Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do we as a customer have the right to audit you?NIS2GDPRDORA
Yes, the right to audit follows from your agreements with us and can arise in several ways. If we process personal data on your behalf, our Data Processing Agreement (DPA) gives you the right to conduct annual audits of the processing covered by the agreement, yourself or through a third party you appoint, at your own expense (GDPR Article 28.3(h)). For customers covered by DORA, audit and access rights are regulated in a dedicated contract addendum, and for those of you with supplier oversight requirements under Cybersäkerhetslagen (NIS2), we provide the documentation you need. In many cases, the need can also be met by our certificates and summaries of completed security reviews, which can be shared on request. Contact us and we will help you plan an audit.
Do your staff have access to our data?Data protection & encryptionGDPR
No, not in day-to-day operations. Our staff work on the underlying platform without visibility into your data content, and do not have access to your instances or applications. Access to your environment takes place only if you explicitly request and approve it, for example in a support ticket, and is then limited to the specific need. All privileged access to the infrastructure uses personal accounts, requires multi-factor authentication and is logged.
Are your services free from foreign legislation such as the CLOUD Act?Digital sovereignty & independenceGDPRDigital sovereignty
Yes. As a Swedish company with no corporate ties outside Sweden, we are not subject to third-country legislation such as the US CLOUD Act and FISA nor equivalent legislation in other countries.
The applicability of legislation such as the US CLOUD Act depends on where the service provider is established, not solely on where its data centers are located. Choosing an EU data centre operated by a non-EU provider does not, by itself, remove the legal implications of third-country legislation.
Customer data on the Elastx Cloud Platform is governed by Swedish and EU legislation. Furthermore, GDPR Article 48 states that judgments or administrative decisions from third countries cannot, on their own, serve as a legal basis for transferring personal data unless supported by an applicable international agreement.
Learn more about how we support digital sovereignty and why Elastx is part of the EuroStack movement.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.
ICT risk managementRegulatory complianceDORA
We ensure and maintain an adequate level of digital operational resilience, and risks within information and communication technology (ICT) are managed within our risk management process.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
How do you share information about threats and vulnerabilities?Regulatory complianceDORA
We continuously monitor and identify cyber threats and vulnerabilities via established sources and have a procedure for sharing relevant threat information, both internally and with affected customers and collaboration partners where appropriate. The aim is to be able to act quickly on new threats and to contribute to stronger shared resilience.
Management of ICT third-party riskRegulatory complianceDORA
Appropriate controls are applied at procurement and on an ongoing basis throughout the contract term to reduce risks linked to critical subcontractors.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.
Incident managementRegulatory complianceNIS2GDPR
For security and personal data incidents we have a documented incident management procedure to detect, handle and report incidents in accordance with applicable law, including Cybersäkerhetslagen (NIS2) and, for personal data breaches, GDPR.
What role does Elastx have under GDPR?Data protection & encryptionGDPRDigital sovereignty
Our role depends on the personal data processing in question. For your customer data and workloads on the platform, we act as a data processor, and we guarantee technical and organizational protective measures under signed Data Processing Agreements (DPA) in accordance with GDPR. For administrative data relating to our own customer relationship with you, for example contact details and login logs for your contract administration, we act as a data controller. For GDPR matters you can reach us at gdpr@elastx.se.
Is data encrypted at rest?Data protection & encryptionNIS2GDPR
Yes. We have a policy and procedures for encryption, and all disks in our environment are encrypted with strong encryption (AES-256). Physical servers use self-encrypting drives (SED) according to TCG Opal with pre-boot authentication, so that a physically stolen storage medium does not grant access to data.
How is data protected in transit?Data protection & encryptionNIS2GDPR
Data in transit is protected with TLS (versions 1.2 and 1.3) using strong encryption (AES-256) and with SSH key pairs. For managed database services, CA certificates are provided so that you can verify and encrypt your client connections.
How are encryption keys managed?Data protection & encryptionNIS2GDPR
The encryption keys are protected by pre-boot authentication with a unique key per server, derived from the server's unique hardware, and are unlocked only at startup.
Where is our data stored?Data protection & encryptionGDPRDigital sovereignty
As a data processor and an ISO/IEC 27018-certified company, we store data within Sweden. This means the information is kept within the EU/EEA and out of reach of foreign legislation such as the CLOUD Act. Personal data is processed only on a lawful basis and is securely erased when it is no longer needed.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
Do you sell or share our data, or use it for marketing?Data protection & encryptionGDPR
No. Personal data entrusted to us is not sold and is not shared with third parties for marketing or advertising purposes without explicit consent. Your data is processed only to deliver the service under the contract and our Data Processing Agreement (DPA).
How do you handle requests to disclose data, for example from authorities?Data protection & encryptionGDPRDigital sovereignty
We do not disclose data to parties outside our delivery other than following a legally binding request. Each such disclosure is documented (what was disclosed, by whom, to whom, when and on what legal basis), and where the law permits we inform the affected customer. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, neither the US CLOUD Act and FISA nor equivalent legislation in other countries. Your data is therefore not subject to foreign compelled disclosure. Furthermore, under GDPR Article 48, a judgment or an authority decision from a third country may not be recognized as grounds for disclosing personal data except on the basis of an international agreement.
Do you use sub-processors?Data protection & encryptionGDPR
It is uncommon for us to use sub-processors. Your data on the platform is stored in Sweden and processed by us as a processor. For certain support services, for example invoicing and dispatch, we may use sub-processors, and the processing is then governed by a Data Processing Agreement (DPA) under GDPR Article 28. We verify that sub-processor agreements are in place, and we notify you before we add or change a data center or sub-processor. Any access for subcontractors to your data on the platform takes place only after your approval.