Q39
Are you PCI DSS compliant? At what level?
Box is PCI DSS Level 1 compliant, as confirmed by multiple sources stating Box meets PCI DSS Level 1 standards.
ThirdProof independently checks public intelligence sources to show what your team can verify about Box before Box sends a questionnaire or a security document.
Box's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Box — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Box's own trust page.
✓ FedRAMP Certified — Class D (High) Checked August 2026.
Box Enterprise Cloud Content Collaboration Platform is FedRAMP Certified at Class D (High) via the Agency path (package F1212191840A).
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 25 returning usable evidence. The Box assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Box Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 55% of a 133-question vendor security questionnaire — without waiting for Box. The remaining 60 are listed as open, so the follow-up you send is short and specific.
Q39
Box is PCI DSS Level 1 compliant, as confirmed by multiple sources stating Box meets PCI DSS Level 1 standards.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Box is GDPR compliant and offers a Data Processing Addendum (DPA) that includes updated EU SCCs issued June 27, 2021 and UK SCCs issued by the UK Information Commissioner's Office.
Q40
Box is HIPAA compliant and signs BAAs; customers with Enterprise, Enterprise Plus, or Enterprise Advanced accounts must sign a HIPAA Business Associate Agreement before storing, transmitting, or processing PHI.
Q23
Box encrypts all data at rest using 256-bit AES encryption, confirmed across multiple support articles.
+ 68 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Box for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Box
Box is an established cloud content management and collaboration platform with a 27-year domain history and a Tier 3 (Moderate Risk) profile.
The vendor demonstrates strong compliance posture with ISO 27001 certification, SOC 2 and SOC 1 claims, HIPAA and GDPR compliance, PCI DSS Level 1 compliance, and a clear commitment to not training AI models on customer data — a significant positive signal in the current landscape. Key strengths include: a minimal, well-controlled infrastructure footprint (2 open ports: 80, 443), zero abuse reports on its IP reputation, clean domain reputation free of malware or phishing indicators, no adverse media coverage, no SEC enforcement filings, and no sanctions matches.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external data registries, threat intelligence feeds, domain registries, regulatory databases, and public trust/security pages without vendor participation.
2 findings identified for Box
Mozilla HTTP Observatory scan of box.com (the marketing website) returned a failing grade (F, 15/100), indicating missing or misconfigured critical HTTP security headers including Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options. This scan evaluated the public-facing marketing site, not the product application endpoints (app.box.com may have different configurations). …
No publicly accessible subprocessor or third-party vendor disclosure page was found for Box despite checking 20 common URL paths. While the vendor references a subprocessor compliance framework and data processing agreements in other materials, the absence of a dedicated, centralized subprocessor list limits transparency and complicates supply chain risk assessment.
Evidence that positively supports Box's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Zero Data Retention for AI Processing
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Box complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Box? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Box assessment above is already written; ask for it and it lands in your inbox.