Security/NORDIC DATA
Your data remains in Sweden
Kliva operates on Swedish infrastructure with geographically separated availability zones, encryption at rest and in transit, and strict access control. No customer data leaves Sweden.
Infrastructure
Geographically Redundant — Entirely within Sweden
Kliva is hosted by a Swedish provider with multiple geographically separated availability zones within the Stockholm region. Data traffic between zones is encrypted. The design is distributed for high availability.
Geographically separated availability zones
The platform runs across multiple availability zones in the Stockholm region. These zones are sufficiently separated to withstand localized disruption at a single facility. They are close enough for synchronous replication of critical data.
Encrypted traffic between zones
All traffic between availability zones uses high-capacity encrypted links. This ensures redundant operation and failover without data exposure on public networks.
Distributed design with multiple upstream providers
Internet connectivity is provided via multiple independent Tier 1 operators and local peering points. No single network dependency can take the service offline.
Physical Security
Staffed Data Centers with Multi-Layer Protection
The data centers are Tier 3-classified with 24/7 manned security, CCTV surveillance, ID and biometric access control, and logged visits. The data halls are classified according to MSB protection classes 2 and 3.
Tier 3 classified data centres
The data centers are Tier 3-classified, with redundancy in fiber, power, cooling, and fire protection. Early smoke detection (VESDA) and controlled physical barriers are part of the basic protection.
24/7 staffed access control
Permanent security personnel on-site, comprehensive CCTV surveillance, and ID and biometric access control with logged visits. Servers are housed in dedicated cages with separate monitoring.
MSB Protection Class 2 and 3
The data centers are classified according to MSB protection classes 2 and 3. This is the level required for sensitive Swedish public sector operations.
Platform Security
Encryption, Access Protection, and Continuous Hardening
All storage is encrypted at rest. Traffic is encrypted in transit. Only authorized operations personnel have access to underlying systems. All access requires two-factor authentication.
Encryption at rest and in transit
All volumes and storage are encrypted at rest. All external traffic is protected with TLS. Key management follows industry best practices.
Two-factor authentication for all operational access
All access for development, operations, and administration of core systems requires two-factor authentication. Only authorized personnel from our infrastructure provider have access to underlying hardware.
Active intrusion protection
Trafik från kända skadliga källor blockeras i kanten. Misstänkta beteenden upptäcks och stoppas innan de når applikationen.
Continuous updates
The latest stable versions and security patches are continuously installed across the entire platform stack. This ranges from orchestration layers to application frameworks.
GDPR
Data Protection According to GDPR
We adhere to GDPR principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. We have appointed a Data Protection Officer and documented procedures for incidents and data subject rights.
Appointed Data Protection Officer
We have an appointed Data Protection Officer (DPO). The DPO is responsible for GDPR compliance and acts as the point of contact for supervisory authorities and data subjects.
Data Processing Agreements with all sub-processors
GDPR-compliant data processing agreements are in place with all third parties and subcontractors who process personal data on Kliva's behalf.
Incident reporting within 72 hours
We have documented procedures to notify supervisory authorities and affected data subjects within 72 hours of a detected incident. This aligns with GDPR requirements.
Support for data subject rights
We provide procedures for the right to access, rectification, erasure, data portability, objection, and restriction of processing.
Storage limitation and regular review
Datalagringsregler säkerställer att personuppgifter inte sparas längre än nödvändigt. Våra dataskyddsåtgärder granskas regelbundet och justeras utifrån vägledning från Integritetsskyddsmyndigheten (IMY).
Hållbarhet
Operation on renewable energy
Our infrastructure is eco-certified and powered by renewable energy. Sustainability is part of vendor selection, not an afterthought.
Renewable energy
The data centers are environmental certified and powered by renewable energy. The hosting provider is ISO 14001 certified and a member of The Green Web Foundation.
Modern hardware and container technology
Updated hardware and modern container technology provide high utilization per watt. This means fewer servers for the same workload.
Transparency and social responsibility
We select suppliers who take social responsibility and avoid business with unethical industries. Transparency and environmental considerations characterize daily operations.
Certifications
Certifications and Regulations
An overview of the standards and regulations that our infrastructure and platform adhere to.
Documentation
Documentation on request
The following documentation is available for customers and prospects. All documents are released under a signed NDA.
- Kliva DORA Compliance Statement (extended version)
- ISO 27001 Certificate and Statement of Applicability
- Register of Information (ICT providers)
- Incident classification matrix
- Summary of annual penetration test
- Kliva Code of Conduct (full version)
Senast uppdaterad: 28 augusti 2026.For questions:hello@kliva.com



