Security and data handling
Across Effective Date: 2026-08-15
This page states plainly what Across does with your data when you connect your tools and run a launch. Every claim here describes what the product does today. Across does not hold SOC 2, ISO 27001, or HIPAA certification, and this page claims none.
What data Across holds
When you connect an analytics tool and track a feature, Across stores one snapshot per sync of usage counts:
- Total users and users who used the feature
- The adoption percentage
- Per-account rollups: account name, plan, adopting users, last seen
Adoption data contains no record of what any individual end user did in your product. Across does not extract per-person event streams from your analytics tool.
Beyond that, Across stores what you create: releases, launch plans, delivery records, and connection records (which tool, which account, what status).
Credentials and connections
Tool connections run through OAuth at our integration partner (Composio). Across stores an account reference and a connection status, not the credentials, for:
- Mixpanel, Amplitude, Pendo, Intercom, Customer.io
- Slack, GitHub, Notion
Zendesk is the one direct connection, because its Help Center API is not available through the broker. The Zendesk API token is stored write-only. It is used to publish articles you approved and is never displayed in the app or returned by any API.
Card details never touch Across. Payments run through Stripe.
Hosting and encryption
Across runs on Vercel. Application data lives in Neon PostgreSQL. Sign-in runs through Neon Auth (Better Auth).
All traffic to and from Across travels over HTTPS/TLS. Neon encrypts the database at rest. Vercel and Stripe encrypt their stored data.
Permissions Across requests
- Mixpanel: read event usage counts (read-only)
- Amplitude: read event usage counts (read-only)
- Pendo: read feature usage counts (read-only)
- Intercom: read message engagement counts (read-only)
- Customer.io: read broadcast metrics (read-only)
- GitHub: read the repos and projects you pick
- Notion: read the pages you pick; create launch pages at destinations you pick
- Slack: read messages in channels you pick; post to the channel you pick on approved delivery
- Zendesk: publish help-center articles you approved
Analytics access is read-only. Across never edits events, dashboards, or any other data in your analytics tool.
Sub-processors
Customer data passes through these services:
- Vercel: hosting and compute
- Neon: PostgreSQL database and authentication (Neon Auth, Better Auth)
- Vercel Blob: image and file storage for help-center assets
- Composio: OAuth broker for connected tools
- Stripe: payments
- Resend: email delivery
- PostHog: product analytics for Across itself, opt-in only
- Amazon Web Services (Bedrock): AI model (Claude) that drafts launch plans from your release notes
Retention and deletion
Your data is kept until you delete it or your account, whichever comes first. On account deletion, data is deleted or anonymized within 30 days, except billing records kept where the law requires.
You can delete your account yourself from settings, or email hello@across.dev and we will do it for you. Disconnecting a tool removes its connection record. Disconnecting Zendesk deletes the stored token immediately.
Access control
Across is a single-operator product. Only the operator has access to production systems: the hosting account, the database, and the integration accounts, each behind its provider's own account security. There is no wider team, and no shared credentials.
Reporting a vulnerability
Email hello@across.dev with details and steps to reproduce. We will acknowledge the report and work on a fix. Please do not run automated scans that could degrade the service for customers.
Certifications
Across does not hold SOC 2 Type II or ISO 27001 today, and has no penetration test report to share. Nothing on this page should be read as an audit result. If your review requires one, a security review call with the founder is available on request: email hello@across.dev.
In-product announcements and your end users
If you run in-product announcements (banner, modal, coachmark, guided tour), Across serves them itself and records, per visitor:
- Whether the announcement matched, was seen, was clicked, or was dismissed
- The session id, so a banner does not re-show within one session
The visitor id is whatever stable id your own snippet reports: your user id, an email hash, or an anonymous cookie. Across uses it only to cap frequency and report counts.
Saved audiences are rule sets you define. Targeting attributes your snippet reports are stored so your rules and reach estimates can read them back.
This makes Across a data processor for your end users' announcement data. It is used only to target, deliver, and report on the announcements you create.
Nothing is published without your approval
A launch plan starts as a draft. Delivery is refused until you approve the plan. After approval, delivery does what the plan says: the Slack message goes to the channel you picked, the help-center article goes to the section you picked, the email goes out through our email provider. Nothing is announced on a schedule or on its own.
See the Privacy Policy for the full data inventory, retention periods, and your rights.
Security questionnaire answers
The block below answers the standard buyer security questionnaire for this product as it runs today. Copy the pairs straight into a vendor form. If a question you need is missing, email hello@across.dev.
Where is the application hosted, and where is data stored? The application runs on Vercel. Application data is stored in Neon PostgreSQL. Authentication runs through Neon Auth (Better Auth).
Is customer data encrypted in transit and at rest? Yes. All traffic travels over HTTPS/TLS. Neon encrypts the database at rest. Vercel encrypts its stored assets.
Who inside your company can access customer data? One person, the operator. Production access is limited to the operator's accounts on Vercel, Neon, and the integration broker. There is no wider team today.
Which sub-processors process customer data? Vercel (hosting), Neon (database and auth), Vercel Blob (file storage), Composio (OAuth broker for connected tools), Stripe (payments), Resend (email delivery), PostHog (opt-in product analytics for Across itself), and AWS Bedrock (Claude, for drafting launch plans).
How long is customer data retained? Until the customer deletes it or their account. Account deletion purges data within 30 days, except billing records kept where the law requires.
How can we request deletion of our data? Email hello@across.dev or delete the account from settings. Disconnecting a tool removes its connection record and any stored token.
What is your breach notification process? If we confirm a breach that affects customer data, we email the affected customers promptly, and no later than 72 hours after confirmation, with what happened and what we are doing about it.
What permissions does your product request in our tools? Analytics tools (Mixpanel, Amplitude, Pendo, Intercom, Customer.io): read-only usage counts. GitHub: read access to the repos and projects we pick. Notion: read access to pages we pick, plus creating launch pages at destinations we pick. Slack: read access to channels we pick, plus posting to the channel we choose when a launch is delivered. Zendesk: publishing help-center articles we approved. Credentials for brokered tools stay with Composio; Across stores only a connection reference.
Do you process our end users' data? Yes, if in-product announcements are used. Across stores per-visitor announcement state (matched, seen, clicked, dismissed), a session id for frequency capping, and the visitor attributes our snippet reports, in order to target and report on announcements. Across acts as a data processor for this data and uses it only to deliver the announcements we create.
Do you hold SOC 2, ISO 27001, or similar certification? No. Across holds neither SOC 2 Type II nor ISO 27001 today, and has no penetration test report to share. A security review call with the founder is available on request.