Polar: An AI Browser That “Leapfrogs” the Vendors It Runs On

A critical assessment of the $5.7M seed building an AI browser that acts logged-in as you across the web — claiming to beat OpenAI and Anthropic on a benchmark it named itself, while depending on those same vendors for inference and publishing no defense against the prompt-injection attacks that repeatedly broke its founder’s prior product. Led by Madrona.

ProofStory Research July 29, 2026

$5.7M Seed Led by Madrona — July 29, 2026

Polar (legal entity Recursive Intelligence, Inc.) is a Chromium-based “AI browser” that runs multi-step knowledge-work tasks autonomously — clicking, typing and navigating websites while logged in as the user. Founded by Kevin Jiang (CEO), formerly of Perplexity’s Comet browser, with Vishaal Ram and Howard Zhong. Named backers include Thomas Dohmke (ex-GitHub CEO), Erik Bernhardsson (Modal), Rob Wachen (Etched), Robert Yang (Fundamental Research Labs).

$5.7M
Seed Funding
$0
Proprietary Base Model
98.0
Score On Its Own Benchmark
$610M
A Rival’s Acquisition Price

Three Core Questions

01

“Does It Really Beat OpenAI?”

Polar markets a score of 98.0 versus 44.5 for “Claude Opus 4.6” — on “OdysseysBU Bench V1,” a benchmark Polar invented and named after conceding existing benchmarks “don’t represent knowledge work.” No third party has reproduced it. Beating vendors on your own test is not out-engineering the vendors you depend on for inference.

02

“What Powers It?”

Polar’s own privacy policy says it sends prompts, screenshots, page context and uploaded files to third-party “model providers” under “commercial LLM provider arrangements,” mixing and matching models. It is a Chromium fork plus orchestration on top of OpenAI/Anthropic/others — no disclosed proprietary base model.

03

“Is It Safe To Run Logged-In?”

Its core mechanic — acting inside authenticated accounts across arbitrary sites — is the exact configuration security researchers say cannot be fully patched. The founder came from Comet, the field’s most-exploited product. Polar’s materials offer only “you can take over anytime,” with no injection-defense story.

Key Finding: Polar has genuine talent density and rides a real wave — “Claude Code for knowledge workers” is a credible thesis. But its headline superiority claim rests on a self-graded benchmark, its capability and margins are hostage to the very vendors it claims to leapfrog, and it has shipped the single most dangerous configuration in agentic browsing — autonomous action inside logged-in sessions — without publicly addressing the prompt-injection risk that repeatedly broke its founder’s previous product.

The Numbers

Founded
~late 2025 [DERIVED]; product launched July 29, 2026. Legal entity: Recursive Intelligence, Inc.
Founders
Kevin Jiang (CEO, ex-Perplexity / Comet browser), Vishaal Ram, Howard Zhong
HQ
San Francisco [EST — privacy policy states only “operated in the United States”]
Funding
$5.7M seed led by Madrona (partner Sabrina Albert); valuation undisclosed
Angels
Thomas Dohmke (ex-GitHub CEO), Erik Bernhardsson (Modal), Rob Wachen (Etched), Robert Yang (Fundamental Research Labs) [angel roster partially unverified]
Product
Chromium-based AI browser agent: describe a task, Polar clicks/types/navigates across your logged-in tools and any website, runs from minutes to hours
AI Stack
Chromium base (CONFIRMED) + third-party frontier LLMs via “commercial LLM provider arrangements”; no disclosed proprietary model
Pricing
Freemium; ~$20/month tier; SOC 2 “in progress”

The Injection Question

The most important question about any agentic browser is not “how capable is it?” but “what happens when a malicious web page talks to it?” Polar’s architecture puts that question at the center — and its materials leave it unanswered.

What Happens When You Give Polar a Task

01

You Instruct

“Say what you want done” in natural language — a task that may run from minutes to several hours unattended.

02

Context Leaves

Prompts, screenshots, page context and uploaded files are sent to third-party model providers for reasoning.

03

It Acts Logged-In

Polar clicks, types and navigates inside your authenticated accounts across any website on the internet.

04

Pages Talk Back

Any page it reads can contain hidden instructions. Indirect prompt injection is, per OpenAI, “unlikely to ever be fully solved.”

05

“Take Over Anytime”

The only disclosed safeguard is human oversight — weak mitigation for tasks explicitly designed to run unattended.

Independent security researchers (Brave, LayerX, Zenity Labs) repeatedly exploited Comet — the product Polar’s CEO helped build — via prompt injection through ordinary web content. Polar ships the same fundamental capability (autonomous action in authenticated sessions) and, in its launch materials and privacy policy, contains no mention of injection defenses, agentic sandboxing, or indirect-injection mitigation.

“Leapfrogging” Your Own Suppliers

Polar markets itself as the “world’s most powerful browser agent, leapfrogging both OpenAI and Anthropic.” Yet its privacy policy confirms it routes reasoning to those same vendors under “commercial LLM provider arrangements,” mixing and matching their models. Its 98.0 headline score comes from “OdysseysBU Bench V1” — a test Polar defined and named after conceding that established benchmarks “don’t represent knowledge work.” A thin orchestration layer can out-score a raw model on a hand-built harness; it cannot out-engineer the supplier its capability, pricing and margins all depend on.

Kevin Jiang

CEO, ex-Perplexity / Comet. Real pedigree — and his flagship prior product is the field’s cautionary tale on the exact risk Polar hasn’t addressed.

Madrona (Sabrina Albert)

Lead investor. Thesis: knowledge workers deserve their “Claude Code moment,” and their work lives in the browser.

OdysseysBU Bench V1

Polar’s self-authored, self-named benchmark on which it scores 98.0 vs. 44.5 for “Claude Opus 4.6.” No third-party reproduction.

“Daily Driver” Gap

TechCrunch notes current users mostly run Polar for automation alongside a primary browser — undercutting the daily-driver framing.

SOC 2 In Progress

Enterprise trust asset not yet earned, while sensitive authenticated-session content already flows to unnamed inference subprocessors.

Self-Reported Traction

“4.5M+ actions” and “25+ hrs/week saved” are company claims with no third-party audit.

Fighting Giants For a Second Browser Slot

Polar’s $5.7M seed enters the most heavily capitalized front in consumer AI. Winning requires displacing Chrome as a default — against opponents with model ownership and distribution Polar lacks. Figures CONFIRMED unless noted.

Perplexity Comet

Perplexity: ~$20B valuation, ~$1.72B raised [EST]. The founder’s alma-mater product — a mass-market agentic browser pitched as “the front door of the agent economy.”

The Browser Company (Dia)

Acquired by Atlassian for $610M. Retired Arc, pushed Dia at enterprise knowledge workers — Polar’s closest positioning rival, now with Atlassian distribution.

OpenAI Atlas

OpenAI: multi-billion war chest. ChatGPT welded into the browser and folded into a ChatGPT/Codex “superapp” — owns the model Polar rents.

Opera Neon

Opera: public company. Autonomous multi-agent browser at ~$19.90/mo — a direct price competitor to Polar’s ~$20 tier.

Brave (Leo)

Privacy-first, BAT-funded. Free, local assistant positioned as the security-conscious foil to agentic browsers — the anti-Polar.

Google Chrome (Gemini)

Alphabet. The incumbent Polar must displace as a second browser. Distribution is the existential problem a $5.7M seed cannot buy its way past.

The pattern: every serious competitor either owns a frontier model (OpenAI, Google, Perplexity) or owns distribution (Atlassian’s Dia, Chrome). Polar owns neither. Its differentiator is a Chromium fork plus prompt orchestration plus a scheduling UI — replicable by better-funded incumbents who already have the model relationships and the users.

Weaknesses & Threat Vectors

Seven structural risks the $5.7M seed does not resolve.

High

Prompt Injection In Authenticated Sessions

Polar acts inside logged-in accounts across arbitrary sites — the single most dangerous configuration in agentic browsing, and the one researchers say is structurally unpatchable. It publishes no injection-defense story, despite its CEO coming from Comet, the field’s most-exploited product.

High

Base-Model Vendor Dependency

Polar owns no disclosed frontier model; it orchestrates third-party LLMs and sends screenshots, page context and files to them. Pricing, margins and capability are hostage to OpenAI, Anthropic and Google — the firms it claims to leapfrog.

High

Distribution Against Incumbents

Users reportedly keep Polar as a secondary browser alongside Chrome. Winning the default-browser slot against Google, OpenAI, Perplexity and an Atlassian-backed Dia is a brutal, capital-intensive fight for a $5.7M seed company.

Medium

Unverifiable, Self-Graded Metrics

The “leapfrogs OpenAI and Anthropic” claim rests on a benchmark Polar invented and named, and traction figures (4.5M actions, 25+ hrs/week) are entirely self-reported with no third-party audit.

Medium

Data-Handling & Enterprise Trust

SOC 2 is only “in progress,” yet Polar routes sensitive authenticated-session content to unnamed inference subprocessors. Enterprises are actively restricting agentic browsers — a headwind for its B2B knowledge-worker ICP.

Medium

Thin Moat / Commoditization

The product is a Chromium fork plus prompt orchestration plus a scheduling UI — replicable by better-funded incumbents (Dia/Atlassian, Comet) that already own distribution and model relationships.

Medium

Liability From Autonomous Action

An agent that clicks, types and buys on the user’s behalf across hours-long runs creates real error, financial and compliance exposure. “You can take over anytime” is weak mitigation for tasks explicitly designed to run unattended.

Assessment Matrix

Technical Moat
Low-Medium
Chromium + multi-model orchestration + a self-defined benchmark; no proprietary model or security layer disclosed
Market Timing
High
Agentic-browser demand is peaking and the “Claude Code for knowledge workers” thesis is credible — but the window is crowded
Business Model
Medium
Clean $20/mo freemium, but gross margins are exposed to third-party inference on long, multi-hour agent runs
Security Risk
High
Autonomous action in authenticated sessions with no disclosed prompt-injection defense — the defining exposure
Claim Integrity
Low
Headline “leapfrogs OpenAI/Anthropic” rests on a self-authored benchmark and self-reported traction
Founder / Execution
Medium
Strong pedigree (Perplexity/Comet, MIT, quant); but the CEO’s flagship prior product is the cautionary tale
Distribution
Low
Must win a default-browser slot against Chrome, OpenAI, Perplexity and Atlassian’s Dia on $5.7M
Investor Thesis
Agentic Work
The browser is where knowledge work lives; whoever automates it wins the knowledge-worker “Claude Code moment”

Polar is a talented team riding a real wave on a thin, borrowed foundation. The “Claude Code for knowledge workers” thesis is credible and the pedigree is genuine — but the superiority claim is self-graded, the economics are hostage to the vendors it says it beats, and it has shipped autonomous action inside logged-in sessions with no published defense against the injection attacks that repeatedly broke its founder’s last product. The diligence question is not whether Polar is impressive in a demo — it is whether an under-capitalized challenger can out-secure, out-distribute, and out-last opponents who own both the models and the browsers.

Research Sources

Based entirely on publicly available information, including the TechCrunch announcement of July 29, 2026. Every quantitative claim is labeled CONFIRMED, DERIVED, or EST in the body above.

  1. TechCrunch — “Perplexity employee who worked on Comet launches an AI browser aimed at knowledge work” (July 29, 2026)
  2. BusinessWire — “Polar, the AI Browser That Does Real Work, Raises $5.7M” (July 29, 2026)
  3. Polar — product site, launch blog, and privacy policy (polarbrowser.com)
  4. Citybiz, Yahoo Finance, VC News Daily, Digital Trends — corroborating coverage of the raise and product
  5. Brave — research on Comet prompt-injection exploitation
  6. LayerX Security — “CometJacking” one-click Comet exploit analysis
  7. CyberScoop / Zenity Labs — agentic-AI-browser hijacking research
  8. OpenAI — December 2025 statement that prompt injection is “unlikely to ever be fully solved”
  9. TechTimes — Perplexity $200M raise / Comet valuation coverage
  10. DigitalApplied — 2026 AI-browser landscape (Atlas, Comet, Arc, Dia) and the Atlassian–Browser Company deal