Updated: October 6, 2026 · Source-first reference130 documented agents & platforms · No paid rankings
AgentenCode evidence profileEnterprise
✓ Editorially reviewedChecked: October 1, 2026

Agent profile · Enterprise

Box Agent

Box Agent is classified by AgentenCode as an enterprise content agent from Box. It belongs to the Enterprise & Productivity category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.

BoxEnterpriseOrganizations
Enterpriseeditorial classification
Boxprovider
5 primary sourcessource status
October 1, 2026last verification

AgentenTrust 2.0 · EU & governance evidence

Trust, privacy and control evidence for Box Agent

Direct answer: AgentenCode currently documents 10 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.

Privacy contextPrivacy & data2 of 8 documentedResidency, training, retention, DPA, subprocessors and processing scope.
Security contextSecurity & access6 of 10 documentedEncryption, SSO, SCIM, RBAC, roles and credential handling.
Human controlHuman control0 of 10 documentedApproval, oversight, permissions and stop or rollback controls.
TraceabilityAudit & traceability2 of 8 documentedAudit logs, APIs, SIEM, observability, tracing and activity history.

Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.

Field-level evidence

Documented controls and values from primary sources.

Documented yesDocumented valueUnknown remains unknown
High confidence

Governance · Audit logs · Available

Yes — documented

Box provides audit trails covering Box AI/Agent activity.

Scope: box_platform_and_box_ai · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Audit logs · SIEM export

Yes — documented

Box audit/security activity can be integrated with SIEM tooling.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Governance · RBAC

Yes — documented

Box uses role-based access controls and granular permissions.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Governance · SSO · Saml

Yes — documented

Box organizations using Box Agent can use SAML 2.0 SSO.

Scope: box_business_enterprise_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Hosting · Managed

Yes — documented

Box Agent is delivered as a managed capability inside Box.

Scope: box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Privacy · Data residency · Available

Yes — documented

Box offers regional data-residency options for Box AI content.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Privacy · Data residency · Customer Region Selectable

Yes — documented

Eligible Box customers can select supported data-storage regions.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Security · Customer-managed keys

Yes — documented

Box supports customer-managed encryption keys through Box KeySafe.

Scope: box_enterprise_keysafe · verified 2026-10-01 · Primary source ↗
High confidence

Security · Encryption · At rest

AES-256

Box documents AES-256 encryption at rest.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Security · Encryption · In transit

TLS 1.2+

Box documents TLS 1.2+ encryption in transit.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗
High confidence

Security · Soc2 Type2

Yes — documented

Box documents SOC 2 Type II compliance.

Scope: box_platform_including_box_agent · verified 2026-10-01 · Primary source ↗

Evidence-backed overview

What is Box Agent?

Box Agent is classified by AgentenCode as an enterprise content agent from Box. It belongs to the Enterprise & Productivity category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.

Product-specific evidence for Box Agent

This profile links 5 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Enterprise & Produktivität.

Data Residency

Yes · Scope: box_platform_including_box_agent · verified 2026-10-01.

Primary source ↗

Region auswählbar

Yes · Scope: box_platform_including_box_agent · verified 2026-10-01.

Primary source ↗

Customer-Managed Keys

Yes · Scope: box_enterprise_keysafe · verified 2026-10-01.

Primary source ↗

Verschlüsselung at rest

AES-256 · Scope: box_platform_including_box_agent · verified 2026-10-01.

Primary source ↗

Verschlüsselung in transit

TLS 1.2+ · Scope: box_platform_including_box_agent · verified 2026-10-01.

Primary source ↗

SOC 2 Type 2

Yes · Scope: box_platform_including_box_agent · verified 2026-10-01.

Primary source ↗

AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.

1primary source
11field-level evidence claims
10documented trust controls
2history events

How to read the evidence

The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.

AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.

Decision context

Provider and category

Box Agent is documented under Enterprise and is associated with Box. Category labels help navigation but do not replace product-specific evidence.

Verification status

The public profile is marked editorially reviewed and was last checked on October 1, 2026.

Trust coverage

10 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.

Source-first use

For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.

Capabilities, strengths and deployment checks for Box Agent

Box Agent is classified as Enterprise Content Agent from Box. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.

Unternehmensdokumente analysieren

This use case is part of the stored profile for Box Agent. The related strength is “Direkter Box-Inhaltskontext”. In a production evaluation, the practical boundary to verify is: Ordner- und Dateiberechtigungen regelmäßig auditieren.

Content-Workflows

This use case is part of the stored profile for Box Agent. The related strength is “Enterprise-Berechtigungen”. In a production evaluation, the practical boundary to verify is: Vertrauliche Inhalte nach Unternehmensrichtlinien behandeln.

Informationssynthese

This use case is part of the stored profile for Box Agent. The related strength is “Mehrstufige Content-Aufgaben”. In a production evaluation, the practical boundary to verify is: Ausgaben vor Weitergabe auf Quellenbezug prüfen.

Dokumentenbasierte Aufgaben

This use case is part of the stored profile for Box Agent. The related strength is “Integration in bestehende Dokumentenabläufe”. In a production evaluation, the practical boundary to verify is: Ordner- und Dateiberechtigungen regelmäßig auditieren.

What to verify before adoption

  • Ordner- und Dateiberechtigungen regelmäßig auditieren. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • Vertrauliche Inhalte nach Unternehmensrichtlinien behandeln. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • Ausgaben vor Weitergabe auf Quellenbezug prüfen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Editorial boundary: The use-case and strength descriptions are product-specific editorial context based on the stored profile. Trust, privacy and governance statements are only presented as facts when field-level primary-source evidence exists.

Verified history

The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.

  • October 1, 2026 · Source Maintenance
  • September 30, 2026 · New profile

Official sources

This profile links 5 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.

Frequently asked questions

What is Box Agent?

Box Agent is listed by AgentenCode as an enterprise agent or agentic product from Box.

How much trust evidence is documented for Box Agent?

The current trust layer documents 10 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.

When was this profile last checked?

The current profile verification date is October 1, 2026. The linked primary sources remain authoritative if the product changes between checks.

Method note: AgentenCode does not certify GDPR or EU AI Act compliance. It documents evidence that can support a separate legal, security or procurement assessment.