Elastx AB

Sweden · elastx.se · 13 vendors

Elastx AB is a Swedish cloud provider offering automated cloud services for business-critical applications and sensitive data. Their platform includes Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Container as a Service (CaaS), Database as a Service (DBaaS), and AI services. The company emphasizes security, sustainability, and ensuring all customer data remains within Sweden.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 13 sub-vendors.

Insights

Last updated 2026-07-21 · revision 12

13 direct vendors, 208 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Elastx AB demonstrates medium-high migration readiness. A key strength lies in its modern and open-source-centric internal tech stack, which includes OpenStack, Kubernetes, Docker, Ceph, Terraform, and Ansible. This foundation promotes portability and reduces proprietary vendor lock-in at the infrastructure level, making technical migration to other platforms potentially more straightforward. The company's offerings of CaaS and PaaS indicate internal expertise in cloud-native deployment patterns. However, several factors present significant challenges to migration. Strict data residency requirements, mandating all customer data to be stored and processed within Sweden/EU, severely limit the choice of potential migration targets and add complexity to ensuring compliance in a new environment. The current lack of documented compliance for GDPR, NIS2, SOC2, and ISO 27001 means that any migration effort would need to meticulously address these regulatory requirements, potentially adding substantial overhead and risk. Furthermore, as a cloud provider, migrating its entire core IaaS/PaaS platform is an undertaking of immense scale and complexity, representing a significant internal architectural 'lock-in' to its current operational model. The absence of growth history data also prevents an assessment of the company's financial capacity to fund such a large-scale migration. While the use of open-source technologies generally aids migration, the contradictory 'Total Vendors: 0' and 'Unknown' vendor lock-in risk mean that specific external vendor dependencies and their impact on migration cannot be fully assessed.

Compliance

9 in-scope frameworks identified; showing 3.

ePrivacy Directive — Assessment Required

The ePrivacy Directive and its Swedish implementation (Lag om elektronisk kommunikation, LEK) apply to providers of electronic communications services and networks. As a cloud and internet infrastructure provider, Elastx may be subject to ePrivacy requirements regarding confidentiality of communications, cookie consent (for their website), and potentially traffic/location data handling. Risk is Medium because violations of ePrivacy/LEK can result in fines from PTS (Post- och telestyrelsen) and IMY, and cookie consent non-compliance is actively enforced in Sweden.

Evidence: https://elastx.se/, https://www.imy.se/en/organisations/data-protection/this-applies-to-you/cookies/, https://www.pts.se/en/

NIS2 (source) — Assessment Required

Elastx AB is a Swedish cloud infrastructure and managed services provider. NIS2 (EU Directive 2022/2555, transposed into Swedish law via the Cybersäkerhetslag) explicitly lists 'cloud computing service providers' and 'data centre service providers' under Annex II as Important Entities, and 'DNS service providers', 'TLD name registries', and 'internet exchange point providers' under Annex I as Essential Entities. Cloud providers meeting the medium-enterprise threshold (50+ employees or €10M+ turnover) are directly in scope. Elastx, as a public cloud provider operating in Sweden, very likely meets these thresholds. Risk is High because NIS2 carries significant penalties (up to €10M or 2% of global turnover for Important Entities) and Sweden has transposed NIS2 into national law. Non-compliance with cybersecurity risk management measures, incident reporting (24-hour initial notification to NCSC/MSB), and supply chain security requirements would constitute a serious violation.

Evidence: https://elastx.se/, https://www.msb.se/en/subject-areas/cybersecurity-and-information-security/nis2/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.msb.se/sv/amnesomraden/informationssakerhet-cybersakerhet-och-sakra-kommunikationer/nis2/

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant for companies that provide assurance reports to third parties about their controls and processes. For cloud providers, ISAE 3402 (a specific application of ISAE 3000 for service organisations) is sometimes used as an alternative or complement to SOC 2 in European markets. Risk is Low because ISAE 3000/3402 is voluntary and not legally mandated. However, European enterprise customers may request ISAE 3402 Type II reports as part of vendor assurance. The absence of such a report is a commercial risk rather than a regulatory violation.

Evidence: https://elastx.se/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or

Financials

Financial Resilience Score: 7/10

Elastx AB operates in a structurally favorable niche: it is one of the few pure-play Swedish public cloud providers, benefiting from strong tailwinds around EU data sovereignty, concerns over the US CLOUD Act, and post-Schrems II demand for EU-owned cloud alternatives. Its business model is based on recurring, multi-year IaaS and managed-services subscriptions, which provides predictable cash flow and reduces revenue volatility. Exposure to Swedish public-sector customers (municipalities, agencies) further strengthens credit quality of the customer base. However, the company faces meaningful structural risks. It competes against hyperscalers (AWS, Azure, GCP, and Microsoft's EU Data Boundary offering) that have vastly greater scale, feature breadth, and pricing power. Cloud infrastructure is capex-intensive, so margins depend heavily on utilization rates. Revenue is geographically concentrated in Sweden, and talent competition in Stockholm for cloud/DevOps engineers is intense. As an unlisted AB, disclosure is limited, making external financial assessment harder. Qualitatively, Elastx has been described in prior public references as a profitable, growing niche provider, and no distress signals (M&A under duress, layoffs, funding events) are publicly known. Ownership appears stable with founders/management. On balance, the company's resilience is moderately strong for its size, supported by favorable market positioning, but constrained by scale disadvantages and geographic concentration. Verified financials from Bolagsverket filings would be needed to refine this assessment.

Key strengths: Sovereign-cloud tailwind from EU data sovereignty concerns and post-Schrems II demand, Recurring subscription revenue model with multi-year IaaS/managed cloud contracts, Strong public-sector customer base in Sweden with high credit quality, Open source / OpenStack expertise reduces licensing costs and differentiates offering, Sustainability positioning with renewable-powered Swedish data centres, Stable ownership with founders/management, no distress signals

Risk factors: Scale disadvantage versus hyperscalers (AWS, Azure, GCP, Microsoft EU Data Boundary), Capex intensity of data-centre and hardware investment; margins depend on utilisation, Geographic concentration risk with revenue almost entirely from Sweden, Intense talent competition for cloud/DevOps engineers in Stockholm, Limited public disclosure as an unlisted AB makes external assessment harder

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report