This concerns the bug bounty itself: Is there a Dropbox internal bug bounty program as well? As data is unencrypted, I assume the biggest thread to customer data are Dropbox employees.
It's possible that GP meant giving independent researchers access to internal tools. That would be interesting but also very difficult to pull off safely.