Sign Up Now Get More Info
Box provides valuable administrative features, which let us easily set granular permission controls across all our content and all our users. — Christopher High, Sales & Marketing Development, Inverness Medical

Security is our top priority

We adhere to the highest industry standards for security at every level of the Box experience. You can share, manage and access your content with confidence.


In addition to a 99.9% network uptime guarantee, Box Business and Enterprise customers benefit from:

  • Data encryption on transfer
    Data is encrypted using SSL on transfer.
  • Data encryption at rest
    Data is encrypted on servers using 256-bit AES SSL. Enterprise only
  • Administrative auditing
    Manage users, groups and access permissions. Monitor file and user activity.
  • Comprehensive reporting tools
    Drill down and generate reports on user and file activity.
  • Sophisticated user password policy enforcement
    Manage complexity requirements, histories and forced resets.
  • AD/LDAP integration
    Option for Enterprise customers over standard Box authentication.
    Enterprise only
  • Role-based access controls
    Choose editing, viewing, previewing & uploading permissions.
  • Password-protection & time-based file controls
    Apply passwords to shared files & folders and expiration dates for file access.

Box security architecture

Box security architecture Click to enlarge

Comprehensive security at every level, for every user

Box.net commits extensive resources to the design, implementation, monitoring and maintenance of our security infrastructure. This includes:

  • Highly scalable and redundant online infrastructures
  • Constant monitoring of production systems
  • Ongoing threat assessments
  • Rapid deployment of industry-standard security technologies

Together, from the point users log into Box to how and where files are stored and accessed, protection is built in at every level.

Protection at the application level

  • Files uploaded to Box are private by default - you control what is shared
  • Shared files can be made private at any time
  • Unique, randomly-generated IDs are applied to links for shared files
  • Search engine and robot indexing of public files is blocked

Protection at the network level

  • Servers reside behind sophisticated firewall that selectively grants access to network resources
  • External penetration testing performed for system security and validation
  • Multiple internet backbone connections provide routing redundancy and high performance connectivity
  • Intrusion Detection System (IDS) continuously monitors network traffic

Protection at the facilities level

  • Servers hosted in redundant facilities, which are automatically backed up to a geographically-separated site
  • Data centers implement ongoing audits, 24/7/365 monitoring and surveillance, on-site security staff, mantraps and strict access controls
  • Power systems feature multiple power feeds, UPS devices and backup generators ensure continuous operation
  • Environmental systems have n+1 redundant configuration to ensure fault tolerance

Protection of your privacy

We take your privacy very seriously and have self-certify compliance with Safe Harbor. Review our Privacy Policy for more information.

It appears that your firewall may be blocking Box.net or you are encountering an error.

Please contact your IT administrator to configure your firewall to recognize all sub-domains of .box.net and .boxcdn.net. The ports that should be opened for these domains are 80 and 443.

If that does not resolve the issue, then please submit a support ticket at http://www.box.net/help.