Elastx vs UpCloud

Compare Elastx and UpCloud on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Elastx

Elastx

Sweden· Cloud Computing

Needs review

Shortlist Elastx when you need a Sweden-only OpenStack public cloud with multi-AZ managed Kubernetes and DBaaS under a Swedish AB and self-operated Stockholm data centers. Skip when you need many global regions, hyperscaler managed-service breadth, or live migration as a platform feature—consider UpCloud, Scaleway, OVHcloud, or Azure/AWS instead depending on sovereignty vs scale tradeoffs.

Swedish OpenStack IaaSMulti-AZ managed KubernetesManaged DBaaSISO 27001/27017/27018 (claimed)Sweden data residencyHourly, no lock-in contracts
Logo: UpCloud

UpCloud

Finland· Cloud Computing

Needs review

Shortlist UpCloud when you want Finnish-contracted IaaS with MaxIOPS storage, CNCF Managed Kubernetes, managed open-source databases, and customer-pinned EU regions—plus optional global PoPs. Skip when you need hyperscaler-only PaaS depth or the absolute lowest bare-metal VPS pricing; consider Hetzner, Scaleway, or AWS/Azure/GCP depending on that gap.

Finnish-operated IaaSMaxIOPS block storageCNCF Managed KubernetesISO 27001 (claimed)Selectable EU regionsZero-cost egress policy
Elastx vs UpCloud: Snapshot
FeatureLogo: ElastxElastxLogo: UpCloudUpCloud
Country of originSwedenFinland
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwedenFinland
Legal entityElastx ABUpCloud Oy (Business ID 2431560-5), Aleksanterinkatu 15 B, 00100 Helsinki
Governing lawNot listedFinland (Terms of Service; arbitration Helsinki)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencySelf-operated Swedish Tier 3 data centers; primary region se-sto with three Stockholm-area AZs (~20 km apart). Customer platform data documented as staying in Sweden; Swift object storage triple-replicated across AZs. Not sold as AWS/Azure/GCP regions. Website analytics: Piwik PRO. Optional products (Varnish CDN beta, Virtuozzo PaaS software, hybrid Cloud Connect/Exchange to other clouds) may add separate paths—confirm in DPA. No public full subprocessor inventory found.Customer-selected regions across 15 DCs (EU majority: FI, SE, NO, DK, DE, NL, ES, PL, UK; plus US-CHI/NYC/SJO, SG, AU) in colocations (Equinix, Digital Realty, CoreSite, Telia, Verne, Green Mountain, etc.). Customer Data stays in chosen DC. Vendor: EU VMs have no customer-data subprocessors; group subsidiaries only otherwise. Account data in Finland with global support access (incl. US/SG). Payments/hCaptcha are separate third parties.
Summary

Swedish cloud provider (Elastx AB) offering OpenStack IaaS, managed Kubernetes, DBaaS, and related services with data and operations kept in Sweden across three Stockholm availability zones.

Finnish IaaS from UpCloud Oy (Helsinki): MaxIOPS block storage, Cloud Servers, managed Kubernetes and databases across 15 global regions with customer-selected residency.

Tags
At a glance: Elastx vs UpCloud
At a glanceLogo: ElastxElastxLogo: UpCloudUpCloud
HQStockholm, Sweden (Elastx AB)Helsinki, Finland
Founded20122011
Primary regionse-sto — 3 AZs in Stockholm areaNot listed
Core stackOpenStack IaaS, Kubernetes CaaS, DBaaSNot listed
Commercial modelHourly usage; no long-term lock-in contracts (vendor)Hourly pay-as-you-go; trial credits; zero-cost egress policy
OwnershipSwedish PE Sobro majority (~53%); no known US parentNot listed
Legal entityNot listedUpCloud Oy (2431560-5)
RegionsNot listed15 DCs / 12 countries (EU-heavy + US/APAC)
Open sourceNot listedNo (platform proprietary)
Self-hostedNot listedNo (public/private cloud IaaS)
Key capabilities: Elastx vs UpCloud
Key capabilitiesLogo: ElastxElastxLogo: UpCloudUpCloud
Swedish OpenStack IaaSYesNot listed
Multi-AZ managed KubernetesYesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Sweden data residencyYesNot listed
Hourly, no lock-in contractsYesNot listed
Finnish-operated IaaSNot listedYes
MaxIOPS block storageNot listedYes
CNCF Managed KubernetesNot listedYes
ISO 27001 (claimed)Not listedYes
Selectable EU regionsNot listedYes
Zero-cost egress policyNot listedYes

Elastx

  • OpenStack IaaS across three Stockholm AZs

    Full virtual data center on OpenStack (Nova/Neutron/Cinder/Swift/Octavia/Barbican and related services): KVM instances, security groups, encrypted block and object storage, load balancers, and HSM-backed secrets. Primary region se-sto uses three separate data centers up to ~20 km apart; you pick AZ per resource. Marketplace-validated OpenStack public cloud; hourly metering. No live migration—design for multi-AZ yourself.

  • Managed multi-AZ Kubernetes (CNCF-certified)

    Private Kubernetes clusters on Elastx OpenStack with at least three control-plane and three worker nodes spread across all three AZs. Fully managed option includes 24×7 cluster monitoring and planned rolling upgrades; non-managed includes office-hours upgrades/support without continuous monitoring. CNCF Certified Kubernetes Platform listing; OpenStack integration for persistent volumes and load balancers. Minimum production footprint is non-trivial—test clusters available under different terms.

  • Managed DBaaS with multi-engine choice

    Self-service datastores for MariaDB, MySQL, PostgreSQL, Microsoft SQL Server, and Valkey with automated provisioning, metrics UI, IP allowlisting, and MFA (TOTP/YubiKey) via Elastx Identity Provider. Single-node or primary plus one/two read replicas; multi-node layouts and backups use multiple Swedish AZs with automatic failover options. Backups land in triple-replicated Swift object storage. Customer owns query design, extra users/DBs, and restore decisions.

  • Platform security defaults and Swedish ops

    Included L3/L4 DDoS protection, threat intelligence blocking, encryption at rest for ephemeral/volume/object storage, encrypted inter-AZ links, and HSM-backed secret management. Data centers described as Tier 3 with 24×7 staffing; staff described as Swedish citizens with annual background checks. Suits regulated buyers who want baseline controls without buying each security add-on separately—still shared responsibility for OS and app hardening on IaaS.

  • GPU and AI workloads on Swedish infrastructure

    NVIDIA Ampere-class and related GPU flavors on OpenStack and Kubernetes for AI, analytics, and HPC-style jobs, plus an AI services offering framed around Swedish digital sovereignty and regulatory control. Useful when models or training data must stay in Sweden; not a substitute for evaluating the separate AI product scope, model licenses, or EU AI Act classification for your use case.

UpCloud

  • MaxIOPS clustered block storage

    In-house all-flash block tier rated up to ~100,000 read IOPS at 4K, separate from compute hosts, with Standard and Archive tiers for capacity. Attach up to 16 devices per server (up to 64 TB total); encryption at rest optional. Suits databases and I/O-heavy apps that outgrow commodity cloud disks.

  • Cloud Servers on AMD EPYC with automation

    Linux/Windows VMs with Starter, Premium, and Cloud Native plan families, hot resize options, firewall, utility and SDN private networking. Full lifecycle via control panel, REST API, CLI, Terraform/OpenTofu, Pulumi, and Crossplane—for teams automating fleets rather than clicking one-off VPS.

  • CNCF Managed Kubernetes (UKS)

    Managed control planes with CNCF-certified Kubernetes versions, autoscaler integration, CSI block volumes, load-balancer integration, and private-only clusters. Worker nodes use ordinary Cloud Server plans including Private Cloud hosts—good fit when you want K8s without running etcd yourself.

  • Managed PostgreSQL, MySQL, Valkey, OpenSearch

    Turnkey databases with automated backups, multi-node HA options, private utility/SDN connectivity, and point-in-time recovery on relational plans. Reduces ops load for product teams that still want open engines rather than proprietary hyperscaler databases.

  • Customer-selected global regions (EU-first footprint)

    Fifteen data centers across twelve countries: dense Northern/Central Europe (Helsinki x2, Stockholm, Stavanger, Copenhagen, Amsterdam, Frankfurt, Madrid, Warsaw, London) plus US, Singapore, and Sydney. Customer Data stays in the chosen zone unless you request a move—use EU zones for residency programmes.

  • Zero-cost egress packaging and 99.999% SLA line

    Public pricing emphasises no per-GB internet egress charges under a Fair Transfer Policy, plus Premium-class 99.999% SLA with service credits for unscheduled downtime. Simplifies bills for chatty APIs and multi-service architectures compared with classic egress meters—confirm fair-use limits for extreme transfer cases.

Assurance & compliance: Elastx vs UpCloud
Assurance & complianceLogo: ElastxElastxLogo: UpCloudUpCloud
Independent security / pen-test audit (public)
Not found

No public independent audit PDF or pen-test report located; ISO management-system claims are separate.

Vendor claimed

Vendor states cloud services audited against Finnish PiTuKri criteria by an independent firm; ISO 27001 ISMS regularly audited. Public PiTuKri report not fully reproduced on marketing pages—request artefacts.

ISO 27001 / 27017 / 27018
Vendor claimed

Vendor states ISO 27001 since 2015 and current 27017/27018; request current certificates. Badge marked claimed.

Vendor claimed

Vendor asserts ISO 27001 certified ISMS and publishes certificate PDF; independent registry re-check not completed in this draft.

ISO 14001 (environmental)
Vendor claimed

Vendor claims ISO 14001 with green electricity; Green Web Foundation badge linked on site.

Not listed
SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on official product/trust pages reviewed.

Not found

Facility providers list SOC reports; no clear first-party UpCloud SOC 2 Type II product claim found on compliance pages reviewed.

GDPR / EU data protection
Vendor claimed

Swedish AB; privacy policy; Sweden data residency claims; DPA path advertised. Confirm processor role wording in contract.

Vendor claimed

Finnish controller/processor under GDPR; customer chooses region; DPA in ToS; CISPE Code of Conduct adherence claimed.

US CLOUD Act exposure (indicative)
Partial

Swedish entity, no known US parent, self-operated SE DCs—not AWS/GCP/Azure primary hosting. Vendor claims Cloud Act–free. Public subprocessor inventory not found; optional hybrid links/CDN/SaaS tools can change residual risk. Indicative only—not legal advice.

Partial

Finnish entity / no known US parent; EU-region VMs can avoid US storage. Material exceptions: optional US DCs, US/SG support affiliates for account ops, US colocations if selected. Assessment not a vendor safety claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

About page: ISO certifications and ability to enter DPAs for GDPR personal data. Obtain signed DPA + subprocessors in procurement.

Vendor claimed

DPA incorporated into Terms of Service; binding on acceptance without separate signature per vendor.

EU AI Act
Not applicable

Core offering is IaaS/CaaS/DBaaS. Separate AI services exist—classify your own AI use case under the AI Act if applicable.

Not applicable

General-purpose IaaS/platform; not an AI system provider by primary product.

CISPE Code of ConductNot listed
Vendor claimed

Vendor states adherence to CISPE data protection code for cloud infrastructure providers.

Considerations & known limitations: Elastx vs UpCloud
Considerations & known limitationsLogo: ElastxElastxLogo: UpCloudUpCloud
No public subprocessor inventory
Medium

Marketing/docs emphasize Swedish operations and ISO, but a complete public subprocessor list was not found. Request it with the DPA before treating residual transfer risk as zero.

Not listed
OpenStack operational constraints
Medium

No live migration; no cross-AZ volume migration while attached; one router per project; floating-IP hairpin limits. Multi-AZ designs must be intentional—not automatic failover of every pattern.

Not listed
Sweden-centric footprint
Low

Primary strength is Swedish residency; teams needing many non-Swedish regions will outgrow the geography and should evaluate multi-country EU clouds or hyperscalers.

Not listed
ISO claims need certificate pack
Low

ISO 27001/27017/27018/14001 are vendor-claimed publicly; independent public audit PDFs for no-logs/pen-test not found. Procurement should verify current certificates.

Not listed
Optional non-EU regions and support accessNot listed
Medium

US, Singapore, and Sydney zones are first-class options. Mis-pinned workloads or defaults can place Customer Data outside the EU. Account information is accessible to non-EEA support staff even when VMs stay in Europe.

Narrower catalogue than hyperscalersNot listed
Low

Strong IaaS and focused managed services; missing many proprietary AWS/Azure/GCP PaaS and AI products. Multi-cloud or dual-vendor designs may still be required.

Limited public SOC 2 for UpCloud entityNot listed
Medium

ISO 27001 and PiTuKri claims are published; a customer-facing SOC 2 Type II for UpCloud itself was not found. Enterprise questionnaires may need NDA artefacts or reliance on ISO plus facility reports.

Colocation facility dependencyNot listed
Low

Platform runs in third-party data centres. Facility certifications differ by site; treat them as complementary to UpCloud’s own ISMS, not a substitute for vendor due diligence.

Fair Transfer Policy on zero egressNot listed
Low

Zero-cost egress is a commercial differentiator but is governed by a Fair Transfer Policy—extreme or abusive transfer patterns may fall outside the marketing promise. Validate for CDN-scale or bulk egress designs.

Fit

Elastx

Best fit when

  • Organizations that must keep infrastructure and personal data processing in Sweden under a Swedish legal entity
  • Platform teams that want OpenStack APIs, Terraform-friendly IaaS, and open standards without commercial lock-in contracts
  • Teams needing CNCF-aligned private Kubernetes with control planes and workers across three Swedish AZs
  • Product teams wanting managed MariaDB/MySQL/PostgreSQL/MSSQL/Valkey with multi-AZ options and object-storage backups
  • Buyers who value included baseline security (DDoS, threat intel, encryption at rest, HSM secrets) and 24×7 Swedish support

Poor fit when

  • Workloads that require many regions outside Sweden or a hyperscaler-scale SaaS/marketplace ecosystem
  • Architectures that depend on live migration or transparent cross-AZ volume moves (not supported)
  • Teams that only need a few simple VMs and prefer a minimal global UI over OpenStack operational depth
  • Buyers who require published independent pen-test/no-logs audit packs before shortlisting (not found publicly)

Consider instead when

  • When: You need high-performance IaaS across multiple European countries with a simpler product surface

    Consider: UpCloud

    Less Sweden-only OpenStack/K8s packaging; stronger multi-country footprint.

  • When: You want broad EU/FR developer cloud (bare metal, serverless, many regions) rather than Sweden-only OpenStack

    Consider: Scaleway or OVHcloud

    Different sovereignty and product mixes; not a drop-in OpenStack twin.

  • When: You need global regions and the deepest managed-service catalogs despite US CLOUD Act exposure

    Consider: Microsoft Azure or AWS

    Opposite sovereignty tradeoff.

  • When: Your RFP is pure Swedish public-sector OpenStack peers

    Consider: Cleura or Safespring (evaluate off-catalog if not listed)

    Closest Nordic sovereignty competitors.

UpCloud

Best fit when

  • EU product teams needing IaaS with Finnish legal entity and pin-to-zone residency
  • Workloads sensitive to block I/O that benefit from MaxIOPS-class SSDs
  • Cloud-native stacks on managed Kubernetes plus managed PostgreSQL/MySQL/Valkey
  • Multi-service apps where predictable outbound transfer packaging matters
  • Agencies and SaaS operators standardising on API/Terraform automation

Poor fit when

  • Organisations that require a full hyperscaler catalogue (proprietary AI/PaaS breadth)
  • Buyers optimising solely for the lowest-cost bare metal or unlimited-traffic VPS
  • Programmes that forbid any non-EU group support access to account metadata without extra controls
  • Teams that will deploy only to US regions yet still market the stack as EU-sovereign

Consider instead when

  • When: You need cheaper raw compute or dedicated servers more than managed K8s packaging

    Consider: Hetzner

    Often stronger on price for VPS/dedicated; compare managed service depth separately.

  • When: You want a broader French/EU public-cloud portfolio or different regional SKUs

    Consider: OVHcloud or Scaleway

    Different product breadth and commercial culture; still European-operated peers.

  • When: You need hyperscaler-managed platforms, global enterprise contracts, or deep marketplace ecosystems

    Consider: AWS, Google Cloud, or Microsoft Azure

    Trade European HQ simplicity for catalogue depth and global account teams.

  • When: You want a compact European cloud with Swiss roots and a tighter region set

    Consider: Exoscale

    Compare region map and managed feature parity to UpCloud’s 15-DC footprint.

Open questions for due diligence

Elastx

  • Will Elastx provide a current ISO certificate package and statement of applicability under NDA?
  • What is the full subprocessor list for support, ticketing, email, monitoring, CDN, and any AI services?
  • Which optional services (Varnish CDN, Virtuozzo PaaS, hybrid Cloud Exchange links) process customer data outside Elastx-operated Swedish DCs?
  • What RTO/RPO and availability SLA apply to the specific SKUs under evaluation (IaaS vs managed K8s vs DBaaS)?

UpCloud

  • Obtain current ISO 27001 certificate scope/dates and any PiTuKri or other audit reports under NDA if required.
  • Confirm DPA Appendix 1 legal names and countries of all group-company subprocessors for your service mix.
  • Document which regions and backup/object-storage endpoints will be allow-listed for EU-only programmes.
  • Ask whether a SOC 2 or equivalent report for UpCloud Oy is available for enterprise review.
  • Validate Fair Transfer Policy thresholds for your expected egress profile.