VendorScore · File storage · Data-access posture
A plain-language answer from Dropbox's public security and E2EE docs. Most files in a typical Dropbox are not in E2EE folders.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Yes for normal files: Dropbox holds the keys and can access content. Mostly no for designated end-to-end encrypted team folders, where Dropbox says content is never decrypted on its servers.
Scored configuration: Dropbox Business Advanced/Enterprise with optional zero-knowledge E2EE folders and advanced key management.
Without E2EE folders, the report estimates Overall ~50: Dropbox can read files.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
By default, files at rest are encrypted with AES-256 using keys Dropbox manages. Dropbox says it does not offer general client-side encryption or customer-created private keys for the whole product.
Evidence: How security worksIn designated E2EE team folders, Dropbox says content "is encrypted and decrypted on approved devices only—never on Dropbox servers." The feature is folder-scoped and plan-gated.
Evidence: Dropbox E2EE feature page, E2EE engineering postOur report flags these gaps in Dropbox's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes for normal files: Dropbox holds the keys and can access content. Mostly no for designated end-to-end encrypted team folders, where Dropbox says content is never decrypted on its servers. VendorScore rates Dropbox 73/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Dropbox Business Advanced/Enterprise with optional zero-knowledge E2EE folders and advanced key management.
Not by default. Normal files are encrypted at rest with AES-256 using Dropbox-managed keys, and Dropbox can access them. Only designated end-to-end encrypted team folders (Advanced/Enterprise) are encrypted and decrypted on approved devices, never on Dropbox servers; the team holds a central team key. Advanced key management keeps team keys in an AWS KMS/HSM hierarchy and is separate from full E2EE.
Rarely, under policy. Dropbox says: "Like most major online services, Dropbox personnel will, on rare occasions, need to access users’ file content" when legally required, to make sure systems and features work as designed, or to enforce its terms, and that access "is limited to a small number of people." Files in E2EE team folders are the exception. Separately, Dropbox team admins can sign in as a user and access that member's team files.
Not without consent. Dropbox's AI Principles say: "We will not build generative AI models using customer content without consent." That page doesn't detail how Dash or other AI features route content to model providers; Dropbox points to a separate AI transparency resource for that.
VendorScore doesn't certify compliance; Dropbox publishes a DPA at https://assets.dropbox.com/documents/en/legal/dfb-data-processing-agreement.pdf. It is Dropbox's Data Processing Agreement for business customers (posted August 23, 2024). Dropbox's Privacy Policy lists Standard Contractual Clauses and the EU-U.S. Data Privacy Framework among its transfer mechanisms.
Dropbox publishes a sub-processor list at https://www.dropbox.com/privacy/subprocessor/dropbox, and its DPA says Dropbox will inform customers in advance of new sub-processors. That page loads dynamically and VendorScore couldn't read its contents for this review, so check it directly for AI or support providers that may see content.
For eligible teams, yes for file data at rest. Dropbox says storage servers are available in the European Union (as well as Australia, Japan and the UK) for eligible users. A team must be on Standard, Advanced, Business, Business Plus or Enterprise, have at least 10 licenses, be on annual billing, and have a billing address outside its current storage location. Dropbox reviews requests individually and the migration can't be undone.
Every URL cited on this page. Score and key findings: VendorScore report (dropbox.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.