Box AI
Box · Productivity · US · www.box.com/ai
services/box-ai.yamlVendor data-handling terms
“Does Box permit AI models to train on customer content? As one of the core pillars of Box's AI Principles , Box will not train AI models on our customers' content without their explicit approval.”
“Box does not retain Box AI prompts and resulting outputs without explicit customer consent, nor do we allow our AI model service partners to do so. Once an answer is returned from our AI model provider that information is deleted from that provider's system. Once a document or application is closed in Box, all question and answer information is deleted from Box AI.”
Box Zones covers stored content; the trust page does not state in which region the model calls are processed.
“Currently, Box AI uses AI foundational models from multiple vendors, such as Microsoft Azure, Google, and others.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| box.com | app | vendor-documented |
| app.box.com | app | vendor-documented |
| api.box.com | api | vendor-documented |
Assessment
Reasoning: The AI features inside Box's content platform. No training without approval, prompts and outputs not retained by Box or its model partners, and existing Box permissions govern what the AI can read. Region of model processing is not stated.
Flags: No training or retention without consent · Model processing region not stated · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training, retention and model-provider terms verified against the Box AI Trust page.
- 2026-09-16Added with vendor-documented domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.