Elastx vs SAP

Compare Elastx and SAP on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: SAP

SAP

Germany· Cloud Computing

Needs review

Shortlist SAP when you need S/4HANA-class ERP breadth under a German parent entity and can fund a structured implementation. Skip when you want lightweight self-serve finance SaaS without a transformation partner. Consider Salesforce when CRM is the system of record, or a Microsoft Dynamics / Azure-centric stack when identity and productivity are already standardised on Microsoft.

EU-operatedFull ERP suiteS/4HANA CloudISO 27001 (claimed)B2B DPA published
Elastx vs SAP: Snapshot
FeatureLogo: ElastxElastxLogo: SAPSAP
Country of originSwedenGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoYes
HeadquartersSwedenGermany
Legal entityElastx ABSAP SE, Dietmar-Hopp-Allee 16, 69190 Walldorf (Mannheim HRB 719915)
Governing lawNot listedGerman entity; order forms may name local SAP affiliates
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
EU-hosted statusNot listedPartial
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Mixed: SAP-operated data centers (including Walldorf / St. Leon-Rot, Germany) plus Enterprise Cloud Services documented on AWS, Microsoft Azure, Google Cloud Platform, or customer data centers. Product-specific subprocessor lists are primarily on My Trust Center for customers.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

German-headquartered enterprise ERP suite (SAP Cloud ERP / S/4HANA) for finance, supply chain, procurement, and HR.

Tags
At a glance: Elastx vs SAP
At a glanceLogo: ElastxElastxLogo: SAPSAP
HQStockholm, Sweden (Elastx AB)Walldorf, Germany
Founded2012Not listed
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)Enterprise subscription and licences (quote-based)
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
Legal entityNot listedSAP SE (HRB 719915 Mannheim)
Product focusNot listedCloud ERP / S/4HANA
Open sourceNot listedNo
Data residency regionsNot listedCustomer-selectable; Americas, Europe, Asia Pacific (incl. SAP DE sites and hyperscalers)
Compliance certs (claimed)Not listedISO 27001, SOC 1/2, BSI C5, plus regional attestations via Trust Center
Key capabilities: Elastx vs SAP
Key capabilitiesLogo: ElastxElastxLogo: SAPSAP
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
EU-operatedNot listedYes
Full ERP suiteNot listedYes
S/4HANA CloudNot listedYes
ISO 27001 (claimed)Not listedYes
B2B DPA publishedNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

SAP

  • SAP S/4HANA Cloud ERP core

    Public and private cloud editions cover finance, supply chain, procurement, sales, and related processes on an in-memory data model with role-based UX. Scope and extensibility differ between Public Edition (standardised) and Private Edition (closer to classic on-premises flexibility).

  • GROW and RISE packaging

    SAP GROW targets organisations starting on standardised AI-enabled cloud ERP. RISE with SAP supports existing on-premises customers migrating toward cloud with transformation services. Packaging choice drives implementation shape more than feature marketing slides.

  • Integration via SAP BTP

    SAP Business Technology Platform and Integration Suite provide APIs, iPaaS connectivity, and extension points to link SAP ERP with third-party and legacy systems. Expect integration projects rather than plug-and-play SMB connectors.

  • Selectable cloud regions and sovereign options

    Customers can choose data center regions; SAP documents Americas, Europe, and Asia Pacific availability, including SAP-operated German sites and hyperscaler regions. Sovereign / regulated options (for example German IT-Grundschutz messaging for SAP-owned facilities) exist but must be contracted explicitly.

  • Trust Center compliance artifacts

    SAP publishes ISO 27001, SOC, C5, and other certificates plus DPAs through the Trust Center and customer portals. Audit reports for specific services are often gated to customers rather than fully public PDFs.

Assurance & compliance: Elastx vs SAP
Assurance & complianceLogo: ElastxElastxLogo: SAPSAP
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Not applicable

ERP suite; not a no-logs privacy network product. Rely on SOC/ISO/C5 attestations instead.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Vendor claimed

Trust Center lists ISO 27001 certificates for cloud services and publishes certificate finder entries (e.g. Central / Enterprise Cloud Services).

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Vendor claimed

SOC 1 and SOC 2 reports described on Trust Center; many reports customer-gated via SAP for Me / My Trust Center.

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

EU parent entity; Trust Center privacy pages and DPAs reference GDPR processing terms.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

German SAP SE parent with no known US parent, but Enterprise Cloud Services explicitly include AWS, Azure, and GCP paths. Medium exposure for hyperscaler-backed tenants. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Vendor claimed

SAP states it signs DPAs; Trust Center hosts Data Processing Agreement documents for cloud, support, and professional services.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Partial

SAP publishes EU AI Act governance materials for Joule Agents and AI features; customer still must assess in-scope AI uses.

BSI C5Not listed
Vendor claimed

Trust Center lists Cloud Computing Compliance Controls Catalogue (C5) audit reports among EU regional offerings.

Considerations & known limitations: Elastx vs SAP
Considerations & known limitationsLogo: ElastxElastxLogo: SAPSAP
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Low

Public pages confirm lists exist on My Trust Center, but a full anonymous dump was not available in this research pass. Request the list for your exact cloud service before security sign-off.

OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Hyperscaler hosting is commonNot listed
Medium

Even with a German parent, many cloud tenants run on AWS, Azure, or GCP. EU region selection does not remove US-group infrastructure operators from the path. Confirm contracted region and subprocessors.

Heavy implementation programmesNot listed
Medium

S/4HANA and RISE projects typically need partners, data migration, and process redesign. Poor fit if you expected self-serve SaaS onboarding.

Catalog category is Cloud Computing, not ERPNot listed
Low

EuropeanStack has no dedicated ERP category yet. This entry is filed under Cloud Computing as the closest existing slug.

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

SAP

Best fit when

  • Midsize to large enterprises consolidating finance, supply chain, and procurement on one ERP
  • Organisations that need deep industry process templates and multi-country localisation
  • Buyers that require a German / EU parent contracting entity plus formal Trust Center attestations
  • Existing SAP ECC customers planning a RISE or S/4HANA transformation
  • Teams with budget for partner-led implementation rather than pure self-serve SaaS

Poor fit when

  • Startups or SMBs needing only simple invoicing without ERP programme overhead
  • Buyers that require a guaranteed EU-only, non-hyperscaler hosting path without reading the contract region
  • Teams seeking an open-source ERP they can fork and fully self-operate without vendor lock-in
  • CRM-first organisations where Salesforce-class customer platforms are the real system of record

Consider instead when

  • When: Your primary system of record is CRM and revenue operations, not manufacturing or complex finance

    Consider: Salesforce

    Stronger CRM depth; US parent and different compliance posture.

  • When: You already standardise on Microsoft identity, M365, and Azure and want ERP in that estate

    Consider: Microsoft 365 / Azure-centric Dynamics stacks

    Compare total cost of identity + productivity + ERP under one US vendor.

  • When: You need a smaller European mid-market ERP without S/4HANA transformation scope

    Consider: Evaluate EU mid-market ERP vendors outside this catalog (no peer ERP slug listed yet)

    Catalog currently lacks a direct European ERP alternative entry.

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

SAP

  • Which exact cloud service and region would this buyer contract (Public Edition vs Private Edition vs RISE on which hyperscaler)?
  • Will the order form be with SAP SE or a local affiliate, and which governing law clause applies?
  • Can the vendor provide the current subprocessor list and SOC/C5 reports for the specific service code without an existing customer login?