Who this comparison is for
File-Vault highlights
- Workspace-native File Explorer with governed upload, preview, download, organization, versions, trash, restore, sharing, metadata, and tags
- Document classification, retention, link/download policy, resource ACL, legal hold, audit, reporting, events, and webhooks
- Handler, RCP, Bridge v2, signed delivery, file binding, ContextResolver, and per-application operation grants
Dropbox Business highlights
- Dropbox Business provides its own storage and collaboration operating model
Capability matrix
| Capability | File-Vault | Dropbox Business | Notes |
|---|---|---|---|
| Workspace File Explorer | Native | provider experience | File-Vault exposes folders, search, preview, download, organize, versions, sharing, trash, restore, metadata, and tags inside the workspace. |
| Per-file/folder resource ACL | Native | varies | File-Vault evaluates database-managed resource principals after workspace permission checks. |
| Retention & legal hold enforcement | Native | varies | File-Vault includes retention policy and legal-hold records in governed destructive operations. |
| Trusted app upload, bind & signed delivery | Native | integration-specific | Applications can use explicit File-Vault capabilities without direct filesystem paths. |
| Handler/RCP/Bridge operation grants | Native | different integration model | File-Vault authorizes calling applications by operation and transport before resource checks. |
| ContextResolver, events, webhooks & audit | Native | varies | File-Vault exposes governed context, publishes file events, delivers configured webhooks, and records operational audit state. |
Total cost of ownership
File-Vault centralizes workspace file security, delivery, resource policy, audit, and application integration so individual business applications can reuse one governed file layer.
Assumptions
- The organization wants its workspace applications to share a consistent file-security and governance boundary.
Migration plan
From Dropbox Business · Inventory files and access requirements → define File-Vault taxonomy/policy → configure folders and permissions → move governed content → connect workspace applications
-
1
Inventory the file sets, folder structure, sharing behavior, metadata, and access requirements that belong in File-Vault.
-
2
Configure File-Vault document taxonomy, classifications, retention, sharing/download policies, folders, routing, and resource ACLs.
-
3
Place governed files into File-Vault and validate preview, download, versions, sharing, audit, and legal-hold behavior.
-
4
Authorize workspace applications for the File-Vault capabilities they require and use File-Vault references in business workflows.
Security
- Workspace permissions, File-Vault resource ACLs, operation grants, secure upload/delivery, sharing policy, retention, legal hold, protected secrets, audit, and trusted caller provenance are enforced around file operations.
Evidence & sources
About File-Vault
File-Vault provides a governed workspace for files and documents. Teams use a familiar File Explorer to browse folders, search, upload, preview, download, copy, move, rename, trash, restore, share, inspect versions, and manage metadata without exposing physical storage paths.
Governance controls include document categories and types, classification, retention, download and link policies, resource ACLs, folder templates, routing rules, legal holds, audit records, security-review records, webhook subscriptions, and usage reporting. Access is evaluated through workspace permissions and File-Vault resource policy before protected operations are performed.
Other applications can use File-Vault as their secure file layer through explicit capabilities for upload planning, secure upload, binding, unbinding, search, signed delivery, folders, versions, shares, audit, reports, webhooks, and ContextResolver. Handler, RCP, and Bridge v2 converge on the same operation and resource authorization model.