Elastx vs Hetzner

Compare Elastx and Hetzner on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Elastx vs Hetzner: Snapshot
FeatureLogo: ElastxElastxLogo: HetznerHetzner
Country of originSwedenGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwedenGermany
Legal entityElastx ABHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Owned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

Tags
At a glance: Elastx vs Hetzner
At a glanceLogo: ElastxElastxLogo: HetznerHetzner
HQStockholm, Sweden (Elastx AB)Gunzenhausen, Germany
Founded2012Not listed
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)Not listed
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
Legal entityNot listedHetzner Online GmbH (HRB 6089 Ansbach)
EU parksNot listedNuremberg, Falkenstein (DE); Helsinki (FI)
Optional cloud regionsNot listedAshburn and Hillsboro (US); Singapore
ModelNot listedIaaS / dedicated / hosting (unmanaged cloud and root)
Open sourceNot listedNo (commercial infrastructure)
Key capabilities: Elastx vs Hetzner
Key capabilitiesLogo: ElastxElastxLogo: HetznerHetzner
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
EU-operated (DE HQ)Not listedYes
Owned DE/FI parksNot listedYes
ISO 27001:2022Not listedYes
BSI C5 Type 2Not listedYes
Bare metal + auctionNot listedYes
Optional US/SG cloudNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

Assurance & compliance: Elastx vs Hetzner
Assurance & complianceLogo: ElastxElastxLogo: HetznerHetzner
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Not applicable

Infrastructure hosting, not an AI system product.

BSI C5 (cloud)Not listed
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

KRITIS / section 8a BSIGNot listed
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Considerations & known limitations: Elastx vs Hetzner
Considerations & known limitationsLogo: ElastxElastxLogo: HetznerHetzner
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Not listed
OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Optional US and Singapore cloud regionsNot listed
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Unmanaged cloud and dedicated serversNot listed
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Narrower managed-service catalog vs hyperscalersNot listed
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

ISO scope is DE/FI parksNot listed
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?