Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Are you covered by Cybersäkerhetslagen (NIS2)?Regulatory complianceNIS2
Yes. We are covered by Cybersäkerhetslagen (the Swedish Cybersecurity Act, 2025:1506), which implements the NIS2 Directive and entered into force on 15 January 2026. We are covered as a provider of essential and critical infrastructure, partly through the transposition of the CER Directive, and as a provider of cloud services, data center services and CDN. PTS (the Swedish Post and Telecom Authority) is the supervisory authority for digital infrastructure, and Myndigheten för Civilt Försvar (MCF, the Swedish Civil Defence Agency) is the national coordinating authority and recipient of incident reports. We meet the law's requirements regarding security measures, management responsibility, training and incident reporting. Oversight of subcontractors and the supply chain is a central part of the requirements.
Can you enter into security protection agreements (SUA)?Regulatory compliance
For security-sensitive customers, for example in the public sector, we can where needed enter into a säkerhetsskyddsavtal (SUA, a Security Protection Agreement) under säkerhetsskyddslagen (the Swedish Protective Security Act, 2018:585). Such an agreement is notified to Säkerhetspolisen (the Swedish Security Service).
Compliance processRegulatory compliance
We have an organization and monitoring in place to stay in control of new or amended regulations, laws and standards relevant to the services. We maintain a legal register that tracks compliance requirements, including GDPR, Swedish security laws, NIS2, DORA and contractual requirements, and we keep our procedures and controls updated against it.
Do you meet accessibility requirements (WCAG and EN 301 549)?Regulatory compliance
We follow the accessibility requirements under the EU Accessibility Directive (in Sweden, lagen om vissa produkters och tjänsters tillgänglighet, 2023:254) for those of our digital interfaces that are in scope, primarily our public websites and self-service interfaces. We work toward the guidelines in WCAG and the European standard EN 301 549.
How do you report serious ICT incidents?Regulatory complianceNIS2DORA
We have a documented, communicated and tested process for reporting serious ICT incidents and cyber threats to customers and competent authorities. Reporting follows applicable rules, including Cybersäkerhetslagen (which implements NIS2) and, for incidents affecting financial entities we deliver to, DORA. For a significant incident we apply the NIS2 model: early warning within 24 hours, an incident report within 72 hours and a final report no later than one month thereafter.
Testing of digital operational resilienceRegulatory complianceDORA
We carry out recurring tests of our resilience. Penetration tests are performed by an independent external party, while continuity exercises are conducted internally. Tests are documented and followed by a plan for remediation and upcoming tests.
Exit strategy and migration planRegulatory complianceDORA
Contracts with critical subcontractors contain exit clauses and a documented process that secures continued delivery during a migration. We validate that the process works through recurring reviews and scenario-based tests of the exit and migration plan, so that it can be carried out in practice if a supplier needs to be replaced.
Supply chain securityRegulatory complianceNIS2
We have controls for our direct suppliers and service providers, that is, those with whom we have a contractual relationship, to ensure that their services meet our security requirements. The requirements are adapted to how critical the supplier is to our delivery.
Personnel securityRegulatory complianceNIS2
We ensure that staff who handle sensitive information and critical systems meet high security requirements. Staff are background-checked before employment, and permissions are granted, reviewed and revoked throughout employment according to the principle of least privilege and zero trust, with multi-factor authentication and clearly defined roles and responsibilities.