Is Box safe?
Review Box security risks.

The following security profile for Box includes the basics you’ll need for a vendor risk assessment: security certifications, supply chain details, privacy policy, terms of service, GDPR compliance, and more.
Box Organization Details

Category

File Sharing

Organization Details

What is Box?

Box is a cloud-based file storage and collaboration service. It enables users to work with people inside and outside their organization, protect their valuable content, and connect all their apps.

Headquarters

Hosting

Hosting locations

Security Program

Security Certifications

SOC2 Compliance
PCI Compliant
HIPAA Compliant
SOC2 Compliance
SOC 2 Compliant
GDPR Compliant
ISO 27001 Compliant
FedRamp Compliant
CSA Star Level 1
Compliant

Security Portal

Bug Bounty

Vulnerability Disclosure

Terms of Service

Authentication

Authentication / SSO

Supported Okta Features
  • SAML
  • SWA
  • Create
  • Update
  • Deactivate
  • Group Push
  • Schema Discovery
  • Group Linking
  • Workflow Templates
  • Workflows Connectors
  • Workflows Compatible
Login with Google support
Login with Microsoft support
Supports SSO
Two-factor authentication via SMS
Two-factor authentication via E-mail
Two-factor authentication via Hardware
Two-factor authentication via Software
Two-factor authentication via TOTP
Two-factor authentication via U2F

OAuth Details

  • 371608620635-lsbr3prap4hae8kl0netf6r54831t8b4.apps.googleusercontent.com - Box
  • Terms of Service:
  • Privacy Policy: https://www.box.com/legal/termsofservice/
  • 828801433755-3ombhq5s4aj80tk0oivrpmh1k452pspd.apps.googleusercontent.com - Box for Google Workspace Add-on
  • Terms of Service:
  • Privacy Policy:
  • 828801433755-4nch3sbc139ls40n7i6e4olemfkccvsp.apps.googleusercontent.com - Box for Google Workspace Add-on
  • Terms of Service:
  • Privacy Policy:
Box Supply Chain
  • Adobe
  • dyn.com
  • WP Engine
  • New Relic
  • Amazon Web Services (AWS)
  • Netlify
  • SendGrid
  • Adobe Experience Cloud
  • Zendesk
  • Proofpoint
  • Marketo
  • Google Tag Manager
  • Swoogo
  • OneTrust
  • Zoom Video Communications
  • Atlassian
  • Apple Business Manager
  • Statuspage
  • Vercel
  • Outreach.io
  • GitHub
  • Google Workspace
  • LogMeIn
  • DocuSign
  • Hotjar
  • Drift
  • Cloudflare
  • Google Analytics
  • Acquia
Box Subdomains
  • ja.developer.box.com
  • fupload-g-jfk.ent.box.com
  • lp.box.com
  • links.box.com
  • track.box.com
  • community.box.com
  • careers.box.com
  • chat.box.com
  • jp.box.com
  • events.box.com
  • promo.box.com
  • sales.box.com
  • gslink.box.com
  • training.box.com
  • blog.box.com
  • docs.box.com
  • status.box.com
  • secure.box.com
  • support.box.com
  • bvid.box.com
  • jobs.box.com
  • mktg-personalization.box.com
  • fupload-g-sjc.ent.box.com
  • developer.box.com
  • jp.developer.box.com
  • fupload-ec2apne1.app.box.com
  • analytics.box.com
  • e.box.com
  • fupload-g-nrt.ent.box.com
  • success.box.com
  • opensource.box.com
  • go.box.com
  • partners.box.com
  • em.box.com

Regain control of SaaS security.

Nudge Security discovers all SaaS accounts ever created by anyone in your org within minutes of starting a free trial. Get a full SaaS inventory today, along with insights and automation to improve your SaaS security posture.

was able to find all this and much more.
Nudge was able to find all this and much more.
Nudge Security provides detailed security profiles for thousands of SaaS apps. Sail through security assessments with our proprietary intelligence on vendors’ security, risk, and compliance programs.
Stop chasing down answers. Start a free 14-day trial of Nudge Security to learn:
Stop chasing down answers.
Start a free 14-day trial of Nudge Security today.
Who’s using Box in your org?
What data does Box have access to?
What is Box’s breach history?
What apps are in Box’s supply chain?