Browse freely. Stay sovereign.
Dart is a Chromium browser where the AI agent runs on your machine, your identity lives in your device’s security chip, and the model is one you already pay for. No middlemen. No markup. No telemetry.
Private beta on macOS & Windows · general availability Q4 2026
Product preview with sample data. Inference runs on-device whenever a local model is selected.
Dart works with every major provider and every local runtime. You own the inference; we build the browser.
Your browser is the most surveilled software you run.
Every search, every tab, every autofill — your browser is the richest data source your device generates. The incumbents monetise all of it. Dart is the first browser designed from the ground up to invert that relationship.
Privacy. Intelligence. Sovereignty.
Dart is built on three non-negotiable guarantees. They compound: strong cryptographic identity makes the agent trustworthy; local AI makes privacy enforceable; open model choice makes the whole thing yours.
Hardware-bound. Quantum-safe.
Your identity is attested by a hardware security module — TPM on Windows/Linux, Secure Enclave on macOS. Keys never leave the chip. Post-quantum algorithms (ML-KEM, ML-DSA) are on by default for new sessions.
Agent runs on your machine.
The Dart Agent indexes your tabs, history, bookmarks, and local files. It answers questions, summarises pages, and completes tasks — all on-device. No prompt leaves your machine unless you explicitly choose a cloud model.
Your model. Your terms.
Connect any provider — Anthropic, OpenAI, Ollama, vLLM, LM Studio, OpenRouter. Credentials live in your OS keychain. We never proxy or mark up inference. Dart charges for the browser; you own the intelligence.
Every tab becomes a knowledge source.
The Dart Agent maintains a local semantic index of everything you read. Ask it anything — compare two papers you read last week, find the clause in that PDF you signed, draft a reply grounded in your actual browsing context.
It reads what you read
The agent reads your open tabs, recent history, bookmarked pages, and local documents. It answers with citations, not hallucinations.
It finishes the task, not just the sentence
Chain tasks across tabs: research → summarise → draft → send. The agent navigates, fills forms, and extracts data — always within bounds you set.
You can check its work
Every agent action is logged to a local, human-readable audit trail. You see exactly what it read, what it skipped, and why it concluded what it concluded.
Product preview with sample data. Inference runs fully on-device when a local model is selected.
We don't sell tokens. You don't pay markup.
Connect Dart to the LLM provider you already pay for, or point it at a local model on your laptop. We never proxy or mark up inference traffic. This is a permanent design choice, not a launch limitation.
Cloud key
Paste your API key. Validated client-side and stored in the OS keychain. Nothing transits our servers.
Local model
Auto-detects models running on localhost. Works fully offline. The only tier where regulated industries can run agents without risk.
OAuth sign-in
One-click provider sign-in. We never see raw credentials. Tokens stay on-device. Easiest path for non-power users.
Enterprise gateway
Your admin provides a gateway URL; the team signs in via SSO. Standard for Team and Enterprise tiers.
A browser that answers “who am I?” with hardware.
Dart’s identity layer uses your device’s security chip — TPM 2.0 on Windows and Linux, the Secure Enclave on macOS. Keys are generated inside the chip and cannot be exported, copied, or read out, even by an administrator. Post-quantum key exchange is on by default, not behind a flag.
Hardware security module. Keys are created inside it and never leave.
ML-KEM and ML-DSA. Quantum-safe handshakes on every new session.
Made for the people who can’t send it to the cloud.
Some teams can paste a contract into a chat window. Most of the interesting ones cannot. Dart exists for the second group — and everyone else gets the same guarantees for free.
Every claim on this page is one we had to measure.
“Runs locally.” “Post-quantum by default.” “Resistant to prompt injection.” These are easy to assert and hard to check, so we run the study, publish the method and the limitations, and release the harness. Three of our ten papers report a negative result about something we hoped would work.
People who've felt the gap.
"We evaluated six privacy-focused browsers for our legal team. Dart was the only one that could run local AI agents and provide hardware-attested identity for our SSO. The BYOM architecture meant our counsel could use the models our firm already licenses. Nothing else came close."
"The Dart Agent summarised 40 tabs from my research session in about 8 seconds, running entirely on my M3 Max. Not one character left my machine. That's the promise everyone else makes and nobody keeps."
"We're in fintech. Harvest-now-decrypt-later is a real threat model for us. Dart is the only browser that ships PQC key exchange by default rather than as an experimental flag."
"I use Claude for creative work, Llama for anything sensitive, and a fine-tuned model for my codebase. Dart lets me switch in one click. No other browser even tries to solve this."
"I've been running Pi-hole for years and using Firefox with uBlock. Dart's telemetry model is the first I've seen that's genuinely off by default rather than opt-out-if-you-know-where-to-look."
Quotes from private beta participants, shared with permission and lightly edited for length. Roles and locations are as self-described; surnames are abbreviated for privacy.
Questions, answered.
Is Dart just another privacy browser?
Why build on Chromium?
What does "hardware-bound" mean in practice?
What data does Dart send to your servers?
Does the agent read everything I browse?
When can I use it?
The latest writing.
Engineering notes and benchmarks from the people building it. See everything on the blog →
The agentic browser security model: what changes when the browser can act
Prompt injection, data exfiltration, and the permission model that has to answer both.
Read →Why harvest-now-decrypt-later makes post-quantum urgent today
Traffic captured this year can be opened later. The window to act is shorter than most teams think.
Read →Running Llama 3.3 70B in your browser agent on consumer hardware
Benchmarks for the Dart Agent on M3, M4, and AMD AI-MAX. What is genuinely usable today.
Read →Your browser should work for you.
Join the people who think the next phase of the web should be measured by what the browser does for you, not to you.
No commitment · we'll write back personally