Compliance frameworks, security audits, and quality certifications this company maintains.
Dropbox maintains SOC 2 Type II certification, demonstrating that its cloud storage infrastructure meets rigorous trust service criteria for security, availability, and confidentiality required by enterprise customers.
Dropbox holds ISO 27001 certification for its information security management system, ensuring enterprise data stored on Dropbox Business is protected under internationally recognized controls.
Dropbox is GDPR compliant, providing EU data residency options and data processing agreements that allow European enterprise customers to use Dropbox Business in accordance with EU privacy law.
Dropbox complies with the California Consumer Privacy Act, giving California users rights to access, delete, and opt out of data sale, supported by Dropbox's privacy controls and data management tools.
Dropbox Business Advanced and Enterprise plans support HIPAA compliance with BAA agreements, allowing healthcare organizations to store and share PHI securely on the Dropbox platform.
Regulatory
FedRAMP Moderate
CertifiedDropbox Sign (formerly HelloSign) holds FedRAMP Moderate authorization, enabling U.S. federal agencies to use Dropbox's e-signature platform for official document workflows.
Dropbox Sign is PCI DSS compliant for handling payment card data associated with subscription billing and enterprise contract workflows that involve financial documentation.
Dropbox has completed the Cloud Security Alliance STAR self-assessment, publishing its cloud security posture in the CSA registry to support enterprise procurement due diligence.
Dropbox is ISO 27018 certified, specifically addressing the protection of personally identifiable information in public cloud services and reinforcing its privacy commitments to business customers.
Dropbox Business supports FINRA compliance for financial services firms requiring secure document retention, audit trails, and access controls for broker-dealer records management.