Elastx vs gridscale

Compare Elastx and gridscale on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: gridscale

gridscale

Germany· Cloud Computing

Needs review

Shortlist when you need a German GmbH cloud with EU/CH/AT location choice, managed Kubernetes/databases, and Hybrid Core white-label HCI. Skip when you need global hyperscaler coverage or pure lowest-cost VMs—consider Hetzner for cost-sensitive compute or AWS/Azure for worldwide breadth; use OVHcloud parent portfolio when scale across more European regions is the priority.

EU-operated (DE entity)Multi-country EU/CH locationsManaged KubernetesHybrid Core HCIBSI C5 (claimed)OVHcloud group
Elastx vs gridscale: Snapshot
FeatureLogo: ElastxElastxLogo: gridscalegridscale
Country of originSwedenGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwedenGermany
Legal entityElastx ABgridscale GmbH, Oskar-Jäger-Straße 173, 50825 Köln (HRB 97235, Amtsgericht Cologne)
Governing lawNot listedGerman law (GTC; English GTC for information only—German prevails)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Customer infrastructure marketed on European Tier 3 locations (Frankfurt multi-AZ, Eichenzell, Hannover, Paderborn, Amsterdam, Gais, Lucerne, Vienna); some Hybrid Core sites partner-operated (hosttech, rhöncloud, BAIONITY, windCORES). Privacy policy also lists US-group ancillary processors: Stripe (payments), Google Analytics/GTM, Microsoft Bing Ads, Meta, LinkedIn; Mautic on-prem DE; Recruitee NL. No public claim that primary VM storage runs on AWS/GCP/Azure.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

Cologne-based German IaaS/PaaS and Hybrid Core HCI cloud (OVHcloud group) with European locations, managed Kubernetes, and white-label private cloud options for DACH teams.

Tags
At a glance: Elastx vs gridscale
At a glanceLogo: ElastxElastxLogo: gridscalegridscale
HQStockholm, Sweden (Elastx AB)Cologne, Germany
Founded2012Not listed
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)B2B; trial then per-minute usage metering
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
Legal entityNot listedgridscale GmbH (HRB 97235)
ParentNot listedOVHcloud (100% since Sept 2023)
HostingNot listedEuropean Tier 3 sites DE/NL/CH/AT (+ partners)
Open sourceNot listedNo (API/IaC clients only)
Key capabilities: Elastx vs gridscale
Key capabilitiesLogo: ElastxElastxLogo: gridscalegridscale
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
EU-operated (DE entity)Not listedYes
Multi-country EU/CH locationsNot listedYes
Managed KubernetesNot listedYes
Hybrid Core HCINot listedYes
BSI C5 (claimed)Not listedYes
OVHcloud groupNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

gridscale

  • Panel + API + Terraform provisioning

    Deploy VMs with attached storage in seconds via the control panel or automate with the REST API and common IaC clients (Terraform, Packer). Built for teams that want both click-ops and git-ops without a hyperscaler control-plane learning curve.

  • Managed Kubernetes, databases, and load balancers

    PaaS layers cover managed Kubernetes orchestration plus fully managed databases with audit logs and automatic backups, and managed load balancers for traffic distribution—so app teams avoid running the full stack themselves.

  • S3-compatible object storage and Rocket NVMe storage

    Object storage follows S3-style APIs for backups, archives, and unstructured data, with region choice called out for GDPR-oriented placement. Rocket Storage targets high-IOPS NVMe workloads; not every Hybrid Core location exposes object storage—check the data-center matrix.

  • Per-minute GPU bare-metal for AI/ML

    GPU instances are marketed as dedicated bare-metal performance for AI/ML and data science, with CPU, RAM, and storage included and usage billed by the minute rather than only long-term reserved shapes.

  • Hybrid Core Concierge HCI and white-label cloud

    Fully managed hyperconverged packages combine hardware delivery, installation, remote operations, white-label branding/SAML options, and access to the wider gridscale location ecosystem—aimed at enterprises and hosters building private or partner clouds.

Assurance & compliance: Elastx vs gridscale
Assurance & complianceLogo: ElastxElastxLogo: gridscalegridscale
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Not applicable

IaaS/PaaS provider—not a no-logs VPN product. Request penetration-test or SOC-style reports under NDA if required.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Vendor claimed

Vendor compliance pages and chronology claim ISO/IEC 27001; obtain current certificate for verification.

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Not found

No public SOC 2 found; vendor promotes ISAE 3402 SOC 1 Type 2 instead (different standard).

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

German controller (gridscale GmbH); European location marketing; privacy policy under DS-GVO. Confirm DPA and location selection for your processing.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

EU entity, no known US parent (OVHcloud France owns group). Customer hosting marketed in EU/CH/AT. Partial because privacy recipient list includes US-group Stripe, Google Analytics/GTM, Microsoft, Meta, LinkedIn for payments/marketing. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Vendor claimed

GTC §14.2 requires a separate order-processing contract when gridscale processes personal data for the customer, finalised at latest on contract conclusion. Execute AV/DPA—do not rely on website privacy alone.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Not applicable

Infrastructure cloud; not an AI system product. GPU capacity may host customer AI workloads under shared-responsibility model.

ISO 27017 (cloud security)Not listed
Vendor claimed

Compliance page links a certificate PDF download; treat as vendor-published evidence until auditor validates.

ISO 27018 (cloud PII)Not listed
Vendor claimed

Claimed on compliance/about materials; request current scope.

ISAE 3402 SOC 1 Type 2Not listed
Vendor claimed

About chronology highlights successful ISAE 3402 SOC 1 Type 2 (incl. January 2025 call-out). Request full report.

BSI C5Not listed
Vendor claimed

Prominently listed on compliance pages; About chronology pairs C5 with January 2025 certification success. Request current attestation.

Trusted Cloud (DE)Not listed
Vendor claimed

Compliance page links Trusted Cloud service listing; verify current entry on trusted-cloud.de.

Considerations & known limitations: Elastx vs gridscale
Considerations & known limitationsLogo: ElastxElastxLogo: gridscalegridscale
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Not listed
OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Parent-group integration after OVHcloud acquisitionNot listed
Medium

100% OVHcloud ownership since 2023 may change roadmap, tooling, support model, or cross-entity data flows over time. Confirm entity, subcontractors, and exit terms for your contract generation.

Partner-operated Hybrid Core locationsNot listed
Medium

Some sites are operated with partners (hosttech, rhöncloud, BAIONITY, windCORES, etc.). Capability matrices differ (for example object storage not everywhere). Map exact location codes to SLA and subprocessor wording.

US-group ancillary processors (account/marketing)Not listed
Medium

Privacy policy lists Stripe, Google Analytics/GTM, Microsoft Bing Ads, Meta, and LinkedIn. Material for DPIAs even when VM disks stay in EU halls. Ask which tools touch production account identities versus marketing only.

Certifications need current attestation packsNot listed
Low

BSI C5, ISAE 3402, and ISO claims are vendor-published. Production security reviews should obtain dated reports rather than relying on marketing badges alone.

Narrower global footprint than hyperscalersNot listed
Low

Location set is European-weighted. Unsuitable as a drop-in for multi-continent latency or hyperscaler-only services (global CDN marketplaces, specialized managed services).

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

gridscale

Best fit when

  • DACH mid-market teams wanting German contracting plus managed PaaS (Kubernetes, databases, load balancers)
  • MSPs and hosters needing white-label branding, multi-tenant accounts, and optional Hybrid Core hardware
  • Workloads that must pick DE/NL/CH/AT regions with Tier 3 marketing claims and green-energy positioning
  • AI/ML or data-science jobs that need GPU bare-metal with per-minute metering
  • Buyers who value panel + API/Terraform over hyperscaler IAM sprawl

Poor fit when

  • Global multi-region applications that need hyperscaler edge, marketplace services, or non-European regions
  • Teams optimising only for lowest bare VM or dedicated-server unit cost (evaluate Hetzner first)
  • Buyers requiring public SOC 2 Type II specifically rather than ISAE 3402 SOC 1 Type 2 / BSI C5 packs
  • Organisations that forbid any US-group ancillary processors (Stripe/Google marketing tools appear in the privacy recipient list)

Consider instead when

  • When: You need the broader European hyperscale portfolio and more regions under one group brand

    Consider: OVHcloud

    OVHcloud is the parent group; gridscale stays the HCI/panel-focused product line

  • When: Cost-sensitive VMs or dedicated servers dominate and you do not need Hybrid Core white-label

    Consider: Hetzner

    Hetzner typically wins raw price/performance for simple compute

  • When: France-centric developer cloud with different location and product skew

    Consider: Scaleway

    Compare ARM options and FR footprint versus gridscale DACH Hybrid Core

  • When: Swiss-rooted EU cloud positioning is the primary evaluation criterion

    Consider: Exoscale

    Still compare DE/CH site maps and managed service depth side by side

  • When: You need worldwide regions, marketplace depth, or US-public-sector cloud programmes

    Consider: Amazon Web Services (AWS) or Microsoft Azure

    Trade EU-entity simplicity for hyperscaler breadth and US ownership path

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

gridscale

  • Will gridscale execute your template AV/DPA and attach a location-specific subprocessor list for the regions you enable?
  • What is the current scope and report date for BSI C5 and ISAE 3402 SOC 1 Type 2 covering the services you will buy?
  • Which privacy-policy third parties process production account/identity data versus website marketing only?
  • How are OVHcloud group affiliates involved in support, billing, or platform operations for gridscale customers post-acquisition?
  • For Hybrid Core partner sites, who is the data-center operator of record and what audit rights apply?