Trust Center
Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Data is stored and managed in Sweden.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
Do you have cyber insurance?Risk management
Yes. We have cyber insurance that covers, among other things, liability, business interruption, data recovery and costs associated with a cyber or information incident, including forensic investigation, handling of personal data breaches and access to incident response around the clock. The cover applies globally and complements our technical and organizational security measures.
Reporting of weaknessesRisk management
Our risk policy and procedure allow anyone to report risks and weaknesses to risk management, for example via a ticket or directly to W&C. Reporting is encouraged, the cases are captured and remediated where relevant.
Governance of risk controlRisk management
The risk assessment process identifies, assesses and manages risks that affect the organization's ability to reach its objectives. In practice, this means we carry out contextual risk assessments of technical vulnerabilities based on our unique environment and apply a framework according to ISO 31000 to proactively evaluate and govern risks in our supply chain.
Risk awareness and learningRisk management
The board, management and relevant staff have knowledge of risks and how they are managed, resolved or reduced to an acceptable level. This is ensured through recurring risk reviews, training and by following up risks and remediations in management reviews.
Assessment of information security risksRisk managementNIS2
Information security risks are automatically given higher priority in the process so that resolution or reduction is handled promptly. In our operational work, this means that detected vulnerabilities are immediately risk-assessed based on system exposure and impact on critical services, which triggers timeframes for patching and mitigating measures.
Response to information security risksRisk managementNIS2
Risks relating to information security and integrity are reported according to the standard process. Particularly sensitive risks are reported to a small number of designated individuals. In practice, this means that standard risks are tracked through our internal ticketing systems, while critical or confidential matters are escalated directly to the management team or handled via our protected whistleblower channel to ensure confidentiality and immediate action.
How do you govern your use of AI?Responsible AIAI Act
We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).
Can we build and run AI applications securely with you?Responsible AIDigital sovereignty
Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.
Can our data be used to train AI models?Responsible AIAI Act
No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.
How do you relate to the EU AI Act?Responsible AIAI Act
The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.