ChaptersCircleEventsBlog

STAR Registry Listing for

Dropbox Inc.

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Dropbox Inc. Logo

Dropbox Inc.

Founded in 2007, Dropbox provides a file hosting service that offers secure file sharing, storage, and collaboration solutions to millions of users. The company has its headquarters in San Francisco, California.

Information about Dropbox Inc.
Listed Since: 02/12/2016
Last Updated: 03/12/2025

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
EU Cloud Code of Conduct (CoC)

EU Cloud CoC (Level 2)
This trustmark signifies adherence to the EU Cloud CoC through a dedicated framework and legally demonstrates GDPR compliance. Cloud Service Providers that have successfully passed the EU Cloud CoC’s evaluation process have their Compliance Mark visible in both the Code’s Public Registry as well as here in the CSA STAR Registry.

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Cloud Controls Matrix v4

STAR Attestation (CCMv4)
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.
Cloud Controls Matrix v4

STAR Certification (CCMv4)
A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).