Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • What does the physical security look like in your data centers?Physical security & data centers

    Our data centers are Tier 3-equivalent and have several physical security layers. Entry is via manual access control with ID checks, fingerprint and man-traps, and the facilities are CCTV-monitored. All access is logged and controlled. The physical access is covered by our ISO/IEC 27001 certification, and the data center facilities are operated by operators with their own independent audits (SOC 2 Type II) at the operator level.

  • How is the physical security of your data centers designed?Physical security & data centers

    Our data centers are protected in multiple layers based on a risk-based assessment: reinforced building construction, perimeter protection and detection, around-the-clock guarding and CCTV surveillance, and strict access control. External walls, ceilings and floors are of reinforced concrete. Where such an assessment has been made, data halls have been independently assessed to the Swedish Theft Prevention Association's SSF 200 protection class 3. Parts of our data center capacity are classified as protected installations (skyddsobjekt) and staffed with certified protection guards. Physical security at the facility level is independently audited and certified to ISO/IEC 27001 and SOC 2 Type II. Many customers base their procurement on MCF's guidance on physical information security for IT spaces (protection level 3); the facilities are designed and operated so that, on a risk-based assessment, they meet or exceed that guidance. Documentation on individual standards can be shared with customers on request as part of a vendor assessment.

  • Who has access to the data centers and how is it regulated?Physical security & data centers

    Elastx rents locked, video-monitored rooms in high-security data centers (our availability zones). Only background-checked Elastx staff have access, and only after prior notification. Access takes place with individual, personal access cards or badges combined with biometric verification, for example fingerprint, and security personnel monitor and control access to the facilities. Detailed visitor logs are kept of everyone who comes and goes, and all access is logged and controlled. Other access requests to our premises are approved by Elastx in advance.

  • Are multiple factors required for physical access to the equipment?Physical security & data centers

    Yes. Physical access to network equipment and servers requires at least two-factor authentication.

  • Camera surveillance (CCTV)Physical security & data centers

    Data centers, corridors and server halls are monitored around the clock with high-resolution, infrared-capable camera surveillance (CCTV). The system alerts on motion or a person in areas where no one should be, and recordings are stored in encrypted, tamper-resistant archives.

  • How are the facilities' perimeter and outer protection secured?Physical security & data centers

    In our availability zones, the perimeter is protected in several layers: fencing and barriers around the facility, bollards that prevent vehicle access, security lighting at entrances and perimeters, and reinforced doors, locks and splinter-protected glass. Controlled entry and exit points with man-traps prevent unauthorized tailgating, and intrusion alarms watch entrances and sensitive areas, including secure zones such as server rooms.

  • How are the facilities protected against fire, power outages and environmental threats?Physical security & data centers

    Our availability zones are built for operational reliability and protection against environmental threats. Smoke detectors, fire alarms and automatic extinguishing systems handle fire, climate systems maintain optimal temperature and humidity for the equipment, and sensors alert on water leakage or flooding. Power supply is fully redundant and appropriately protected, critical systems are protected by uninterruptible power (UPS), and diesel generators take over during longer outages. Sensitive equipment is protected against electromagnetic interference (EMI).

  • How are equipment and cables handled in the facilities?Physical security & data centers

    Servers and network equipment are placed in locked rooms and, where applicable, in locked cabinets, and network and power cables are protected and concealed to prevent tampering, including at our fiber junction points. Physical equipment is labeled and registered in an asset register so that it can be tracked, linked to an owner and handled securely throughout its lifecycle.

  • How do you work with physical security on an ongoing basis?Physical security & data centers

    Physical security is managed on an ongoing basis. Employees are trained in physical security procedures and reporting paths, physical and environmental protective measures are reviewed regularly, and access permissions are reviewed and revoked when needed, particularly after staff changes. There are documented plans for how physical security incidents are to be handled, for example break-in attempts, unauthorized access, fire or power outage, and the plans are exercised regularly together with the data center operators.

  • How do you govern your use of AI?Responsible AIAI Act

    We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).

  • Can we build and run AI applications securely with you?Responsible AIDigital sovereignty

    Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.

  • Can our data be used to train AI models?Responsible AIAI Act

    No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.

  • How do you relate to the EU AI Act?Responsible AIAI Act

    The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.