Box Trust Center

Putting our customers and their content first

Trust

A longstanding commitment to security and compliance

At Box, security and compliance are part of our DNA. We're dedicated to earning and keeping our customers' trust — every day. The Box Trust Center connects you to the latest information on how we prioritize security, compliance, data privacy, and reliability for our products.

Our approach to reliability

You've put your trust in Box as a valued service provider and partner. To keep your trust, we’re committed to updating you on what's happening with and within the Box Services, whether it’s planned maintenance or an unexpected service disruption.

Enabling the responsible and secure use of enterprise-grade AI

With the adoption of AI, enterprises face unique security, privacy and compliance challenges that must be carefully addressed as regulations continue to evolve.  We are committed to being transparent about our AI practices, technology, vendors, and data usage.

 

Exceed global compliance requirements

Intelligent Content Management enables advanced privacy and compliance in today’s global, digital-first world. We’re committed to delivering a secure content platform that helps you meet and exceed your regulatory and compliance needs and obligations.

Protecting US government agencies critical information

Digitize your agency services and drive government cloud security while maintaining industry compliance. Within the United States Federal and Department of Defense community, Box has achieved a number of certifications that demonstrate our capabilities and commitment to security.

Values that build trust (and a better world)

Environmental, social, and governance (ESG) priorities are woven into the fabric of our culture at Box. Our ESG website and ESG data sheet outline our commitments to protect our planet, invest in people and communities, and acting with integrity. We expect the same commitment from our suppliers, as set forth in our Supplier Code of Conduct.

How we approach security and compliance

Compliance Catalogue C5
Cloud Computing Controls Compliance Catalogue (C5)

Provided under NDA — please contact your account team

CAIQ
Consensus Answer Initiative Questionnaire (CAIQ)
Download
FedRAMP High Authorization
FedRAMP High Authorization
Learn more
Finra
FINRA Report

Provided under NDA — please contact your account team

gxp validation
GxP Validation
Learn more
HECVAT Full
HECVAT Full

Provided under NDA — please contact your account team

HIPAA assessment letter
HIPAA Assessment Letter

Provided under NDA — please contact your account team

HIPAA compliance
HIPAA Compliance
Download
ISMAP Certification
ISMAP Certification
Learn more
ISO thumbnail
ISO Certification
Download
ITAR
ITAR

Provided under NDA — please contact your account team

PCI DSS
Payment Card Industry Data Security Standard (PCI DSS)

Provided under NDA — please contact your account team

SIG
SIG

Provided under NDA — please contact your account team

SOC 1 & 2 - Type II
SOC 1 & 2 - Type II

Provided under NDA — please contact your account team

StateRAMP
StateRAMP
Download
Trusted Partner Network Gold Shield
Trusted Partner Network Gold Shield
WCAG
Web Content Accessibility Guidelines (WCAG) 2.0 Level AA

VPAT provided under NDA — please contact your account team

How we prioritize data privacy

CCPA
CCPA

Find out how to steer clear of risk and keep your reputation intact as you meet obligations for the California Consumer Privacy Act (CCPA).

Learn more
Cookie notice
Cookie notice
Explore how and why Box utilizes cookies and how you can change your cookie preferences.
Learn more
gdpr
GDPR

Read about our GDPR compliance, our Data Processing Addendum (DPA), and our product offerings for data protection obligations.

Learn more
Privacy notice
Privacy notice

See what information is collected, retained, used, disclosed, and transferred by Box and how to exercise your data subject rights.

Learn more
Regional information
Regional information

Discover how we comply with region-specific data privacy regulations.

Learn more
schrems II and Brexit
Schrems II and Brexit
Take a look at our continued commitment to safeguarding your data and how we process formal government requests.
Learn more
subprocessors
Subprocessors
Find out about Box's subprocessors and the services they provide.
Learn more

Explore our resources

supplier code of conduct
Our supplier code of conduct

Learn how we engage with suppliers, and find out about ethical and compliance requirements. 

Learn more
ESG at box
ESG at Box

Explore Box’s environmental, social, and corporate governance commitments.

Learn more
accessibility improvements
Accessibility Improvements to the Box Web Application
Discover how we’re committed to providing a simple and compelling experience for our users.
Learn more

FAQ

Find answers to frequently asked questions on security, reliability, compliance, and privacy.

Security

Compliance

Reliability

Privacy

Ready to get started?