Elastx vs Open Telekom Cloud

Compare Elastx and Open Telekom Cloud on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: Open Telekom Cloud

Open Telekom Cloud

Germany· Cloud Computing

Needs review

Shortlist when you need a German Telekom/T-Systems OpenStack public cloud with DE/NL/CH regions and a strong BSI C5/ISO/TISAX package for regulated or public-sector workloads. Skip when you need hyperscaler global PaaS breadth or pure self-hosted OpenStack—consider OVHcloud, Scaleway, or AWS/Azure for those cases.

EU-operated (T-Systems)OpenStack public IaaSBSI C5 Type II (claimed)DE / NL / CH regionsGPU + ModelArts AIPay-as-you-go
Elastx vs Open Telekom Cloud: Snapshot
FeatureLogo: ElastxElastxLogo: Open Telekom CloudOpen Telekom Cloud
Country of originSwedenGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwedenGermany
Legal entityElastx ABT-Systems International GmbH (Deutsche Telekom group); product marketed as T Cloud Public / Open Telekom Cloud
Governing lawNot listedGerman / EU law for the cloud service (confirm contract)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Primary: Telekom/T-Systems twin-core data centers in Germany (Biere/Magdeburg), Netherlands (Amsterdam region), and Switzerland (Bern/Zollikofen). No public indication that AWS, Azure, or GCP is the primary IaaS host. Backups/DR via platform multi-AZ services. Full public subprocessor table not found—request DPA annex. Historical Huawei technology partnership is supply-chain diligence, not US-cloud hosting.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

Deutsche Telekom / T-Systems sovereign European public cloud (now marketed as T Cloud Public): OpenStack-based IaaS and platform services in Germany, Netherlands, and Swiss regions with BSI C5, ISO, and SOC attestations.

Tags
At a glance: Elastx vs Open Telekom Cloud
At a glanceLogo: ElastxElastxLogo: Open Telekom CloudOpen Telekom Cloud
HQStockholm, Sweden (Elastx AB)Not listed
Founded2012Not listed
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)Pay-as-you-go (+ optional discounts/reservations)
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
HQ / operatorNot listedGermany — T-Systems / Deutsche Telekom
Current brandNot listedT Cloud Public (formerly Open Telekom Cloud)
PlatformNot listedOpenStack-based public cloud
RegionsNot listedGermany (Biere/Magdeburg), Netherlands, Switzerland
Self-hostNot listedNo — managed public cloud
Key capabilities: Elastx vs Open Telekom Cloud
Key capabilitiesLogo: ElastxElastxLogo: Open Telekom CloudOpen Telekom Cloud
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
EU-operated (T-Systems)Not listedYes
OpenStack public IaaSNot listedYes
BSI C5 Type II (claimed)Not listedYes
DE / NL / CH regionsNot listedYes
GPU + ModelArts AINot listedYes
Pay-as-you-goNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

Open Telekom Cloud

  • OpenStack public cloud with Elastic Cloud Server and GPUs

    Self-service IaaS on OpenStack: Elastic Cloud Server flavors from general-purpose to GPU shapes for AI/ML and graphics, plus Dedicated Host and Bare Metal where the region supports them. Provision via console, API, or automation; Auto Scaling for metric-driven capacity. Suited to production VMs and hybrid patterns that need European operator control rather than a thin VPS plan.

  • Multi-AZ object, block, and file storage in EU regions

    Object Storage Service provides S3-compatible multi-AZ object storage; Elastic Volume Service attaches block disks with snapshots; Scalable File Service offers NFS shared filesystems. Cloud Backup and Recovery and related services back up VMs and volumes into platform object storage. Pin workloads to DE, NL, or Swiss regions according to residency policy.

  • VPC networking, Direct Connect, and security services

    Virtual Private Cloud isolation, Elastic Load Balancer, VPN, NAT, Enterprise Router, and Direct Connect for high-bandwidth hybrid links. Security stack includes Anti-DDoS, WAF, Cloud Firewall, Host Security Service, and Key Management Service with bring-your-own-key options—useful for regulated network architectures without leaving Telekom-operated regions.

  • Cloud Container Engine and managed data services

    Cloud Container Engine runs Kubernetes-managed clusters and images; companion services cover container instances and registries. Relational Database Service supports MySQL, PostgreSQL, and Microsoft SQL with HA and backup patterns; document, cache (Redis-class), MapReduce, and search services extend the data plane. Service availability differs between DE and NL—check the regional matrix before design freezes.

  • ModelArts and sovereign AI positioning

    ModelArts provides an end-to-end AI development path (data prep, training, deployment) on European infrastructure, with GPU-backed instances for training and inference. Aimed at teams that want model and training-data residency under the same European operator as their IaaS—confirm which AI services exist in your chosen region (several AI offerings are DE-focused).

  • Twin-core European data centers (DE, NL, CH)

    Published regions: twin-core Germany (Biere/Magdeburg), Netherlands (Amsterdam area), and Switzerland (Bern/Zollikofen) for Swiss data residency. Vendor claims geo-redundant twin-core design, high availability targets, and renewable-powered German facilities. Not a global multi-continent footprint—by design for European sovereignty shortlists.

Assurance & compliance: Elastx vs Open Telekom Cloud
Assurance & complianceLogo: ElastxElastxLogo: Open Telekom CloudOpen Telekom Cloud
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Not applicable

IaaS platform—not a no-logs consumer VPN. Independent assurance is via ISO/SOC/C5-style audits rather than a no-logs report.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Vendor claimed

Vendor certifications page links ISO/IEC 27001 umbrella certificate PDF for download; re-verify serial/date in procurement.

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Vendor claimed

SOC 2 Type II (request report); SOC 3 public PDF linked on certifications page. SOC 1 Type II also claimed.

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

EU operator, EU/CH regions, ISO 27018/27701 claims, DPA language on marketing pages—confirm signed DPA for your entity.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

German Telekom/T-Systems operator, no known US parent of the cloud business, primary hosting on Telekom EU/CH data centers (not AWS/GCP/Azure). Not a legal clearance of zero extraterritorial risk. Historical Huawei tech partnership is separate supply-chain diligence. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Vendor claimed

Vendor GDPR pages state DPA, TOMs, and audit reports available for B2B; obtain current signed pack—not fully self-serve public template verified here.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Partial

Platform offers AI services (ModelArts) that may fall under customer AI Act obligations; OTC itself is infrastructure—not an automated high-risk AI system assessment by EuropeanStack.

ISO/IEC 27017 (cloud security)Not listed
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

ISO/IEC 27018 (cloud PII)Not listed
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

BSI C5 Type IINot listed
Vendor claimed

Vendor claims BSI C5:2020 Type II (ISAE 3000); detailed report typically on request via audit-reports download flow.

TISAX Level 3Not listed
Vendor claimed

Vendor states TISAX Level 3 for Germany and Netherlands regions.

Considerations & known limitations: Elastx vs Open Telekom Cloud
Considerations & known limitationsLogo: ElastxElastxLogo: Open Telekom CloudOpen Telekom Cloud
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Not listed
OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Historical Huawei technology partnershipNot listed
Medium

Platform launched with Huawei hardware/software partnership; residual stack components may still matter for sensitive public-sector RFPs. T-Systems states independent operation. Review supply-chain docs under NDA.

Service catalog differs by regionNot listed
Medium

Several services (e.g. ModelArts, bare metal, some database/analytics SKUs) are unavailable in NL or limited to DE. Design against the live regional matrix, not the full marketing list.

Limited public subprocessor tableNot listed
Low

Unlike some SaaS vendors, a complete public subprocessor inventory was not found on marketing pages. Request DPA annex and subcontractor list before high-assurance processing.

Smaller global ecosystem than AWS/Azure/GCPNot listed
Low

Expect fewer regions, fewer proprietary PaaS services, and a smaller marketplace than US hyperscalers. Migration tools and partner ecosystem exist but differ in depth.

Brand transition OTC → T Cloud PublicNot listed
Low

Documentation, console URLs, and community still mix Open Telekom Cloud and T Cloud Public names. Factor rebrand into runbooks and vendor risk registers.

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

Open Telekom Cloud

Best fit when

  • German public sector and regulated buyers needing Telekom-group operator plus BSI C5 / ISO package
  • Enterprises pinning workloads to DE, NL, or Swiss twin-core regions under GDPR (and Swiss DSG where relevant)
  • Teams wanting OpenStack-based IaaS with ECS, object/block storage, VPC, and Kubernetes (CCE) without US hyperscaler residency defaults
  • AI/ML projects that require GPU capacity and ModelArts-class tooling with European data residency messaging
  • Hybrid architectures using Direct Connect / VPN into Telekom data centers with 24/7 European support expectations

Poor fit when

  • Workloads that require dozens of global regions or deep proprietary hyperscaler PaaS catalogs
  • Buyers seeking a free self-hosted OpenStack distribution rather than a commercial public cloud
  • Teams that need every service in every region—several AI, bare-metal, and data services are DE-only or limited
  • Organisations that reject any non-European technology supply chain without further review (historical Huawei partnership)

Consider instead when

  • When: You need extensive bare-metal catalogs and a very large multi-country EU footprint

    Consider: OVHcloud

    Different operator (France) and product packaging; compare bare-metal and region maps.

  • When: You prefer developer-centric European cloud packaging outside the Telekom stack

    Consider: Scaleway or Exoscale

    Scaleway for FR/NL-oriented developer UX; Exoscale for Swiss multi-zone IaaS + managed K8s.

  • When: You need global regions, marketplace depth, or proprietary PaaS only hyperscalers provide

    Consider: AWS, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and multi-region complexity in exchange for breadth.

  • When: You want German-market hosting adjacency with a different commercial/product mix

    Consider: IONOS

    Often compared for German buyers; validate IaaS depth vs OTC enterprise cloud features.

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

Open Telekom Cloud

  • Will T-Systems provide the current full subprocessor/subcontractor list and signed DPA annex for our legal entity and region?
  • What is the residual Huawei (or other non-EU) component inventory for the regions we will use, and is it acceptable under our procurement policy?
  • Which services in our target architecture are available in DE vs NL vs Swiss regions with which SLAs?
  • Can we obtain current C5 Type II and SOC 2 reports (not only marketing claims and SOC 3 summary) under NDA?
  • For AI workloads, which ModelArts/GPU SKUs and data paths apply, and how do they map to our EU AI Act role?