SOC 2 company profile

Dropbox SOC 2 status and provider evidence

Review Dropbox’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeNot publicly specified
Providers found0
Last checked2026-08-29
Providers

Dropbox’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Primary compliance evidence

Dropbox public statement

ocesses through independent third-party audits. - **Auditors:** SOC audits are conducted by Ernst & Young LLP; ISO certifications are audited by EY CertifyPoint (Netherlands). - **SOC 2 Report:** Covers Security, Availability, Processing Integrity, Confidentiality, and Privacy for more than 100 controls. It includes an audited mapping to ISO standards (referred to as a SOC 2+ report). - **SOC 1 / SSAE 18 / ISAE 3402:** Supports customers' Sa

Classification: self attested · checked 2026-08-29
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement