Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • Do we as a customer have the right to audit you?NIS2GDPRDORA

    Yes, the right to audit follows from your agreements with us and can arise in several ways. If we process personal data on your behalf, our Data Processing Agreement (DPA) gives you the right to conduct annual audits of the processing covered by the agreement, yourself or through a third party you appoint, at your own expense (GDPR Article 28.3(h)). For customers covered by DORA, audit and access rights are regulated in a dedicated contract addendum, and for those of you with supplier oversight requirements under Cybersäkerhetslagen (NIS2), we provide the documentation you need. In many cases, the need can also be met by our certificates and summaries of completed security reviews, which can be shared on request. Contact us and we will help you plan an audit.

  • What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty

    The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.

  • How is management involved in information security?Governance & complianceNIS2

    Management reviews our management system quarterly to assess that it is relevant and effective. The review is based on any events since the previous occasion, including risks, deviations and incidents. The security work we carry out and our material risks are also reported at board level.

  • Which laws and regulations do you comply with?Governance & complianceNIS2

    In addition to the ISO standards, we comply with Swedish and European laws and regulations, including Cybersäkerhetslagen (NIS2), GDPR, the Data Act and the AI Act.

  • How do you ensure security awareness among staff?Governance & complianceNIS2AI Act

    All staff, including management, undergo mandatory and recurring training in information security, data protection and responsible use of AI, and new staff are trained before system access is granted. We reinforce the security culture continuously, including with recurring phishing simulations, external penetration tests and ongoing internal sharing of vulnerability information. We contractually require subcontractors to maintain strict security awareness among their own staff and to comply with relevant regulations and security requirements.

  • Are you covered by Cybersäkerhetslagen (NIS2)?Regulatory complianceNIS2

    Yes. We are covered by Cybersäkerhetslagen (the Swedish Cybersecurity Act, 2025:1506), which implements the NIS2 Directive and entered into force on 15 January 2026. We are covered as a provider of essential and critical infrastructure, partly through the transposition of the CER Directive, and as a provider of cloud services, data center services and CDN. PTS (the Swedish Post and Telecom Authority) is the supervisory authority for digital infrastructure, and Myndigheten för Civilt Försvar (MCF, the Swedish Civil Defence Agency) is the national coordinating authority and recipient of incident reports. We meet the law's requirements regarding security measures, management responsibility, training and incident reporting. Oversight of subcontractors and the supply chain is a central part of the requirements.

  • ICT risk managementRegulatory complianceDORA

    We ensure and maintain an adequate level of digital operational resilience, and risks within information and communication technology (ICT) are managed within our risk management process.

  • How do you report serious ICT incidents?Regulatory complianceNIS2DORA

    We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.

  • Testing of digital operational resilienceRegulatory complianceDORA

    We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.

  • How do you share information about threats and vulnerabilities?Regulatory complianceDORA

    We continuously monitor and identify cyber threats and vulnerabilities via established sources and have a procedure for sharing relevant threat information, both internally and with affected customers and collaboration partners where appropriate. The aim is to be able to act quickly on new threats and to contribute to stronger shared resilience.

  • Management of ICT third-party riskRegulatory complianceDORA

    Appropriate controls are applied at procurement and on an ongoing basis throughout the contract term to reduce risks linked to critical subcontractors.

  • Exit strategy and migration planRegulatory complianceDORA

    Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.

  • Risk analysis and system securityRegulatory complianceNIS2

    Risk-based analyses and risk-reducing measures are carried out in accordance with applicable law and recognized standards, primarily ISO/IEC 27001 and ISO 31000.

  • Incident managementRegulatory complianceNIS2GDPR

    For security and personal data incidents we have a documented incident management procedure to detect, handle and report incidents in accordance with applicable law, including Cybersäkerhetslagen (NIS2) and, for personal data breaches, GDPR.

  • Continuity and crisis managementRegulatory complianceNIS2

    We have plans for, among other things, backup, disaster recovery and crisis management to secure uninterrupted delivery in accordance with laws and contracts.

  • Supply chain securityRegulatory complianceNIS2

    We have controls for our direct suppliers and service providers, that is, those with whom we have a contractual relationship, to ensure that their services meet our security requirements. The requirements are adapted to how critical the supplier is to our delivery.

  • Security in the acquisition, development and maintenance of networks and IT systemsRegulatory complianceNIS2

    Security is integrated into the acquisition, development and maintenance of networks and information systems, including the handling and reporting of vulnerabilities.

  • How do you evaluate that the security measures are effective?Regulatory complianceNIS2

    We have documented policies and procedures to regularly evaluate the effectiveness of the measures for cybersecurity risk, with criteria, responsibilities, evidence, reporting and remediation.

  • Cyber hygiene and trainingRegulatory complianceNIS2

    An awareness and training plan ensures that staff and relevant stakeholders have the security knowledge their role requires.

  • Personnel securityRegulatory complianceNIS2

    We ensure that staff who handle sensitive information and critical systems meet high security requirements. Staff are background-checked before employment, and permissions are granted, reviewed and revoked throughout employment according to the principle of least privilege and zero trust, with multi-factor authentication and clearly defined roles and responsibilities.