VendorScore · Comparison · Data-access posture
Evidence dated 2026-10-06 to 2026-10-07, public docs only, not legal advice.
Short answer
Both can read your normal files. In the scored configurations, Dropbox (73/100) has less inherent vendor read access than Box (64/100), because Dropbox's designated E2EE team folders are never decrypted on Dropbox servers, while Box KeySafe gives you key custody but Box still decrypts files for previews and Box AI.
Higher score = less inherent vendor read access in the scored configuration, not a more secure product. Each score comes from that vendor's VendorScore page.
| Dropbox | Box | |
|---|---|---|
| Overall score | 73/100 | 64/100 |
| Scored configuration | Dropbox Business Advanced/Enterprise with optional zero-knowledge E2EE folders and advanced key management. | Box Enterprise with Box KeySafe (customer-managed keys in AWS KMS or GCP Cloud KMS/HSM) and Box Zones for residency. |
| Key custody option | Dropbox-managed keys by default. Advanced key management keeps team keys in an AWS KMS/HSM hierarchy, separate from full E2EE; no general client-side encryption for the whole product. | Box KeySafe: keys in your AWS KMS or GCP Cloud KMS/HSM, with a kill switch. Search indexes, comments, metadata and Box Notes stay on Box-managed keys. |
| E2EE / CSE scope | Designated end-to-end encrypted team folders (Advanced/Enterprise): encrypted and decrypted on approved devices, never on Dropbox servers. Normal files: Dropbox can access them. | None. AES-256 at rest and TLS in transit is server-side encryption; Box decrypts files through your KMS to preview, download or run Box AI. |
| AI training default (scored config) | Off by default (opt-in). Dropbox says it won't build generative AI models using customer content without consent. | Off by default (opt-in). Box says it won't train Box AI on your queries, outputs or other Confidential Information without explicit consent. Box AI still processes KeySafe-protected content, decrypted at query time. |
| EU residency | For eligible teams: EU storage for file data at rest (at least 10 licenses, annual billing). Dropbox reviews requests individually and the migration can't be undone. | Yes, with the paid Box Zones add-on (content at rest); some processing and metadata storage may continue from the United States. |
| DPA link | Dropbox DPA | Box DPA (page that links the DPA; DPA content not reviewed) |
Dimension scores (key custody, plaintext access, encryption claims, subprocessors, auditability) stay in the full PDFs.
Get the full 5-dimension PDFs — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Only Dropbox, and only in designated end-to-end encrypted team folders (Advanced/Enterprise), which are encrypted and decrypted on approved devices, never on Dropbox servers. Box encrypts data at rest with AES-256 and in transit with TLS, which is server-side encryption, not E2EE.
No. Box still decrypts files through your KMS to preview, download or run Box AI on them. Dropbox advanced key management keeps team keys in an AWS KMS/HSM hierarchy and is separate from full E2EE.
Dropbox says its personnel will, on rare occasions, need to access file content (for example when legally required or to enforce its terms), with access limited to a small number of people; E2EE team folders are the exception. Box personnel access data within the scope of their authorization, and VendorScore found no documented customer-approval gate for Box staff access to content.
Dropbox says it won't build generative AI models using customer content without consent. Box says it won't train Box AI on customer queries, outputs or other Confidential Information without explicit consent; Box AI does process KeySafe-protected content, decrypted at query time.
Dropbox offers EU storage for file data at rest to eligible teams (at least 10 licenses and annual billing); requests are reviewed individually and the migration can't be undone. Box Zones, a paid add-on, stores content at rest in a region you choose, though some processing and metadata storage may continue from the United States.
Every URL cited on this page. Scores, configurations and facts come from the linked VendorScore vendor pages and their reports; nothing here goes beyond them.
This comparison restates the vendor pages for the scored configurations only; default setups usually score lower. A higher score means less inherent vendor read access in that configuration, not a safety rating. VendorScore doesn't certify compliance. Public-docs review only. Not a pen test, not legal advice, not a SOC 2 substitute.