Security
Last updated
Security at Default
We take security seriously. Default protects customer data with industry-standard controls across our infrastructure, application, and operational practices, and we continuously review our posture as the platform evolves.
Default is SOC 2 Type II compliant, and our hosting providers operate in SOC 2 audited environments. Data is encrypted in transit and at rest. Access to production systems is restricted, logged, and reviewed.
Workspace admins can verify their email domain and set up Single Sign-On (SSO), so your team signs in through your identity provider, such as Okta or Microsoft Entra.
The Default Pixel on your website follows built-in privacy and data handling rules. It drops the value of any form field whose name matches a sensitive pattern, such as password or token, never sends file uploads, and respects the consent choices your cookie banner passes to it.
Trust center
A full trust center with certifications and security documentation is coming soon. Our sub-processor list is available at Sub-processors.
Contact
For specific security questions, vulnerability reports, or to request our SOC 2 Type II report and other security documentation, contact security@default.com.
The marketing engine behind the best teams
One platform to manage workflows, enrich records, route leads, and schedule meetings.
