Technology
Dropbox, Inc. (DBX)
Data as of July 16, 2026
Environment story
Dropbox discloses minimal direct environmental data in its 10-K filing. No Scope 1, Scope 2, or Scope 3 emissions figures are provided. No net-zero target date is disclosed. The company operates significant custom-built data center infrastructure in co-location facilities and relies on Amazon Web Services, both of which carry material energy and carbon footprints. Infrastructure costs increased $53.1 million in 2025 due to data center refresh cycles and facility costs, suggesting ongoing capital-intensive operations. The company makes no reference to renewable energy commitments, carbon reduction targets, or environmental controversies. Without disclosed emissions baselines, targets, or mitigation strategies, environmental performance cannot be rigorously assessed. The absence of substantive ESG reporting on environmental metrics represents a significant gap relative to peer practices.
Criticisms on file
No material criticisms on file for this pillar.
Disclosed initiatives
No disclosed initiatives on file for this pillar.
Social story
Dropbox conducted a significant workforce reduction in Q4 2024 but provides no quantitative disclosure of CEO-to-median-worker pay ratios, diversity metrics for executive or board leadership, or workforce composition by gender or underrepresented groups. The 10-K notes Andrew W. Houston (Co-Founder and CEO) remains critical to vision and strategy, but does not disclose his compensation relative to median worker pay. The company operates under a Virtual First work model with a distributed global workforce across ~180 countries, creating coordination risks but no apparent union-suppression issues are documented. No modern slavery statements, human rights audits, or supply-chain ethics certifications are disclosed. The company does not report turnover rates, plant safety metrics, or labor union standing. Diversity and inclusion programs are not mentioned. The absence of structured social impact disclosure limits ability to assess alignment with ESG benchmarks.
Criticisms on file
-
Dropbox Sign Security Breach (April 2024): Unauthorized access to Dropbox Sign production environment, triggering consolidated class action lawsuit in Northern District of California and ongoing regulatory scrutiny.Source: DBX Form 8-K filed May 1, 2024; 10-K Risk Factors disclosure
-
Q4 2024 Workforce Reduction: Substantial headcount reduction resulting in severance, benefits and related expenses; impact on employee morale and retention not quantified.Source: DBX 10-K MD&A and Notes to Consolidated Financial Statements
Disclosed initiatives
-
Virtual First Work ModelTransition to distributed remote-first workforce since October 2020, intended to improve employee satisfaction and attract talent globally.
Governance story
Dropbox maintains a single class of Class A common stock structure with no disclosed dual-class voting disparities, supporting governance neutrality on share structure. Board independence percentage is not disclosed in the 10-K filing, preventing assessment against the 75% independence threshold. No specific lobbying expenditures targeting environmental deregulation or consumer-protection rollbacks are disclosed. The company faces material regulatory and litigation exposure: the April 2024 Dropbox Sign unauthorized access incident has triggered ongoing class action litigation and regulatory scrutiny, representing a significant governance and operational risk. The company is subject to SEC and regulatory investigations related to the breach. No antitrust proceedings or SEC consent decrees are disclosed. The company maintains convertible debt (2026 and 2028 Notes) and a secured term loan facility with covenants limiting operational flexibility. Overall governance posture is adequate but weakened by unresolved security-related regulatory exposure and lack of board composition transparency.
Criticisms on file
-
Dropbox Sign Unauthorized Access Incident (April 24, 2024): Breach of production environment leading to consolidated class action lawsuit and ongoing regulatory scrutiny; company management indicated awareness of reputational and customer-relationship harm.Source: DBX Form 8-K filed May 1, 2024; 10-K Risk Factors and MD&A
-
Data Security and Privacy Breach History: 10-K discloses multiple past security incidents including unauthorized access to URLs embedded in Dropbox Sign content shared with third parties; error in anti-malware service integration resulted in URL exposure to third-party subscribers.Source: DBX 10-K Risk Factors section on Privacy and Data Security
Disclosed initiatives
-
Cybersecurity Compliance and Incident ResponseCompany reports continuous assessment of security posture via penetration testing and red-team exercises; elevated response protocols following April 2024 breach.
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of Dropbox, Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open Dropbox, Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics