Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about Dropbox before Dropbox sends a questionnaire or a security document.
Dropbox's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Dropbox — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Dropbox's own trust page.
⚠ Dropbox was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Dropbox assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Dropbox Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 68% of a 133-question vendor security questionnaire — without waiting for Dropbox. The remaining 42 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Dropbox files at rest are encrypted using 256-bit Advanced Encryption Standard (AES), which is confirmed across multiple official sources.
+ 86 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Dropbox for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Dropbox
Dropbox is a mature, established SaaS file storage and collaboration platform operating at significant scale with strong positive security fundamentals.
The company demonstrates comprehensive security controls including encryption (AES-256 at rest, TLS 1.3 in transit), robust identity and access management, redundant multi-region infrastructure with 99.9% uptime SLA, and extensive compliance certifications claimed on their trust pages. Strengths include: a 31-year domain history with enterprise-grade infrastructure, clean threat reputation (no malware blacklist presence), a dedicated security team responsible for protecting ~1 exabyte of data across half a billion users, annual security awareness programs (Trustober), formal incident response procedures with GDPR-compliant 72-hour breach notification, third-party penetration testing, and published Data Processing Agreements supporting GDPR and other regulations.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence presented in this report was independently sourced from external data repositories, public registries, domain analysis, threat intelligence, and archived media without participation or validation from Dropbox.
4 findings identified for Dropbox
Historical media archives contain references to Dropbox data breaches and security concerns. The primary article identified is from Cloudwards.net (July 2026, 29 days old) focusing on data breaches and alternatives. …
Dropbox's [AI data usage policy](https://www.dropbox.com/privacy) requires customers to actively opt out of AI model training rather than opting in by default. The policy indicates training commitment is 'opt_out' — meaning customer data may be used to train AI models unless the customer explicitly disables this. …
A subprocessor page exists at https://trust.dropbox.com/subprocessors but automated parsing could not extract individual subprocessor entries. The page may use a non-standard format (JavaScript-rendered, iframe-embedded, PDF, or proprietary layout). …
Nine certifications are claimed on Dropbox's [trust pages](https://trust.dropbox.com/) (SOC 1, HIPAA, GDPR, CCPA, SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS) but could not be independently verified through public certification registries (FedRAMP Marketplace, HITRUST Directory, IAF CertSearch, PCI Council registry). The trust page likely includes downloadable certificate documents, but those are vendor-attested evidence. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports Dropbox's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Dropbox complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Dropbox is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. Dropbox maintains SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018 certifications, along with HIPAA and PCI DSS compliance claims. For organizations with federal compliance requirements, FedRAMP-authorized alternatives include Box (Moderate impact level). ThirdProof's assessment independently verifies Dropbox's claimed certifications and assesses whether the vendor's security controls meet your compliance framework requirements.
ThirdProof investigated Dropbox across 27 intelligence sources. Sanctions screening returned clear with no OFAC, EU, or UN matches. Domain reputation is clean across 93 security engines with an A+ SSL/TLS grade. Historical adverse media was flagged in archived sources — organizations should review the full report for details on past security incidents and assess current remediation posture.
Represent Dropbox? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Dropbox assessment above is already written; ask for it and it lands in your inbox.