Kliva

    Security/NORDIC DATA

    Your data remains in Sweden

    Kliva operates on Swedish infrastructure with geographically separated availability zones, encryption at rest and in transit, and strict access control. No customer data leaves Sweden.

    Hosted in SwedenISO 27001-certified infrastructure
    Request documentation

    Infrastructure

    Geographically Redundant — Entirely within Sweden

    Kliva is hosted by a Swedish provider with multiple geographically separated availability zones within the Stockholm region. Data traffic between zones is encrypted. The design is distributed for high availability.

    Geographically separated availability zones

    The platform runs across multiple availability zones in the Stockholm region. These zones are sufficiently separated to withstand localized disruption at a single facility. They are close enough for synchronous replication of critical data.

    Encrypted traffic between zones

    All traffic between availability zones uses high-capacity encrypted links. This ensures redundant operation and failover without data exposure on public networks.

    Distributed design with multiple upstream providers

    Internet connectivity is provided via multiple independent Tier 1 operators and local peering points. No single network dependency can take the service offline.

    Physical Security

    Staffed Data Centers with Multi-Layer Protection

    The data centers are Tier 3-classified with 24/7 manned security, CCTV surveillance, ID and biometric access control, and logged visits. The data halls are classified according to MSB protection classes 2 and 3.

    Tier 3 classified data centres

    The data centers are Tier 3-classified, with redundancy in fiber, power, cooling, and fire protection. Early smoke detection (VESDA) and controlled physical barriers are part of the basic protection.

    24/7 staffed access control

    Permanent security personnel on-site, comprehensive CCTV surveillance, and ID and biometric access control with logged visits. Servers are housed in dedicated cages with separate monitoring.

    MSB Protection Class 2 and 3

    The data centers are classified according to MSB protection classes 2 and 3. This is the level required for sensitive Swedish public sector operations.

    Platform Security

    Encryption, Access Protection, and Continuous Hardening

    All storage is encrypted at rest. Traffic is encrypted in transit. Only authorized operations personnel have access to underlying systems. All access requires two-factor authentication.

    Encryption at rest and in transit

    All volumes and storage are encrypted at rest. All external traffic is protected with TLS. Key management follows industry best practices.

    Two-factor authentication for all operational access

    All access for development, operations, and administration of core systems requires two-factor authentication. Only authorized personnel from our infrastructure provider have access to underlying hardware.

    Active intrusion protection

    Trafik från kända skadliga källor blockeras i kanten. Misstänkta beteenden upptäcks och stoppas innan de når applikationen.

    Continuous updates

    The latest stable versions and security patches are continuously installed across the entire platform stack. This ranges from orchestration layers to application frameworks.

    GDPR

    Data Protection According to GDPR

    We adhere to GDPR principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. We have appointed a Data Protection Officer and documented procedures for incidents and data subject rights.

    Appointed Data Protection Officer

    We have an appointed Data Protection Officer (DPO). The DPO is responsible for GDPR compliance and acts as the point of contact for supervisory authorities and data subjects.

    Data Processing Agreements with all sub-processors

    GDPR-compliant data processing agreements are in place with all third parties and subcontractors who process personal data on Kliva's behalf.

    Incident reporting within 72 hours

    We have documented procedures to notify supervisory authorities and affected data subjects within 72 hours of a detected incident. This aligns with GDPR requirements.

    Support for data subject rights

    We provide procedures for the right to access, rectification, erasure, data portability, objection, and restriction of processing.

    Storage limitation and regular review

    Datalagringsregler säkerställer att personuppgifter inte sparas längre än nödvändigt. Våra dataskyddsåtgärder granskas regelbundet och justeras utifrån vägledning från Integritetsskyddsmyndigheten (IMY).

    Hållbarhet

    Operation on renewable energy

    Our infrastructure is eco-certified and powered by renewable energy. Sustainability is part of vendor selection, not an afterthought.

    Renewable energy

    The data centers are environmental certified and powered by renewable energy. The hosting provider is ISO 14001 certified and a member of The Green Web Foundation.

    Modern hardware and container technology

    Updated hardware and modern container technology provide high utilization per watt. This means fewer servers for the same workload.

    Transparency and social responsibility

    We select suppliers who take social responsibility and avoid business with unethical industries. Transparency and environmental considerations characterize daily operations.

    Certifications

    Certifications and Regulations

    An overview of the standards and regulations that our infrastructure and platform adhere to.

    Documentation

    Documentation on request

    The following documentation is available for customers and prospects. All documents are released under a signed NDA.

    • Kliva DORA Compliance Statement (extended version)
    • ISO 27001 Certificate and Statement of Applicability
    • Register of Information (ICT providers)
    • Incident classification matrix
    • Summary of annual penetration test
    • Kliva Code of Conduct (full version)
    Shared withCustomers, prospects under evaluation, financial supervisory authorities
    RequirementSigned NDA before release
    Response timeUsually within two business days

    Request documentation

    We will respond within two business days.

    Senast uppdaterad: 28 augusti 2026.For questions:hello@kliva.com

    Kliva

    Kliva support

    We usually reply within minutes

    Hi, how can we help?

    Ask a question or pick a shortcut below.