Private by architecture.

Blanc’s privacy is structural: what the browser blocks, what it refuses to run, and how it handles the data you care about.

The shield shows blocking inside the browser. This illustration uses a sample count of two blocked requests.

The browser itself is the security layer.

Blocking lives in the network layer.

Blanc Blocker runs inside the browser, not as an extension. Reviewed EasyList and EasyPrivacy snapshots are hash-pinned into each Blanc release; the browser does not fetch changing filter scriptlets at startup. The shield shows what was blocked on each page. How blocking works.

Every page runs sandboxed.

Web pages run inside Chromium’s sandbox, isolated from the browser and from your files. Blanc’s own pages — settings, history, favorites — live on a privileged internal scheme that ordinary web content cannot link into, and the browser re-checks who is calling on every internal request.

No general extension installation.

Blanc does not support installing arbitrary browser extensions. The bundled uBlock Origin provider is an optional blocking integration for regular tabs on supported builds, not general Chrome Web Store support. Private tabs use Blanc Blocker.

How Blanc handles sensitive data.

Sync the server cannot read.

Sync is off by default. Favorites, eligible settings, and optional open-tab snapshots are encrypted on your device. The current v1 server stores ciphertext under an opaque account locator and cannot read or merge it. The passphrase is never stored or sent, and the retained key is wrapped by the operating system credential service.

Passkeys live in the Secure Enclave.

On a Mac with Touch ID, Blanc creates device-bound passkeys inside Apple’s Secure Enclave. The private key never leaves the chip, and Blanc is signed with an Apple-issued Developer ID and provisioned to hold its own keychain access group. macOS only for now.

Permissions ask first.

Camera, microphone, location, notifications — each request raises a Blanc prompt, and each decision is remembered for that site. Decisions made in a private tab are never written to disk.

Usage measurement waits for your choice.

A fresh profile presents usage measurement on, but sends nothing until you save the choice and lets you turn it off before continuing. If left enabled, packaged builds count launches and a fixed allowlist of local feature actions using the narrow pseudonymous payload listed in the privacy policy—never URLs, searches, page content, game state, or private-tab feature activity. The choice stays device-local and can be switched off at any time.

Respecting the VPN you already chose.

WebRTC stays in its lane.

WebRTC can reveal network addresses that sidestep a proxy. Blanc limits it to your default connection by default, and an optional “disable direct UDP” mode blocks a specific direct-UDP path around an application proxy. It is not a promise of anonymity — it reduces one well-known proxy-bypass risk.

DNS you can encrypt — or hand to your VPN.

Blanc can send DNS lookups over an encrypted connection (DoH) to Cloudflare, Quad9, Mullvad, or a provider you name — or stay out of the way and leave DNS to your system or VPN. Encryption hides your lookups from the network in transit; it does not hide the sites themselves, and it makes the resolver a party you choose to trust. Automatic mode upgrades opportunistically and is not a guarantee.

1Password login fill on macOS.

Optional 1Password fill on macOS.

Use matching Login items from your installed 1Password desktop app and account. Blanc’s narrow SDK integration is off by default, and credential lookup and fill require your explicit action. It is not automatic fill, an extension runtime, or a Blanc password store.

A local hint, before any lookup.

A small hint can appear when the visible page has a current-password field. It uses bounded structure-only metadata, never field values or page text, and makes no request to 1Password. Settings can explicitly verify your saved 1Password account identifier.

Set up 1Password in Blanc

See when your microphone or camera is in use.

Access you can see and stop.

The Island shows microphone and camera use across the window’s tabs and popups. Open the indicator’s popover to see the active surfaces and stop their access. Closing a capturing tab ends its access immediately.

A choice for choppy call playback.

Call audio buffering offers Automatic, Stable, and Resilient receive-buffer modes for WebRTC calls. Stable targets about 400 ms; Resilient targets about one second. Extra buffering trades conversational responsiveness for more tolerance of choppy playback. It cannot guarantee a fix for network, source, Bluetooth, driver, or hardware faults.

A clearer explanation and a choice about recovery.

Certificate failures get their own explanation.

Blanc shows a dedicated certificate-failure surface with site-trust details, so a connection problem does not disappear into a generic navigation error.

Restore tabs or start fresh.

After an unclean shutdown, Blanc offers explicit recovery choices. Recovery runs locally and does not upload browsing data.

Diagnostics you choose to share.

Settings → Export diagnostics creates a local file for troubleshooting. Review it before sharing it with support; exporting does not send it anywhere.

A public security baseline.

Blanc’s current OpenSSF self-assessment records all 24 Level 1 controls and all 19 Level 2 controls as met. The public record covers how the project handles source, changes, dependencies, vulnerability reports, build provenance, and releases.

Read the OpenSSF assessment
OpenSSF Baseline version 2026.08.28, Level 2

Check that a download is really ours.

public v1.27.0 · October 3, 2026

Verify the package for your platform.

Authentication evidence for the official v1.27.0 downloads
PlatformWhat is checkedArtifacts and evidence
macOSDeveloper ID signature, notarization, Gatekeeper assessment and the app’s stapled ticket.Official DMG · Mac verification steps · v1.27.0 verification record
WindowsValid, timestamped Authenticode signature with the exact expected publisher; installer digest bound to windows-signature.json.Official installer and signature report · Windows verification steps · v1.27.0 native checks
LinuxAppImage checksum authenticated by the Sigstore-signed SHA256SUMS manifest. Linux has no equivalent OS-level publisher signature here.Official AppImage, manifest and Sigstore bundle · Manifest verification steps · v1.27.0 public-download checks

These checks authenticate the publisher and downloaded bytes. They do not establish that the application is free of security flaws or provide an independent review of its architecture. The release record distinguishes hosted checks, physical-machine confirmations and owner waivers.

An external audit is still pending.

The status, plainly

No independent external security audit has been completed. Internal and AI-assisted security reviews are maintainer evidence. The next step is preparing a scope and funding proposal, without promising an audit date.

Known work belongs in the scope

Sync v1 encrypts data, but possession of its account locator authorizes ciphertext retrieval, replacement and deletion. Concurrent writes and deletion can race. Merged request-size limits are not yet deployed. These unresolved findings remain part of the public maintainer assessment.

A quieter browser, with the quiet parts documented.

download blanc