Start free trial

Dropbox

Docs & evidenceTwo-way syncOAuth 2.0

Evidence that arrives as a PDF has to live somewhere, and for a lot of teams that somewhere is already Dropbox. Urengi files each report in the folder you name and links it from the review, so there is one copy rather than two.

Category
Docs & evidence
Auth method
OAuth 2.0
Direction
Two-way
Sync frequency
Real time
Scopes requested
3
Available on
All plans
Maintained by
Urengi

What the Dropbox integration does

Three jobs that keep evidence in one place rather than in two.

Reports file themselves

A SOC 2 or pen test collected by Urengi lands in the folder you named, under the vendor and the year, and the review links to it.

Existing evidence gets found

Reports already sitting in the folder are matched to vendors on connect, so a review does not chase a document you have had for months.

Expiry is read from the file

The report's period end becomes the review's reopening date, so an out-of-date SOC 2 is caught by the schedule rather than by an auditor.

Exactly what Urengi can see

Three scopes on a single app folder. Urengi cannot see the rest of your Dropbox.

Urengi reads

  • File and folder names inside the app folder
  • Evidence documents Urengi filed
  • File modification dates

Urengi writes

  • Evidence documents into the app folder
  • Vendor and year subfolders
  • Nothing outside that folder, ever

Urengi never touches

  • Any file outside the app folder
  • Shared links, teams or member data
  • Paper docs or file comments
  • Anything after you revoke the token

Connect it in four steps

One authorisation, one field mapping, and a test sync you run yourself.

01

Authorise the connection

Open Dropbox from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.

02

Choose what syncs

Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.

03

Map your fields

Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.

04

Run a test sync

Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.

Your token, your rules.

Urengi stores the Dropbox token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in Dropbox and every Urengi write stops within seconds the audit log keeps the history, the connection simply ends.

Read the security statement
SOC 2 Type II
audited annually
Per-tenant keys
no shared secrets
Revocable in Dropbox
one click, no ticket
EU or US residency
chosen at signup