Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Is the environment monitored around the clock?Logging & monitoringNIS2
Yes. We monitor the platform's operation and network traffic around the clock, year-round (24/7/365), with automatic alerts going directly to our engineers. The real-time monitoring tracks platform health, security metrics and network traffic and alerts on anomalies, and central dashboards watch for, among other things, unauthorised access attempts and abnormal traffic patterns. Operational and security logs are collected centrally, and we work continuously to strengthen our ability to detect security events.
Is privileged access to the infrastructure logged?Logging & monitoring
Yes. We keep audit logs for all infrastructure, which includes logins and privileged access to underlying systems. The logs are collected centrally and retained for an extended period, and relevant extracts can be provided on request - for example in connection with a security or personal data incident.
How do you detect capacity shortages before they affect the service?Logging & monitoring
We monitor capacity continuously and have automatic thresholds in the data centers for, among other things, disk, CPU, memory (RAM) and graphics cards (GPU) that create a ticket when exceeded, so that capacity shortages can be addressed in time.
Can we access our own logs and monitor the service?Logging & monitoring
Yes. You can access logs for your own services and make endpoints available for monitoring with the tool of your choice. Access is limited to log data relating to your own services.
How long is monitoring data retained?Logging & monitoring
Metrics from the platform's monitoring are retained for at least 90 days. Audit logs are retained for an extended period, and relevant extracts can be provided on request.
Capacity managementLogging & monitoring
Resource usage is monitored continuously and reviewed at set intervals, and future capacity needs are planned for to maintain the required performance.
Event loggingLogging & monitoring
Logs of user activities, errors and security events are created, retained and reviewed regularly.
Protection of log informationLogging & monitoring
Logging facilities and log information are protected against tampering and unauthorised access. Logs are collected centrally and tamper-resistantly, sent in real time to access-controlled archives and retained as forensic evidence.
Clock synchronisationLogging & monitoring
The clocks in all relevant systems are synchronised to a common, traceable reference time source. We synchronise to ntp.se, the Swedish standard time service operated by RISE and Netnod, which makes logs comparable across systems and enables accurate forensics.