Bloom

Taking back the web...again.

A web browser built on the belief that the internet belongs to its users. No telemetry. No dark patterns. No gatekeeping. Just a browser that does what you tell it to.

What makes Bloom different

Bloom removes the layers of vendor policy that have accumulated in modern browsers and returns control to where it belongs: with you.

DANE/TLSA Verification

The first major browser to support DNS-Based Authentication of Named Entities. Domain owners can authenticate their certificates through DNS, bypassing the CA oligarchy.

Zero Telemetry

No usage data collection. No crash reporting unless you explicitly enable it. No experiments, studies, or "anonymous" analytics. Your browsing is yours alone.

No Policy Enforcement

No HSTS preload lists dictating which sites must use HTTPS. No vendor-imposed certificate pinning. No "unsafe site" warnings for HTTP. The browser renders — it doesn't govern.

Full URL Transparency

The complete URL, including protocol, is always visible. No more hidden "https://" or domain-only address bars. You see exactly where you are at all times.

Open Source

Built on Mozilla's Gecko engine with a transparent patch queue. Every change is documented, reviewable, and reversible. No hidden forks.

Your Settings, Your Rules

Every security decision has an off switch. Secure by default, but the user is always the final authority. No paternalistic overrides.

Bloom lotus

The browser should serve you.

Over the past decade, browsers have quietly shifted from being tools that serve users to being platforms that serve vendors. Features that were designed to "protect" users have become mechanisms of control — deciding which websites are trustworthy, which protocols are acceptable, and which certificates are valid.

Bloom starts from a different premise: the user is sovereign. The browser is a window into the web, not a filter. Security features should empower informed decisions, not make decisions on your behalf. Every option has an off switch. Every default can be changed.

Read Our Principles

Where we're headed

Bloom is being built in the open. Here's a glimpse of the road ahead.

Phase 1 — MVP with DANE

First release with DNS-Based Authentication of Named Entities. The foundational feature that no other major browser supports.

Phase 2 — Quality of Life Improvements

Traditional browser layout, keyboard shortcuts restored (Ctrl+Shift+Enter for .org), full URL with protocol always visible.

Phase 3 — Policy Removal

Removing code that dictates policy: HSTS preloading, forced HTTPS redirects, certificate pinning, download delays, and more.

Phase 4+ — Independence

Removal of telemetry and sync code, establishment of a Public Benefit Corporation, enterprise support.

The web deserves better.

Bloom is open source and built in the open. Follow the development, contribute code, or just spread the word.