NodeX Cloud AB
Sweden · owned by Independent (Sweden) · nodexcloud.org · 7 vendors
NodeX Cloud AB is a Lund University spinout based at MINC Incubator in Malmö, Sweden, developing decentralized cloud storage infrastructure secured with post-quantum cryptography (Kyber1024 / ML-KEM) and Reed-Solomon erasure coding. The company offers an S3-compatible storage proxy designed for EU-regulated enterprises in healthcare, defense, banking, and government, ensuring compliance with GDPR, NIS2, and DORA regulations. It has filed two patents at the Swedish Patent Office (PRV), built on over four years of academic cryptography research.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 3
- Financial Resilience: 3
Technology vendors
- GoDaddy Inc. — Technology — United States
- Looker — Technology — United States
- Veeam Software Group GmbH — Technology — United States
- and 4 more
Insights
Last updated 2026-08-18 · revision 4
7 direct vendors, 140 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
Subvendors by controlling owner country (sample)
- China: 3
- Denmark: 2
- Brazil: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
NodeX Cloud AB demonstrates medium migration readiness. On the positive side, its internal tech stack, including Google Cloud Storage, and key technologies like an S3-Compatible API and Decentralized Node Architecture, suggest a relatively modern and adaptable infrastructure. The S3-compatible API, in particular, helps mitigate vendor lock-in to a specific cloud storage provider, offering flexibility for potential migrations. However, significant challenges arise from the company's core business and regulatory environment. NodeX Cloud AB's focus on 'EU Data Sovereignty / Geo-Fencing' and compliance with GDPR, NIS2, and DORA implies stringent and complex data residency and regulatory requirements. While 'Data Residency Requirements' are listed as 'Unknown - Assessment Required', the company's product descriptions strongly indicate strict requirements, which would substantially increase the complexity, cost, and risk associated with any migration. The 100% revenue concentration on a single product could also impact the financial stability and ability to fund a large-scale migration. The vendor data is contradictory ('Total Vendors: 0' vs. listed vendor HQ countries and use of GCS); however, if there are few critical vendors, managing these relationships during migration might be simpler, but the dependency on them remains a factor.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
NodeX Cloud AB is a cloud storage infrastructure provider — the exact profile for which SOC 2 was designed. Enterprise customers in regulated sectors (healthcare, banking, defense, government) routinely require SOC 2 Type II reports as a condition of vendor onboarding. As an early-stage company targeting regulated enterprise customers, the absence of a SOC 2 report represents a significant commercial and risk barrier. SOC 2 is not legally mandated in the EU but is a de facto market requirement for cloud service providers selling to enterprise and regulated-sector customers globally. Risk is Medium because non-compliance does not carry regulatory fines but creates material business risk (lost contracts, failed vendor assessments).
Evidence: https://nodexcloud.org, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
Swedish Patent Law — Assessment Required
NodeX Cloud AB has filed two patents at the Swedish Patent Office (PRV). Patent protection is relevant to the company's IP strategy and competitive positioning but does not represent a compliance risk in the traditional regulatory sense. Risk is Low as patent filing is a proactive IP protection measure, not a compliance obligation.
Evidence: https://nodexcloud.org, https://www.prv.se/en/
EHDS — Assessment Required
NodeX Cloud AB explicitly targets healthcare as a primary use case ('healthcare records'). The European Health Data Space (EHDS) Regulation entered into force in March 2025 and establishes rules for the use and sharing of health data across the EU. Cloud storage providers handling health data for EU healthcare organizations will be subject to EHDS requirements, including data quality, interoperability, and security standards. Risk is Medium because EHDS is newly enacted and implementation timelines are phased, but healthcare is a stated primary market for NodeX.
Evidence: https://nodexcloud.org, https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space_en, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32025R0327
Financials
Financial Resilience Score: 3/10
NodeX Cloud AB is a very early-stage Swedish deep-tech startup, a Lund University spinout housed at MINC Incubator in Malmö. No verifiable financial figures were obtainable, but the qualitative profile suggests a pre-revenue or earliest-commercial-phase company that is almost certainly loss-making and dependent on external funding rounds. Runway rather than profitability is the key financial metric at this stage. The company benefits from strong regulatory tailwinds (NIS2, DORA, GDPR) that create mandatory demand for EU-sovereign, encryption-strong storage. Its post-quantum readiness via NIST-standardized ML-KEM (Kyber) is a credible technical differentiator, and its academic lineage with two PRV patent filings suggests defensible technology. However, patents are only filed (not granted), and the company faces long procurement cycles (12-24+ months) in its target sectors of healthcare, defense, banking, and government. Competitive pressure is significant from sovereign-cloud players (OVHcloud, Scaleway, Exoscale, Elastx, Safespring, Cleura) and storage-specific competitors (Wasabi, Backblaze B2, MinIO, Cubbit), as well as hyperscaler sovereign offerings. Customer concentration risk is high at this stage, and cryptography/distributed-systems talent in Sweden is scarce and expensive. The low resilience score reflects the typical fragility of a seed/pre-Series A deep-tech startup.
Key strengths: Regulatory tailwind from NIS2, DORA, and GDPR creating mandatory demand, Post-quantum encryption (Kyber1024/ML-KEM) as technical differentiator vs hyperscalers, Academic IP moat from Lund University with two PRV patent filings, MINC Incubator support providing network and soft-funding pathways (Vinnova, EIC Accelerator, Eurostars), S3-compatible API lowers switching cost for prospects
Risk factors: Stage risk: almost certainly loss-making and dependent on external funding, Long sales cycles (12-24+ months) in healthcare, defense, banking, government, Intense competition from OVHcloud, Scaleway, Elastx, Safespring, Cleura, Wasabi, Backblaze, MinIO, Cubbit, and hyperscaler sovereign offerings, High customer concentration risk with likely handful of pilot customers, Scarce and expensive cryptography and distributed-systems talent in Sweden, Patent uncertainty - filings may be narrowed or rejected, Single product line concentration (~100% on S3-compatible sovereign storage proxy)
Revenue by product/service
- S3-compatible sovereign storage proxy: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.