Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • How do you keep different customers' environments separate?Network & isolationNIS2

    We separate different customers' environments (tenants) logically using, among other things, VLAN, VXLAN and software-defined networking (SDN), and the platform's administration layer is kept strictly isolated from customers' runtime environments. The logical segmentation prevents lateral movement and keeps customer workloads separate.

  • How do you protect against DDoS and network attacks?Network & isolationNIS2

    DDoS protection at the network level (L3/L4) against volumetric attacks is included in the platform service at no extra cost, is always active and requires no configuration. In addition, we offer a web application firewall (WAF) and threat intelligence as options, together with secure network zoning that blocks known malicious sources. We also offer a CDN service that can offload and protect web traffic.

  • How do you govern and secure your network services?Network & isolation

    Networks are managed, monitored and controlled to protect the information in systems and services. Network traffic is segmented and governed on the principle of blocking what is not explicitly allowed, and different security zones are kept separate. For all network services, both in-house and outsourced, security mechanisms, service levels and requirements are defined, and these are included in contracts.