Security Leadership In The Cloud

With its large technical and engineering teams, Box was a significant upgrade – in terms of the security of information – compared to the systems we had been using internally.

Isaac Leonard, GrowthPoint Technology Partners

How It Works: Security

Protecting your corporate content is our top priority. We invest heavily in the security and resiliency of our data centers, software and entire business operation. Result: You feel safe entrusting your content to Box.

Account Settings and Global Controls

Administrators control the account settings of all Box users and can easily configure permissions and privileges for the entire organization, a department and/or individual user accounts.

  • Configure policies for password strength and resets, failed logins and session duration
  • Manage permissions for access, preview, editing, download and sharing
  • Password-protect confidential documents and set expiration dates for file access

Single Sign-on

Box seamlessly integrates with leading single sign-on provider: Ping Identity, Citrix, Intel, VMware, Okta, OneLogin, Symplified and more.

  • Active Directory/LDAP integration to leverage your existing user management systems
  • SAML 2.0 and ADFS 2 support for streamlined integrations with cloud SSO providers
  • Multifactor authentication support through the above SSO providers and other third parties

Comprehensive Reporting and Audit Trails

Box provides reporting capabilities and comprehensive audit trails for nearly every action or activity that occurs within Box. Admins can track account actions, document lifecycles, sharing activity and more.

  • Track user name, email address, IP address, date/time for all actions
  • Generate detailed reports and sort by group, date range, file or user
  • Predefined reports give insight into potential security concerns

Sophisticated Data Encryption

Box uses state-of-the-art technology and industry best practices for data encryption during transit to and from the Box cloud, as well as while stored within Box.

  • Encryption at transfer with 256-bit SSL and at rest with 256-bit AES
  • Content Delivery Networks for transfer optimization and additional encryption cycle
  • Encryption keys are securely stored in separate locations and frequently rotated

Comprehensive Network Protection

The Box network is constantly monitored and undergoes frequent threat assessments to ensure data protection; multiple Internet backbone connections provide routing redundancy and high-performance connectivity.

  • Servers reside behind robust firewalls that selectively grant access to network resources
  • External penetration testing ensures system security and validation
  • Intrusion Detection System (IDS) monitors network traffic

Data Center Security and Availability

Box uses multiple data centers to host its application and data, providing essential redundancy. All data centers employ physical security, strict access policies and secure vaults and cages.

  • Data centers include SAS 70 Type II certification, biometric entry authentication and 24/7 armed guards
  • N+1 or greater redundancy for all components of essential systems
  • Uninterruptible power and backup systems, plus fire/flood prevention at storage sites

Your Privacy is Paramount

First and foremost, Box takes every security measure to make sure confidential information stays that way. We have provided administrative, technical and physical safeguards to help ensure your organization remains HIPAA compliant.

  • SAS 70 Type II and Safe Harbor certified
  • Configurable security settings and access controls
  • Review our privacy policy
Customers that use this Box solution

View all case studies