Skip to main content
Skip to main content

Box Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Box before Box sends a questionnaire or a security document.

Box's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Box — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Box's own trust page.

FedRAMP Certified — Class D (High) Checked August 2026.

Box Enterprise Cloud Content Collaboration Platform is FedRAMP Certified at Class D (High) via the Agency path (package F1212191840A).

Risk
Tier 3Moderate Risk
Evidence confidence
98%
25 of 27 sources returned data
Questionnaire
73 / 133 answered
55% from public evidence
Last assessed
Aug 28, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 27.5 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Box is not listed on the FedRAMP Marketplace (checked August 2026).
SOC 2 Status
Box — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Box returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Box a Moderate Risk tier across 27 intelligence sources, 25 of which returned usable evidence (evidence confidence 98%).

27 sources queried, 25 returning usable evidence. The Box assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Box Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

73 questions answered before Box responds.

ThirdProof used public evidence to pre-fill 55% of a 133-question vendor security questionnaire — without waiting for Box. The remaining 60 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

Box is PCI DSS Level 1 compliant, as confirmed by multiple sources stating Box meets PCI DSS Level 1 standards.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Box is GDPR compliant and offers a Data Processing Addendum (DPA) that includes updated EU SCCs issued June 27, 2021 and UK SCCs issued by the UK Information Commissioner's Office.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

Box is HIPAA compliant and signs BAAs; customers with Enterprise, Enterprise Plus, or Enterprise Advanced accounts must sign a HIPAA Business Associate Agreement before storing, transmitting, or processing PHI.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Box encrypts all data at rest using 256-bit AES encryption, confirmed across multiple support articles.

Public evidencehigh confidence

+ 68 additional evidence-backed answers

Get the Complete Box Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Box sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Vendor Commits to Not Training on Customer Data
  • Zero Data Retention for AI Processing
  • Clean domain reputation

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Incident Response — 7 of 10 questions need vendor input
  • Network & Infrastructure — 7 of 14 questions need vendor input
  • Vulnerability Management — 6 of 8 questions need vendor input
  • Governance & Risk — 5 of 10 questions need vendor input

Reviewing Box for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Box

Box is an established cloud content management and collaboration platform with a 27-year domain history and a Tier 3 (Moderate Risk) profile.

Area Requiring Attention

The vendor demonstrates strong compliance posture with ISO 27001 certification, SOC 2 and SOC 1 claims, HIPAA and GDPR compliance, PCI DSS Level 1 compliance, and a clear commitment to not training AI models on customer data — a significant positive signal in the current landscape. Key strengths include: a minimal, well-controlled infrastructure footprint (2 open ports: 80, 443), zero abuse reports on its IP reputation, clean domain reputation free of malware or phishing indicators, no adverse media coverage, no SEC enforcement filings, and no sanctions matches.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from external data registries, threat intelligence feeds, domain registries, regulatory databases, and public trust/security pages without vendor participation.

Investigation Findings

2 findings identified for Box

1 medium1 low
medium

Security header deficiencies detected

Mozilla HTTP Observatory scan of box.com (the marketing website) returned a failing grade (F, 15/100), indicating missing or misconfigured critical HTTP security headers including Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options. This scan evaluated the public-facing marketing site, not the product application endpoints (app.box.com may have different configurations). …

low

No subprocessor page found

No publicly accessible subprocessor or third-party vendor disclosure page was found for Box despite checking 20 common URL paths. While the vendor references a subprocessor compliance framework and data processing agreements in other materials, the absence of a dedicated, centralized subprocessor list limits transparency and complicates supply chain risk assessment.

Security Strengths

Evidence that positively supports Box's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Vendor Commits to Not Training on Customer Data

AI Data Usage Policy

Zero Data Retention for AI Processing

AI Data Usage Policy

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Box complete vendor assessment

Tier 3
Moderate Risk
73 / 133
questionnaire answers
27
sources checked
Aug 28, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 28, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Frequently asked about Box

Is Box FedRAMP authorized?+
Box was not found in the FedRAMP Marketplace when it was checked on August 28, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Does Box have SOC 2 Type II?+
Box states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Box on the OFAC sanctions list?+
Box returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Box's vendor risk tier?+
ThirdProof assigned Box a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 98% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Box.
Has Box had any data breaches or security incidents?+
ThirdProof's adverse media and incident screening as of August 2026 did not surface a validated security incident involving Box. Public sources do not record every incident, so this is not a guarantee that none occurred — ask Box directly for its incident disclosure history and breach notification commitments.
Is Box PCI DSS compliant?+
Box is PCI DSS Level 1 compliant, as confirmed by multiple sources stating Box meets PCI DSS Level 1 standards. ThirdProof records this from Box's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Box support HIPAA and sign BAAs?+
Box is HIPAA compliant and signs BAAs; customers with Enterprise, Enterprise Plus, or Enterprise Advanced accounts must sign a HIPAA Business Associate Agreement before storing, transmitting, or processing PHI. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Box security questionnaire?+
Yes. ThirdProof answered 73 of 133 questions (55%) about Box from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 60 are listed as open, so the follow-up you send Box is short and specific.

If Box is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Box assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required