Security

We built AcrossView so that we cannot see your screen

A remote-support tool can see everything on a computer. That is why support sessions are end-to-end encrypted, why the person at the computer approves every session, and why we explain exactly what our servers can and cannot do.

What our servers can and cannot see

In a support session, our servers
can seewho connected to whom, when, for how long, and how much data flowed; your IP address
cannot seethe screen, the voice, the camera or the chat: these are encrypted with keys that exist only on the two devices
cannot doforge a chat message, a click or a keystroke, or replay one that was sent earlier

How a session is protected

1. A fresh key for every session

When a session is accepted, the two devices each create a new X25519 key pair and exchange the public halves. From the shared secret they derive, with HKDF-SHA256, one key for the screen and sound, one for messages, and the security code. The keys are thrown away when the session ends.

2. A security code on both screens

Both people see the same six-digit code. If anyone, including a compromised server, swapped the keys to sit in the middle, the two codes would differ. Reading the code aloud catches it.

3. Encrypted from screen to screen

Every video and audio frame is encrypted with AES-GCM on the sending device and decrypted only on the receiving one. Our room server forwards frames it cannot read.

4. Sealed messages and input

Chat messages, clicks and keystrokes are sealed with AES-256-GCM, bound to the sender and to the kind of message. Each piece of input carries an increasing number. A message that is forged, altered, attributed to someone else or replayed fails to open and is thrown away. Our automated tests inject exactly such messages through the room server itself and check that none is carried out.

5. Consent first, and the person at the computer stays in charge

  • Nothing is shared until they press Allow, which waits five seconds after the request appears.
  • The request names who is asking and says when that identity is not verified.
  • Seeing the screen and using the mouse and keyboard are separate permissions; control can be switched off at any moment.
  • End session is always on screen and cannot be hidden by the other side.

6. Each computer has its own identity

The Windows app creates an Ed25519 key for the computer and proves it holds that key every time it connects; the ID is tied to that key. The key is stored encrypted with Windows' own data protection, for the signed-in user only.

Meetings

Meetings are encrypted between each browser and our servers, which pass the media on to the other participants. They are not end-to-end encrypted, so that up to 100 people can take part efficiently. Meetings are not recorded.

The rest of the system

  • All connections use TLS. Servers run in Mumbai, India.
  • We do not record sessions, and we do not keep chat.
  • This website has no analytics, advertising or tracking scripts.
  • AcrossView is written from scratch by its own team; it is not a re-branded copy of another remote-desktop product.

Reporting a vulnerability

If you find a security problem, please tell us through the contact form before telling anyone else, and give us a reasonable time to fix it. We will reply, keep you informed, and thank you publicly if you wish.