Product Pricing Security & data Research Publications Blog About Careers Alpha Talk to us Download alpha
Dart Browser Research

A small group working on the parts of the browser nobody can check.

Local inference, hardware-bound identity, agent security, on-device retrieval, and the measurement work that keeps all four honest. We publish the method and the limitations alongside the result — including the results that went against us.

Publications17Ten full papers, plus technical notes, preprints, datasets, and talks since 2025.
Open artefacts30Corpora, harnesses, and attribution tables released or available on request.
Research areas5Each with a named lead and a written list of open problems.
External contributors3Independent researchers paid to break our defences, plus three advisors.
Agenda

Five areas, and what we don’t know yet.

Each area has a lead, a written agenda, and a list of open problems we have not solved. We publish the open problems because a research group that only lists its answers is a marketing department.

Local inference

2 papersLead · Mohit Bhardwaj

Making capable models run inside a browser's latency and memory budget, on hardware people already own, without the browser becoming unusable while they do.

Open problems we are working on

  • Speculative decoding schedules that yield to the compositor under load
  • Quantisation that degrades gracefully on extraction rather than falling off a cliff
  • Honest capability reporting so the agent can decline a task it cannot do well

Applied cryptography

2 papersLead · Dr. Anna Weiss

Hardware-bound identity that a user cannot accidentally export and an administrator cannot silently extract, plus the migration path to post-quantum primitives.

Open problems we are working on

  • Recovery flows for non-exportable keys that do not reintroduce a central authority
  • Reducing the post-quantum ClientHello below the initial congestion window
  • Attestation that proves key residency without becoming a tracking identifier

Agent security

2 papersLead · Priya Raghunathan

A browser that can act on your sessions is a new class of security problem. We work on capability boundaries, content provenance, and making failures visible.

Open problems we are working on

  • Confirmation boundaries that cover action parameters, not just the action
  • Provenance that survives summarisation and tool chaining
  • Detecting multi-turn priming without keeping a transcript we promised not to keep

On-device retrieval

2 papersLead · Mohit Bhardwaj

Indexing everything a person reads, on their own disk, fast enough to query mid-sentence and small enough that they never notice the storage.

Open problems we are working on

  • Chunking that respects document structure without a per-site parser
  • Incremental index maintenance that never competes with rendering
  • End-to-end answer correctness as a metric, replacing recall@k

Measurement & transparency

2 papersLead · Dr. Tomás Oliveira

Auditing what software discloses, including ours. If a privacy claim cannot be independently checked, we treat it as marketing rather than architecture.

Open problems we are working on

  • Verifiable claims about local-only execution that a user can check themselves
  • Reproducible network-disclosure measurement across OS-mediated services
  • A disclosure taxonomy that survives disagreement about categories
Recent papers

Full papers, most recent first.

Every paper carries an abstract, a stated method, figures with underlying data, an explicit limitations section, and its artefacts. See the full publication record →

How we publish

Method first, headline second.

We have a commercial interest in these results and pretending otherwise would be worse than admitting it. These are the rules we hold ourselves to so the work stays checkable by people who do not trust us.

Pre-registration

The threshold is set before the run

Success criteria are written down and circulated internally before data collection begins, so a disappointing result cannot quietly become a different question.

Limitations

Every paper says where it is weak

Selection bias, synthetic data, narrow hardware samples. If a caveat would change how you read the number, it belongs in the paper rather than a footnote nobody reaches.

Artefacts

The harness ships with the claim

Corpora, evaluation harnesses, and attribution tables are published or available on request under a stated licence.

Corrections

Papers are versioned in public

When a reader finds an error we revise the paper, bump the version, and say what changed at the top. Five of the ten have been corrected this way.

Work with us

Ways in.

Visiting researchers

Three-month residencies

We host two visiting researchers a year on a three-month residency, funded, remote, working on one of the open problems above. No publication embargo and no assignment of prior work.

apply · research@dartbrowser.com with a one-page proposal
Adversarial programme

We pay you to break it

Novel prompt-injection vectors that defeat the current defence stack are paid on a published scale. Three external researchers contributed 160 vectors to DBR-2026-03 under this programme.

disclose · security@dartbrowser.com · 90-day coordinated disclosure
Replication

Tell us we’re wrong

If you have run something comparable and got a different answer, we want the data. Replications that contradict a published result get a correction notice and a credit on the paper.

replicate · harnesses and corpora on the artefacts page
Correspondence

Disagree with a number? Tell us.

We would rather be corrected in public than be wrong in private. Every paper lists a correspondence address and a person who will read it.

Coordinated disclosure · 90 days · security@dartbrowser.com