or changed employmentAccess & authorization
Information security responsibilities that apply after terminated or changed employment are defined, communicated and enforced. This includes, among other things, that confidentiality and non-disclosure undertakings remain in force, that assets are returned and that access is revoked, so that the protection of information is maintained even after the role has changed or ended.
How are user permissions granted and revoked?Access & authorization
We have a formal process for the entire lifecycle of user accounts. When a person joins, the account is registered and granted the permissions the role requires according to the principle of least privilege. Upon a change of role the permissions are adjusted, and when an employment or contract ends the account is deregistered and access is revoked immediately, including SSH keys and VPN credentials, while confidentiality undertakings remain. The process covers all user types and all systems and services, and permissions are reviewed regularly.
How do you handle privileged (administrative) permissions?Access & authorization
Privileged access rights, that is, elevated administrative permissions, are handled more strictly than ordinary user access. They are granted restrictively and only to named, personal accounts, limited to what the role requires and followed up specifically. Administrative access to the production environment always requires multi-factor authentication.
How is secret authentication information (for example passwords and keys) handled?Access & authorization
The assignment and handling of secret authentication information, such as passwords, API keys and certificates, is governed by a formal process. Such information is distributed securely, stored protected and rotated when needed, and secrets are never stored in plaintext in source code. We use a password management system that maintains good password quality.
What is expected of users regarding secret authentication information?Access & authorization
Users follow the organization's procedures for protecting passwords and other secret authentication information, including not sharing login credentials and handling them securely.