Elastx vs STACKIT

Compare Elastx and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Elastx vs STACKIT: Snapshot
FeatureLogo: ElastxElastxLogo: STACKITSTACKIT
Country of originSwedenGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwedenGermany
Legal entityElastx ABSchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawNot listedGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Elastx vs STACKIT
At a glanceLogo: ElastxElastxLogo: STACKITSTACKIT
HQStockholm, Sweden (Elastx AB)Not listed
Founded2012Not listed
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)Not listed
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Elastx vs STACKIT
Key capabilitiesLogo: ElastxElastxLogo: STACKITSTACKIT
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
EU-operatedNot listedYes
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Elastx vs STACKIT
Assurance & complianceLogo: ElastxElastxLogo: STACKITSTACKIT
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Elastx vs STACKIT
Considerations & known limitationsLogo: ElastxElastxLogo: STACKITSTACKIT
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Not listed
OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?