Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • How do we dispute an invoice or claim SLA compensation?Service delivery & SLA

    If you believe an invoice is incorrect, create a support ticket in our support portal (support.elastx.se) with priority Normal and we will investigate. The same applies if you believe we have not met our support SLA or availability SLA: create a support ticket with priority Normal, and we will investigate the event and handle any compensation in the ticket. The compensation levels are set out in the availability SLA.

  • Which availability levels (SLA) do you offer?Service delivery & SLA

    We publish clear availability SLAs per service. Elastx-managed services across multiple availability zones have 99.95% monthly uptime, and compute and storage built redundantly across multiple zones have 99.99%. Redundant services within a single zone have at least 99.9%, single instances without redundancy at least 99.5% and non-redundant connectivity at least 99%. If a level is not met, you may be entitled to financial compensation on your next invoice (10, 30 or 100% depending on the size of the deviation). Planned maintenance windows and force majeure are excluded. Full terms are available in our availability SLA.

  • What support and response time do you offer?Service delivery & SLA

    Support around the clock (24x7) is included in all our services, and we monitor our platform and our services 24x7. The response time is governed by the severity of the case: 15 minutes for business-critical cases (around the clock), 1 hour for high impact, 4 hours during office hours for normal cases and next business day for low priority. Cases are logged and tracked in our support portal, and current operational status is published continuously on our status page. Full terms are available in our support SLA.

  • Do we receive reports on quality and delivery?Service delivery & SLA

    Customer contracts can contain terms on reporting of quality and delivery. Current operational status and availability are published continuously on our status page, and follow-up of service levels (SLA) can be compiled and shared with you according to the contract.

  • Support deliveryService delivery & SLA

    We provide support to customers where cases are classified by priority and severity. The service levels are described in our support SLA.

  • How do you govern your use of AI?Responsible AIAI Act

    We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).

  • Can we build and run AI applications securely with you?Responsible AIDigital sovereignty

    Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.

  • Can our data be used to train AI models?Responsible AIAI Act

    No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.

  • How do you relate to the EU AI Act?Responsible AIAI Act

    The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.