Elastx vs Hetzner

Vergleichen Sie Elastx und Hetzner nach Funktionen, Rechtsraum, Nachweisen und Einsatzpassung.

Beide als Alternativen zu: Amazon Web Services (AWS), Microsoft Azure

Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Elastx vs Hetzner: Überblick
MerkmalLogo: ElastxElastxLogo: HetznerHetzner
HerkunftslandSwedenGermany
KategorieCloud ComputingCloud Computing
Open SourceNeinNein
Self-HostedNeinNein
HauptsitzNicht angegebenGermany
RechtsträgerNicht angegebenHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
US-Mutter / KontrolleNicht angegebenKeine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)Nicht angegebenMittel
Hosting / ResidenzNicht angegebenOwned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.
Zusammenfassung

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

Tags
Auf einen Blick: Elastx vs Hetzner
Auf einen BlickLogo: ElastxElastxLogo: HetznerHetzner
HQNicht angegebenGunzenhausen, Germany
Legal entityNicht angegebenHetzner Online GmbH (HRB 6089 Ansbach)
EU parksNicht angegebenNuremberg, Falkenstein (DE); Helsinki (FI)
Optional cloud regionsNicht angegebenAshburn and Hillsboro (US); Singapore
ModelNicht angegebenIaaS / dedicated / hosting (unmanaged cloud and root)
Open sourceNicht angegebenNo (commercial infrastructure)
Key capabilities: Elastx vs Hetzner
Key capabilitiesLogo: ElastxElastxLogo: HetznerHetzner
EU-operated (DE HQ)Nicht angegebenJa
Owned DE/FI parksNicht angegebenJa
ISO 27001:2022Nicht angegebenJa
BSI C5 Type 2Nicht angegebenJa
Bare metal + auctionNicht angegebenJa
Optional US/SG cloudNicht angegebenJa

Elastx

  • Three Swedish Availability Zones for High Availability

    Elastx spreads infrastructure across three zones, each 20 km apart, ensuring no single failure impacts services. This supports active-active setups and automatic failover. Triple redundancy protects data, with built-in backups and disaster recovery options. Customers report seamless operations during outages elsewhere.

  • Open-Source IaaS with OpenStack and Kubernetes

    The platform uses OpenStack for virtual machines, block/object storage, and networking. Kubernetes CaaS handles container orchestration, with managed clusters including auto-scaling and load balancers. Documentation covers persistent volumes, ingress controllers, and integrations like cert-manager. No proprietary tech means easy migration.

  • Advanced Security and DBaaS

    DDoS protection, WAF, threat intelligence, and encryption come standard. DBaaS supports MySQL, PostgreSQL, MariaDB, Redis, Valkey, and MSSQL, with automated backups, scaling, and observability metrics. Firewalls, TLS, and role-based access align with enterprise needs. ISO certifications verify compliance processes.

  • Flexible Pricing and Sustainability

    Pay hourly for resources used, with no contracts or egress fees for common scenarios. Included services reduce surprise costs. Green electricity powers data centers, meeting ISO 14001 standards. Support tiers offer 24/7 access for critical users.

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

Assurance & compliance: Elastx vs Hetzner
Assurance & complianceLogo: ElastxElastxLogo: HetznerHetzner
Independent security / no-logs auditNicht angegeben
Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

ISO 27001Nicht angegeben
Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

SOC 2 / SOC 3Nicht angegeben
Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

GDPR / EU data protectionNicht angegeben
Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

US CLOUD Act exposure (indicative)Nicht angegeben
Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Data processing agreement (B2B)Nicht angegeben
Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

EU AI ActNicht angegeben
Not applicable

Infrastructure hosting, not an AI system product.

BSI C5 (cloud)Nicht angegeben
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

KRITIS / section 8a BSIGNicht angegeben
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Considerations & known limitations: Elastx vs Hetzner
Considerations & known limitationsLogo: ElastxElastxLogo: HetznerHetzner
Optional US and Singapore cloud regionsNicht angegeben
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Unmanaged cloud and dedicated serversNicht angegeben
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Narrower managed-service catalog vs hyperscalersNicht angegeben
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

ISO scope is DE/FI parksNicht angegeben
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Passung

Elastx

Best fit when

Nicht angegeben

Poor fit when

Nicht angegeben

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

Open questions for due diligence

Elastx

Nicht angegeben

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?