Open source · Audited · v0.9 beta

Browse dark.
Ship clean.

Kepler is a browser for people who read the source. Every tab runs in its own sealed process, every request is accountable, and the whole thing is a reproducible build you can rebuild yourself in about eleven minutes.

Linux · macOS · Windows No telemetry, ever MPL-2.0
kepler — verify
Kepler start page in Secure browsing mode with shortcut tiles
Secure browsing: private, HTTPS-only, every tracker blocked, nothing saved.
Kepler browsing GitHub with the AI side panel open
Kepler with the built-in AI panel — Claude, ChatGPT, Gemini, Copilot and Perplexity one click away.
Kepler showing a Wikipedia article on Kepler-22b in dark mode
Dark mode for every site — even Wikipedia.

Anonymous by default

No face. No name. No trail.

Like a mask in a crowd, Kepler makes you indistinguishable. Fingerprint flattening, sealed tabs and optional orbit relays mean the sites you visit see a Kepler user — never you.

  • Every Kepler user presents the same fingerprint — canvas, fonts, timezone and screen.
  • Cookies and storage die with the tab unless you say otherwise.
  • Orbit relays hide your IP address behind three volunteer hops.
  • No account, no sign-in, no sync server that knows who you are.
A white mask on a black background, symbolising anonymity

Built for liftoff

Engineered like a launch vehicle.

Rockets don't get a second try, so every stage is tested before it flies. Kepler is built the same way: a Rust engine that starts cold in under a second, and a release pipeline where nothing ships until it's verified.

  • Cold start in under a second, even with a hardened profile.
  • Memory-safe Rust in the parsers, network stack and sandbox broker.
  • Every parser is fuzzed continuously before a release leaves the pad.
  • Signed, reproducible builds — same commit, same bytes, every launch.
A rocket lifting off with its engine lit

Ready when you are

Point it at the dark and go.

Free, open source, and quiet by default.