Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do you test your continuity capability?Continuity & recoveryNIS2DORA
Yes. We exercise our continuity plan (Business Continuity Plan, BCP) through recurring, full-scale continuity exercises as part of our ISO/IEC 27001 work. The exercises are typically unannounced for the majority of the organization in order to give a realistic result, and they test the crisis management team's decision-making, the technical containment procedures and our communication channels under high pressure.
What did this year's continuity exercise show?Continuity & recovery
Exercises confirm our crisis preparedness and technical resilience. The crisis management team establishes structure quickly, and we can if needed isolate an entire availability zone to protect customer environments in the other zones. Identified areas for improvement are followed up in a structured way and managed over time, including clearer crisis mandates, a dedicated communications lead, more formalized procedures for endurance during prolonged incidents and improved traceability and reporting in line with Cybersäkerhetslagen (NIS2) and DORA.
How is the platform built for redundancy and recovery?Continuity & recoveryNIS2DORA
The platform is distributed across three active availability zones in the Stockholm area (STO1, STO2 and STO3), geographically separated so that a physical or environmental disruption in one zone does not take down the service. Services are replicated between the zones for automatic redundancy. For critical backups and logs we offer The Vault - an immutable, ransomware-resistant storage that additionally sits in a separate region around 350 km from the Stockholm area, in a protected underground facility. It is based on Object Lock (WORM - Write Once, Read Many), which means data cannot be changed or deleted during the configured lock period, even if permissions are compromised.
Do you back up our data?Continuity & recoveryNIS2
We back up our own platform, for example configuration and system images, and these backups are created and tested according to a defined backup policy. Backup and any replication of your data is configured and governed by you, with tools in the platform or external tools, based on your wishes and what your contract covers - this gives you full control over what is saved, where and for how long. For immutable storage of critical copies and logs we offer The Vault. Our object storage service stores three copies by default, distributed across three availability zones.
How are the continuity processes implemented and maintained?Continuity & recovery
Procedures and controls to maintain continuity during a disruption are established, documented, implemented and maintained. The continuity and disaster recovery plan contains controls that are verified regularly to ensure that it is valid and effective.
What training does staff receive in crisis management?Continuity & recovery
Staff who are part of the crisis organization receive recurring training and exercises in crisis management, for example in roles and mandates, decision-making under pressure, internal and external communication and the technical containment and recovery procedures. Other staff receive training at an overview level so that everyone knows how to act and where to turn in a crisis.
How do you govern your use of AI?Responsible AIAI Act
We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).
Can we build and run AI applications securely with you?Responsible AIDigital sovereignty
Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.
Can our data be used to train AI models?Responsible AIAI Act
No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.
How do you relate to the EU AI Act?Responsible AIAI Act
The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.