K-Dense has released a beta, open-source AI research assistant designed to keep scientific work on a researcher's own computer while preserving a detailed record of how results were produced. A new arXiv preprint from four K-Dense employees describes K-Dense BYOK, short for bring your own keys, as a local workspace that can use either hosted AI models or models running on the same machine.

The system separates the model from the surrounding research software. Researchers choose model access for each chat, while the application provides tools for reading files, running code and organizing projects. The paper says each project is stored as an ordinary folder containing data, scripts, outputs, conversation history, cost records and provenance entries. That structure is meant to let users inspect, move or archive their work without depending on a vendor-controlled database.

K-Dense BYOK adds scientific scaffolding to the functions of a general coding agent. Version 0.9.14 includes a library of written scientific procedures, guided workflow templates, catalogs of research-data sources and specialist agents for tasks such as statistical review, methodology checks, citation review and scientific writing. The paper reports 163 scientific skills, 326 workflow templates, 229 data-resource entries and 21 specialists in the version it documents.

AI-generated editorial illustration of research files and scripts kept in a local project
AI-generated illustration: Research files and scripts kept in a local project.

Its central design choice is a provenance log that the AI agent cannot write or edit directly. The application observes tool use, records the model and action involved, and fingerprints files with SHA-256 hashes. Each entry is appended rather than overwritten. When the software cannot determine which operation changed a file, it labels the relationship as uncertain instead of presenting an inferred link as confirmed.

A separate Living Lab Notebook records the agent's account of its reasoning. Entries can represent hypotheses, methods, observations, decisions or notes and may link to files. Corrections create new entries while preserving the originals. Because notebook citations point to files tracked by the provenance layer, the workspace can flag when a cited file has changed and the earlier conclusion may now refer to a stale version.

The paper presents this structure as a response to AI overclaiming and poor reproducibility. The authors distinguish between what an agent says it did and the externally observed record of its actions. They also acknowledge a gap: the current provenance recorder does not capture the software environment itself, even though environment details are important for reproducing computational work.

AI-generated editorial illustration of a linked record of research steps and outputs
AI-generated illustration: A linked record of research steps and outputs.

In an internal evaluation, the authors compared K-Dense BYOK with Claude Science and Biomni Lab on 20 interdisciplinary research prompts. All three platforms completed all prompts. The authors report that K-Dense BYOK led on their scientific-quality and research-execution scores, and that its exported deliverables more often included environment records and commands for regenerating results. The comparison used Claude Opus 4.8 in both K-Dense BYOK and Claude Science, while Biomni Lab did not disclose its model.

Those results require substantial caution. The K-Dense team designed, ran and scored the benchmark themselves. A single AI judge, Grok 4.5, scored each bundle once and was not blinded to platform identity. The managed platforms can change continuously, their tested versions were not fully recorded, and only 20 prompts were used. The authors explicitly call the evaluation an internal study and identify their employment by K-Dense as a direct conflict of interest.

Local execution also does not eliminate security risks. The paper says the agent runs commands with the same operating-system permissions as the researcher, which could expose saved credentials or other files. A malicious document could attempt an indirect prompt-injection attack. The authors recommend isolating untrusted work in a container, virtual machine or separate user account and note that third-party skills are instructions that extend trust to their authors.

The software remains unfinished. The paper says built-in literature and regulatory-document search, automated browsing, automatic citation checking and some record-based export features were not available after a core rebuild. Small local models may also struggle with sustained tool use. The code is available under the MIT license, but the manuscript is a preprint and the platform's reported advantages have not been independently replicated.