Trust Center

Swedish-owned. Data stored in Sweden. Certified security. Open standards. Here you will find information about how we protect data, meet regulatory requirements and build a platform trusted by organizations with the highest demands for security, compliance and control.

Why organizations trust Elastx

  • Digital Sovereignty

    Swedish jurisdiction and free from the U.S. CLOUD Act.

  • Data Stays in Sweden

    Data is stored and managed in Sweden.

  • Certified Security

    ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified.

  • High Availability

    Built with redundancy, continuous monitoring and expert support around the clock.

  • No Vendor Lock-In

    Open standards and full control over your data.

  • How do you develop secure software?Secure developmentNIS2

    Our in-house development follows a secure development procedure. Security requirements are defined early, code undergoes mandatory peer review and automatic static security analysis (SAST) of container images, and no secrets or keys are stored in source code. The source code resides in access-controlled repositories with MFA, where permissions are governed by developer role and branch protection is applied. Build and deployment pipelines are automated, and changes are tested in isolated test environments before they reach production. No real customer data or personal data is used in development or test environments.

  • Do you contribute to the open projects you build on?Secure development

    Yes. We are active and contribute continuously to OpenStack and Kubernetes, the projects we ourselves build on and use. Our contributions concern, among other things, OpenStack (compute, identity and networking) and Kubernetes, including Cluster API. Other contributions occur more sporadically. This gives us early insight into security updates and the ability to influence upcoming standards.

  • Separation of development, test and production environmentsSecure development

    Development, test and production environments are separated to reduce the risk of unauthorized access or changes in the production environment.

  • How do you govern system changes during development?Secure development

    Changes to systems during the development lifecycle are governed by formal change control procedures. This means, for example, that changes are documented and approved, that code is peer reviewed before merging, that automated tests are run and that there are documented procedures to roll back if something goes wrong.

  • How do you engineer secure systems?Secure development

    Our in-house development is based on the principle of Defense in Depth across all technical layers and on established security guidelines, including the OWASP Top 10. We apply secure coding principles, for example parameterized database queries against SQL injection and context-based escaping against scripting attacks (XSS), and the source code is scanned automatically in our build pipelines. Configuration is managed as code from reviewed, immutable baselines, and sessions are protected with secure cookie settings.

  • Secure development environmentSecure development

    Secure development environments for system development and integration are established and protected throughout the development lifecycle. Business-critical applications are reviewed and tested carefully after platform changes, so that changes to operating platforms do not adversely affect the business or security.

  • Outsourced developmentSecure development

    We generally do not outsource system development and avoid it as far as possible. Where it does occur, the work is supervised and follows the organization's standards and regulatory requirements.

  • De-identified test dataSecure development

    No real customer or personal data is used in testing. Test data is de-identified or synthetic and is therefore not handled with the same protection requirements as production data.

  • How do you govern your use of AI?Responsible AIAI Act

    We have a policy for AI ethics and AI governance. AI is a support to human expertise, not a replacement - a human reviews and approves AI-generated output before it is used internally or delivered externally, and responsibility always remains with the human. We review output to counteract bias and inaccuracies, and the use follows our information classification, ISO 27001 and the EU AI Act. Staff who work with AI receive training in responsible use (AI literacy).

  • Can we build and run AI applications securely with you?Responsible AIDigital sovereignty

    Yes. Our AI platform lets you develop AI with Swedish data residency and regulatory compliance. GPUs are available in both OpenStack IaaS and Kubernetes CaaS, and vector data is handled by our database service (DBaaS) with Postgres Vector together with our high-capacity storage. For more advanced needs, such as private language models (LLM), Retrieval Augmented Generation (RAG) with separate databases, agents and APIs, we offer a solution together with our partner ConfidentialMind. Everything runs in our Swedish environment, your data is kept isolated and is never used to train external models.

  • Can our data be used to train AI models?Responsible AIAI Act

    No. Data classified as confidential or higher, including customer data, may never be fed into public or unmanaged AI services. AI services that handle such data must contractually guarantee that data is not used to train models and have clear rules for storage and data localization, and they are risk-assessed according to our ISO 27001 process for suppliers. Secrets such as passwords and keys are never fed into any AI system.

  • How do you relate to the EU AI Act?Responsible AIAI Act

    The EU AI Act (2024/1689) sets a harmonized framework for the development and use of AI within the EU with protection for fundamental rights. Elastx uses AI as support internally and then acts as a deployer (under Article 3.4), not as a developer of high-risk AI. We comply with the regulation through our policy for AI ethics and AI governance: human review and approval of AI output, measures against bias and inaccuracies, training in AI literacy, and ensuring that confidential data or secrets are never fed into unmanaged AI services.