A small group working on the parts of the browser nobody can check.
Local inference, hardware-bound identity, agent security, on-device retrieval, and the measurement work that keeps all four honest. We publish the method and the limitations alongside the result — including the results that went against us.
Five areas, and what we don’t know yet.
Each area has a lead, a written agenda, and a list of open problems we have not solved. We publish the open problems because a research group that only lists its answers is a marketing department.
Local inference
Making capable models run inside a browser's latency and memory budget, on hardware people already own, without the browser becoming unusable while they do.
Local inference
Open problems we are working on
- Speculative decoding schedules that yield to the compositor under load
- Quantisation that degrades gracefully on extraction rather than falling off a cliff
- Honest capability reporting so the agent can decline a task it cannot do well
Selected work
Applied cryptography
Hardware-bound identity that a user cannot accidentally export and an administrator cannot silently extract, plus the migration path to post-quantum primitives.
Applied cryptography
Open problems we are working on
- Recovery flows for non-exportable keys that do not reintroduce a central authority
- Reducing the post-quantum ClientHello below the initial congestion window
- Attestation that proves key residency without becoming a tracking identifier
Selected work
Agent security
A browser that can act on your sessions is a new class of security problem. We work on capability boundaries, content provenance, and making failures visible.
Agent security
Open problems we are working on
- Confirmation boundaries that cover action parameters, not just the action
- Provenance that survives summarisation and tool chaining
- Detecting multi-turn priming without keeping a transcript we promised not to keep
Selected work
On-device retrieval
Indexing everything a person reads, on their own disk, fast enough to query mid-sentence and small enough that they never notice the storage.
On-device retrieval
Open problems we are working on
- Chunking that respects document structure without a per-site parser
- Incremental index maintenance that never competes with rendering
- End-to-end answer correctness as a metric, replacing recall@k
Selected work
Measurement & transparency
Auditing what software discloses, including ours. If a privacy claim cannot be independently checked, we treat it as marketing rather than architecture.
Measurement & transparency
Open problems we are working on
- Verifiable claims about local-only execution that a user can check themselves
- Reproducible network-disclosure measurement across OS-mediated services
- A disclosure taxonomy that survives disagreement about categories
Selected work
Full papers, most recent first.
Every paper carries an abstract, a stated method, figures with underlying data, an explicit limitations section, and its artefacts. See the full publication record →
Method first, headline second.
We have a commercial interest in these results and pretending otherwise would be worse than admitting it. These are the rules we hold ourselves to so the work stays checkable by people who do not trust us.
The threshold is set before the run
Success criteria are written down and circulated internally before data collection begins, so a disappointing result cannot quietly become a different question.
Every paper says where it is weak
Selection bias, synthetic data, narrow hardware samples. If a caveat would change how you read the number, it belongs in the paper rather than a footnote nobody reaches.
The harness ships with the claim
Corpora, evaluation harnesses, and attribution tables are published or available on request under a stated licence.
Papers are versioned in public
When a reader finds an error we revise the paper, bump the version, and say what changed at the top. Five of the ten have been corrected this way.
Who does the work.
Four researchers and three external advisors, ten papers between them. Small enough that every paper has a person you can write to about it. Read more about the team →
Ways in.
Three-month residencies
We host two visiting researchers a year on a three-month residency, funded, remote, working on one of the open problems above. No publication embargo and no assignment of prior work.
We pay you to break it
Novel prompt-injection vectors that defeat the current defence stack are paid on a published scale. Three external researchers contributed 160 vectors to DBR-2026-03 under this programme.
Tell us we’re wrong
If you have run something comparable and got a different answer, we want the data. Replications that contradict a published result get a correction notice and a credit on the paper.
Disagree with a number? Tell us.
We would rather be corrected in public than be wrong in private. Every paper lists a correspondence address and a person who will read it.
Coordinated disclosure · 90 days · security@dartbrowser.com