Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Dropbox, your compliance team needs documented proof they can be trusted. ThirdProof investigated Dropbox across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
27 sources queried. 100% confidence. Every Dropbox investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Dropbox's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 46% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Dropbox's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Dropbox is not listed on the FedRAMP Marketplace. Dropbox maintains SOC 2 Type II and ISO 27001 certifications.
High Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
26
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Dropbox
Dropbox (dropbox.com) is a publicly traded SaaS cloud storage and collaboration platform (NASDAQ: DBX) assessed at Risk Tier 2 (High Risk), driven primarily by a well-documented history of significant security incidents rather than any current active threat indicators. Dropbox presents meaningful operational strengths across multiple domains. Infrastructure security is tightly controlled, with only standard ports 80 and 443 exposed, TLS 1.3 enforced with strong cipher suites, and a clean Malware detection service and URLhaus status. The domain has been registered since 1995 and is protected by enterprise-grade registrar controls through MarkMonitor. Dropbox publishes a comprehensive trust and compliance page and maintains a 99.9% contractual uptime SLA with a higher internal target of 99.95%. The vendor operates redundant data centers with active-passive replication across multiple facilities, and its published subprocessor page lists Amazon Web Services and Intigriti — both of which passed sanctions and safety checks. A Data Processing Agreement dated August 23, 2024 with EU Standard Contractual Clauses is publicly available. The primary risk driver for this assessment is Dropbox's historical security incident record, documented across multiple credible media sources:
Independence Statement
All evidence in this assessment was independently sourced from public registries, threat intelligence feeds, domain infrastructure analysis, certificate transparency logs, media archives, and sanctions databases without vendor participation or notification.
4 findings identified for Dropbox
3 Hacker News stories about "Dropbox" related to operational. Top story: "Backblaze has stopped backing up OneDrive and Dropbox folders and maybe others" (1117 points).
dropbox.com is missing 3 recommended security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options.
dropbox.com has certificates from 32 different Certificate Authorities. This may indicate inconsistent certificate management practices.
9 article(s) mention "Dropbox" with risk keywords, severity reduced due to article age: "Dropbox Breach Exposes Customer Credentials, Authentication Data" (Dark Reading) https://news.google.com/rss/articles/CBMisgFBVV95cUxPN2laTkRpYkdZbDkzZXRpVEFVMmJIdDhKS0ppcnFCeUg2b1NaQ2p4eDZXYXczYmhmVnozM015OTZPQWJkYVFPWV9hc09hTGh0MEhYa0dBa2djckxRdEY5NG02Tm9MUFJybnJfelZkT0hFUXd2Ull5TzE0QXB3S3lZNXR2Y0lOWnpNSnk2MzVsSHd5NUxoMnJHV3FjMXRNWmV2RVVhQ2dHY25TUlZ0el93NnJR?oc=5; "Dropbox Breach: Hackers Unauthorizedly Accessed 130 GitHub Source Code Repositor..." (The Hacker News) https://news.google.com/rss/articles/CBMiggFBVV95cUxQRWxDM2RmTzdmVy14dDlxaDA2bUZGUXdReWhLQnlCZHhhblVhbjVJTXZna19DeEp1QjRuUGFPcWU0R0tfT2E3SDBqeXh6NWxzRGN3a0h2NkRCT0RZck9oMWZ1Sy1MaTctUk1pLVpEbXRRVE1idkwzSFBhaWtuMVFfYUJR?oc=5; "Dropbox Hacked! Threat Actor Accessed Passwords and Phone Numbers" (Bitdefender) https://news.google.com/rss/articles/CBMiugFBVV95cUxQa2R5b2VnR2xremhwWVhTekoyUkRUMTU2QUxyeWt1Nm5HUkZWRW9PcHNQbnkyMEU2aE40NUZvNm43d0lQclVhVEU2eWpmNGRhcXlSRU52U05Ld1lRc0VtdGJ0d2J4eHdIckdneTFNVjFjWHo1SE5JTEduR01EWnh4MENTRGNzYzJ2LXprNS15aXJQNG1feHNBVnB5YmhpMEw1NTB0WTBsbnhqcEJiV3pQa0ZXekhpUnpFdGc?oc=5
30 positive signals verified
Legal Entity Actively Registered
Business Registration →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (30+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →HTTP Security Grade: B+
HTTP Security Scan →Large Certificate Footprint (437 subdomains)
Certificate Transparency →Established Web Presence (29+ years)
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Low Abuse Score: 1% (1 reports)
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 1
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: ISO 27017
Trust & Compliance Page Scan →Certification Claimed: ISO 27018
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →2 Subprocessors Identified
Supply Chain & Subprocessor Discovery →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Dropbox
Request the current SOC 2 Type II report and bridge letter from Dropbox's security team — visit [trust.dropbox.com](https://trust.dropbox.com) to request access (an NDA may be required). Confirm the report covers the current period and was issued within the last 12 months. If Dropbox is in scope for your own SOC 2 boundary, identify the complementary user entity controls (CUECs) specified in the report and document how your organization implements them.
Resolve the ISO 27001 and PCI DSS registry contradiction by requesting the current ISO 27001 certificate (with certificate number, issuing body, scope, and expiry date) and the PCI DSS Attestation of Compliance (AoC) document directly from Dropbox's security or compliance team. Cross-reference the ISO certificate number against the IAF CertSearch registry at iafcertsearch.org to independently confirm validity.
Request Dropbox's written response or post-incident documentation for the April/May 2024 Dropbox Sign breach, specifically confirming: (a) whether your organization's data was in scope, (b) what architectural remediation was implemented, and (c) current status of affected systems. Retain this documentation alongside this assessment report for SOC 2 CC9.2 evidence.
Request a complete and current subprocessor list from Dropbox beyond the two entries currently published at [trust.dropbox.com/subprocessors](https://trust.dropbox.com/subprocessors). For a platform of Dropbox's scale, a two-entry list is likely incomplete. Confirm whether any subprocessors access your specific data, and verify they meet equivalent security standards.
Clarify Dropbox's AI data handling policy as it relates to your organization's data — specifically whether Dropbox Dash or other AI features process your stored files, whether customer data is used to train or fine-tune AI models, and whether an enterprise opt-out is available. Review the [Dropbox privacy policy](https://www.dropbox.com/privacy) and request a written statement from your account team if the policy language is ambiguous for your use case.
Document this assessment with a reviewer signature and retention date to satisfy SOC 2 Trust Services Criterion CC9.2 third-party risk management evidence requirements. Retain for the duration of the vendor relationship and through the next SOC 2 audit cycle.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Dropbox? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Dropbox on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Dropbox's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Dropbox a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Dropbox appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Dropbox's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Dropbox's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Dropbox claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Dropbox depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Dropbox appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Dropbox is not listed on the FedRAMP Marketplace and has not pursued FedRAMP authorization. Dropbox maintains SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018 certifications, along with HIPAA and PCI DSS compliance claims. For organizations with federal compliance requirements, FedRAMP-authorized alternatives include Box (Moderate impact level). ThirdProof's assessment independently verifies Dropbox's claimed certifications and assesses whether the vendor's security controls meet your compliance framework requirements.
ThirdProof investigated Dropbox across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 86% confidence. Sanctions screening returned clear with no OFAC, EU, or UN matches. Domain reputation is clean across 93 security engines with an A+ SSL/TLS grade. Historical adverse media was flagged in archived sources — organizations should review the full report for details on past security incidents and assess current remediation posture.
Your first 5 Dropbox assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, FedRAMP Marketplace verification, business registration, adverse media analysis, cyber risk scoring, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2, HIPAA, CMMC, and FedRAMP compliance evidence packages.
Seeing this in an audit? ThirdProof lets you investigate Dropbox and every other vendor in your stack — average report time: 7 minutes. Get Dropbox's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Dropbox across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.