Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do we as a customer have the right to audit you?NIS2GDPRDORA
Yes, the right to audit follows from your agreements with us and can arise in several ways. If we process personal data on your behalf, our Data Processing Agreement (DPA) gives you the right to conduct annual audits of the processing covered by the agreement, yourself or through a third party you appoint, at your own expense (GDPR Article 28.3(h)). For customers covered by DORA, audit and access rights are regulated in a dedicated contract addendum, and for those of you with supplier oversight requirements under Cybersäkerhetslagen (NIS2), we provide the documentation you need. In many cases, the need can also be met by our certificates and summaries of completed security reviews, which can be shared on request. Contact us and we will help you plan an audit.
What does your exit strategy look like if we want to leave?Digital sovereignty & independenceDORADigital sovereignty
The goal is that you should never feel locked in. We build on open standards and open source (including OpenStack and Kubernetes), which means you can move your applications and data to another environment. You can export your data ahead of a termination, and we apply no mandatory lock-in periods, in line with the EU Data Act.
ICT risk managementRegulatory complianceDORA
We ensure and maintain an adequate level of digital operational resilience, and risks within information and communication technology (ICT) are managed within our risk management process.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
How do you share information about threats and vulnerabilities?Regulatory complianceDORA
We continuously monitor and identify cyber threats and vulnerabilities via established sources and have a procedure for sharing relevant threat information, both internally and with affected customers and collaboration partners where appropriate. The aim is to be able to act quickly on new threats and to contribute to stronger shared resilience.
Management of ICT third-party riskRegulatory complianceDORA
Appropriate controls are applied at procurement and on an ongoing basis throughout the contract term to reduce risks linked to critical subcontractors.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.
How do you avoid vendor lock-in?Data protection & encryptionDORADigital sovereignty
We build on open standards and open source (including OpenStack and Kubernetes) so that you can move your applications if you want. We apply no mandatory lock-in periods, and you pay for the resources you allocate. As a Swedish company we operate under Swedish and European jurisdiction and are not subject to third-country legislation, and we comply with the EU Data Act to counteract lock-in effects.
How quickly do you inform us of an incident or personal data breach?Incident managementNIS2GDPRDORA
In the event of an incident affecting you, we inform you without undue delay, and at the latest within 24 hours of becoming aware, so that you have time to meet your own obligations. In the event of a significant incident, we follow Cybersäkerhetslagen (NIS2) in reporting to the competent authority (MCF): early warning within 24 hours, an incident report within 72 hours and a final report no later than one month after the incident report.
How do you report material events to authorities?Incident managementNIS2GDPRDORA
Material events are reported according to applicable rules. Serious incidents covered by Cybersäkerhetslagen (NIS2) are reported to Myndigheten för Civilt Försvar (MCF), and for incidents concerning financial entities we deliver to, we follow DORA. In the event of a personal data breach, we as a data processor inform the affected data controller without undue delay under GDPR, so that they can fulfill their own notification obligation.
Do you test your continuity capability?Continuity & recoveryNIS2DORA
Yes. We exercise our continuity plan (Business Continuity Plan, BCP) through recurring, full-scale continuity exercises as part of our ISO/IEC 27001 work. The exercises are typically unannounced for the majority of the organization in order to give a realistic result, and they test the crisis management team's decision-making, the technical containment procedures and our communication channels under high pressure.
How is the platform built for redundancy and recovery?Continuity & recoveryNIS2DORA
The platform is distributed across three active availability zones in the Stockholm area (STO1, STO2 and STO3), geographically separated so that a physical or environmental disruption in one zone does not take down the service. Services are replicated between the zones for automatic redundancy. For critical backups and logs we offer The Vault - an immutable, ransomware-resistant storage that additionally sits in a separate region around 350 km from the Stockholm area, in a protected underground facility. It is based on Object Lock (WORM - Write Once, Read Many), which means data cannot be changed or deleted during the configured lock period, even if permissions are compromised.
How do you ensure security in your supply chain?Supply chainNIS2
We are part of a supply chain and apply a continuous, documented and risk-based review of our suppliers, in line with the requirements on supply chain security in Cybersäkerhetslagen (NIS2). New suppliers are reviewed and approved before they are taken into use, and our critical and essential suppliers are followed up annually as well as upon noted deviations. A summary or certificate regarding the supplier review can be shared on request.
Can you give concrete examples of how you secure the supply chain?Supply chainNIS2Digital sovereignty
Yes. Our fiber infrastructure is provided in part via Stokab, which is covered by the City of Stockholm's central guidelines and monitored operationally by CERT Stockholm. Our CDN is delivered by Varnish Software as a fully European service with a control plane in France, isolated from foreign legislation such as the CLOUD Act. Throughout, we prioritize suppliers within the EU/EEA and services that are not exposed to foreign jurisdiction.
How do you assess new suppliers before engaging them?Supply chainNIS2
We apply a structured framework for supplier risk assessment in two steps. In the first step we assess the supplier as a whole - security maturity (for example ISO/IEC 27001 certification or an ISAE 3000 report), financial stability and how they in turn manage their own subcontractors. The outcome is approved, escalation for deeper review or a stop. In the second step we assess the specific service's risk according to a likelihood and impact model (ISO 31000), taking into account data protection, availability and business impact. The assessment is carried out and documented before a supplier is taken into use, and critical suppliers are approved by management.
Do you place security requirements on your suppliers in contracts?Supply chainNIS2
Yes. We place security requirements on suppliers in contracts, and the requirements are tightened in step with the risk the service entails, for example requirements on encryption, redundancy and contingency plans. We also require suppliers to have control of their own supply chain and to keep their staff trained in accordance with NIS2. The framework also contains binding rules for data transfer that govern which data may be stored where, regardless of what the other parts of the assessment show.
Have you carried out an actual review of your suppliers, or is it just a policy?Supply chain
We have carried out and documented a due diligence review of our critical and essential suppliers, and we do so continuously, at least annually. The review assesses the suppliers' security maturity against recognized standards such as ISO/IEC 27001 and SOC 2 Type II, seeks evidence of effective processes for incident reporting, vulnerability management and continuity, and analyzes financial stability. Where a supplier lacks formal certification, we assess compensating controls and make a documented, risk-based decision.
Do you take into account where data is stored and which jurisdiction applies?Supply chainNIS2GDPR
Yes. When we assess and select suppliers, we take into account where data is stored physically and which jurisdiction the supplier is subject to, including exposure to foreign legislation such as the CLOUD Act. Where relevant, we prioritize storage within the EU/EEA and suppliers that offer European data sovereignty.
Governance of suppliers' service deliverySupply chain
We have service level agreements with suppliers and measure the fulfillment of their services.