Trust Center
Answers to common questions about security, compliance, operations, and how we handle your data.
Why organizations trust Elastx
Digital Sovereignty
Swedish jurisdiction and free from the U.S. CLOUD Act.
Data Stays in Sweden
Customer data is stored in Swedish data centers.
Certified Security
ISO 27001, ISO 27017, ISO 27018 and ISO 14001 certified, with regular independent audits.
High Availability
Built with redundancy, continuous monitoring and expert support around the clock.
No Vendor Lock-In
Open standards and full control over your data.
How do you work with vulnerabilities and patching?Vulnerability management & patchingNIS2
We have a central process and policy for vulnerability management. We carry out regular vulnerability scanning, rank vulnerabilities by risk and track them to remediation according to defined service levels (SLA). Container images are also scanned automatically in the build pipeline, and patching is carried out regularly with priority on high-risk systems.
How do you harden the systems?Vulnerability management & patchingNIS2
We harden physical and logical components (for example servers, virtual machines and service protocols) according to established hardening standards (including CIS Benchmarks), and the configuration is managed as code so that a secure baseline is maintained.
How do I report a vulnerability to you?Vulnerability management & patchingNIS2
We have an established process for responsible vulnerability disclosure. If you or a security researcher discovers a vulnerability, it can be reported confidentially to compliance@elastx.se. We receive, assess and remediate reported vulnerabilities according to our vulnerability and patch management process.
How do you protect against malicious code?Vulnerability management & patchingNIS2
We have multi-layered protection against malicious code at the hypervisor, orchestration and endpoint levels. All company devices have endpoint-level security monitoring (EDR), and in selected environments intrusion detection continuously monitors container runtimes. The protection is combined with recurring security training and awareness among staff.