Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

103 Commits

Repository files navigation

A List of companies that use formal verification methods in software engineering

If you see a company on the list that doesn't exist anymore, or does not use formal methods anymore, please send a pull request with an explanation. The same goes if you're currently working at, or know a company that uses formal methods but is not on the list. Please include the website, github (if applicable), locations, and sector. If the company is hiring please include a link to the ad.

NameLocationSectorSource
AmazonUSAeCommerce, Cloud computingTLA+How Amazon Web Services Uses Formal Methods, Use of Formal Methods at Amazon Web Services, CBMCModel Checking Boot Code from AWS Data Centers, DafnyAWS Encryption SDK
AirbusFranceAstrée: "In 2003, Astrée proved the absence of any runtime errors in the primary flight-control software of an Airbus model. The system’s 132,000 lines of C code were analyzed completely automatically in only 80 minutes on a 2.8GHz 32-bit PC using 300MB of memory (and in only 50 minutes on an AMD Athlon 64 using 580MB of memory). Since then, Airbus France has been using Astrée in the development of safety-critical software for vari­ous plane series, including the A380.", Coq (Interview with Xavier Leroy), CAVEAT, a C-verifier developed by CEA and used by Airbus., Frama-C (Industrial use of a safe and efficient formal method based software engineering process in avionics).
AppleSanta Clara Valley, California, USAHardware and Software
ArmAustin, Texas, & San Jose, California, USAHardwareACL2Verification of Arithmetic Hardware, Verifying against the official ARM specification, TLA+Linux Kernel
AdaCoreUSA, New York??
Alacris?Blockchain
BAE SystemsCoqReddit
BedRock SystemsBoston & Bay Area, USA; Berlin & Munich, GermanySystems Security, Trustworthy ComputeCoq, C++, github
The Boeing CompanyUSAAerospace, DefenseCoq (no proof), Ivory (source)
BoschGermanyAutomotiveAstrée
Capgemini Engineering (previously Altran)France, ParisConsultingAlloyWhat happens when you rethink software assurance from the ground up?
Centaur TechnologyUSAHardwareACL2
Cog SystemsAustralia, New South Wales, SydneySite
Data61Australia Isabelle/HOL (The seL4 verification project)
DatadogUSACloud Computing, SoftwareTLA+How we use formal modeling, lightweight simulations, and chaos testing
DraperUSADefense, SpaceCoq, Z3
EthereumSwitzerlandWhy3Dev Update: Formal Methods, Isabelle/HOLA Lem formalization of EVM and some Isabelle/HOL proofs, CoqFormal Verification of Ethereum Contracts
EdgeSecuritySoftwareTamarinWireGuard
eSpark LearningUSA, IL, ChicagoEducationTLA+Formal Methods in Practice: Using TLA+ at eSpark Learning
ElasticGlobalSearch & analytics softwareTLA+Isabelle/HOLelasticsearch-formal-models repositoryconference talk and current open positions
European Space AgencyTLA+ (Formal Development of a Network-Centric RTOS: The European Space Agency's Rosetta spacecraft, which flew to a comet, used a real-time operating system called Virtuoso to control some of its instruments. The next version of that operating system, called OpenComRTOS, was developed using TLA+)
FacebookUSAINFERMoving Fast with Software VerificationZoncolanHow Facebook uses static analysis to detect and prevent security issues
Fondazione Bruno Kessler (FBK)ItalySpace, Avionics, Automotive, Railways, Energy, Semiconductors, ManufacturingNuSMVsymbolic model checker, nuXmvsymbolic model checker for finite- and infinite-state synchronous transition systems, OCRAverification of logic-based contracts refinement, xSAPsafety assessment of synchronous finite-state and infinite-state systems., MathSAT 5SMT solver, NuRV tool for Runtime Verification
FireEyeDresden, Germany (team defunct)SecurityCoqJob announcement: formal methods engineer and scientific developer at FireEye
FinProofRussia, SPbFinance (Blockchain)Coq, Agda
Formal LandGlobalSoftwareCoqVerification of Rust, Verification of Solidity, Verification of zero-knowledge systems, Verification of the Tezos blockchain
Formal VindicationsBarcelona, SpainLawCoqFormalized datetime software
GaloisPortland, Oregon, USAConsulting/ResearchCoq (?)
genua GmbHGermanyCPAcheckerAnother Path for Software Quality? Automated Software Verification and OpenBSD and Application of Software Verificationto OpenBSD Network Modules
GoogleCA, USACloud computing, Computer software, AICoq (Simple High-Level Code For Cryptographic Arithmetic – With Proofs, Without Compromises (Chromium)), Formal Modeling and Analysis of Google’s Megastore in Real-Time Maude
GrammatechFrama-CC Library annotations in ACSL for Frama-C: experience report
Green Hills SoftwareUSAAerospaceACL2Industrial Use of ACL2
Kestrel InstituteUSAComputer Science ResearchMostly ACL2, some Isabelle/HOL, a little of PVS and Coq. See the web site, particularly project pages and people pages, for details and publications.
IBMUSA?SPIN/PromelaPaul E. McKenney's Journal, What is RCU, Fundamentally? (Linux Kernel, RCU), CoqQ*Cert
IGE+XAOEuropeComputer Aided DesignCoqExperience Report: Smuggling a Little Bit of Coq Inside a CAD Development Context Coq is used to verify the following: (i) domain-specific algorithms (application of "patches" to electrical design documents) (ii) graph algorithms (A* search, length-preserving tree layout, B&B TSP, ...) (iii) data structures (union-find, priority queues, ...) (iv) programming language related questions (custom language type inference) (v) small research projects
InferaraJapan, GlobalSoftware / Consulting / BlockchainInferenceInference is a Programming Language that defines a high-assurance, deterministic computing model with non-deterministic extensions for developing verifiable programs. It enables developers to write both executable code and formal specifications in a unified language, using a familiar syntax similar to imperative programming languages.Inference allows formal proof of the correctness of the specified properties to be expressed as a theorem-prover theory and verified in an automated way. The compiler (infc) targets multiple backends: generating executable binaries (currently WASM via LLVM IR) for deployment and proof units (Rocq) for formal verification. The Language Start Guide and the Language Specification provides more information.
IntelUSAHardwareProver (Fifteen Years of Formal Property Verification in Intel), HOL Light (Formal verification of IA-64 division algorithms), TLA+ (Pre-RTL formal Verification: An Intel Experience)
Informal SystemsToronto, Vienna, Lausanne, BerlinBlockchain, Distributed SystemsQuintQuint specification language, TLA+Apalache, Symbolic Model Checker for TLA+, RustMalachite (BFT consensus engine), CometBFT Consensus and Hermes (Inter-Blockchain Communication protocol) in Rust with Quint and TLA+ specs, Model Based Testing with TLA+ and Apalache
InfoTecsRussia, MoscowTLA+, Coq, Construction and formal verification of a fault-tolerant distributed mutual exclusion algorithm, Построение и верификация отказоустойчивого алгоритма распределенной блокировки
ISP RASMoscow, RussiaOperating systems; hardwareFrama-C, Jessie, Why3Astraver, Linux kernel library functions formally verified; SPIN/Promela, MicroteskSite; Event-BМоделирование и верификация политик безопасности управления доступом в операционных системах, part of the Event-B specification; Isabelle/HOLFormal specification of the Cap9 kernel
Kernkonzept GmbHGermanyOperating systemsL4Re (source)
KasperskyMoscow, RussiaSecurity/AVAlloy, TLA, Event-B (source), Ivory (source)
Machine Zone Inc.RussiaMobile gaming software, Real-time computing, Cloud-based networkingTLA+Twitter
MicrosoftRedmond, USASoftware developmentTLA+TLA+ Proofs, Thinking for Programmers, High-level TLA+ specifications for the five consistency levels offered by Azure Cosmos DB, Microsoft’s Static Driver VerifierThorough static analysis of device driversClousotStatic contrace checking with Abstract Interpretation, Formal Methods and Tools for Distributed Systems, Formal Methods at Scale in Microsoft
MongoDBNew York, USASoftware developmentTLA+TLA+ Spec of a simplified part of MongoDB replication system
NASAUSASpacePVSNASA Langley Formal Methods Research Program. JPFJava Pathfinder, Robust Software Engineering Group, Model CheckingJet Propulsion Laboratory, SPIN/PromelaInspiring Applications of Spin, PVS (source)
Nomadic LabsParis, FranceblockchainCoqpage on software verification
OCamlProParis, FranceSoftwareE-ACSLSymbolic execution in Owi. SPARK, Creusot, Why3DéCySif
OracleRedwood Shores, CA, USAEnterprise software, Cloud computing, Computer hardwareACL2 (Proving Theorems about Java and the JVM with ACL2)
Particular SoftwareTLA+TLA+ Specifications for NServiceBus
PingCAPTLA+TLA+ in TiDB
Prover TechnologyEuropeRailwayModel checking
Rusbitech (РусБиТех)Russia, MoscowСистемное ПОFrama-C, Event-B (Моделирование и верификация политик безопасности управления доступом в операционных системах)
Rockwell CollinsUSA, Cedar Rapids, IowaHigh Assurance SystemsFormal Methods in the Aerospace Industry: Follow the Money
SerokellTallinn, EstoniaFintech, blockchain, IoT, machine learning, formal verificationAgda
Synopsis??Site
SysterelFranceSoftware, Consulting, ServiceS3 a model checker for a synchrone language, B method, Event-b/Rodin. Recruiting.
SiFiveUSA, San Francisco Bay AreaHardwareCoqLinkedIn
StateboxAmsterdam, NetherlandsBlockchainIdris (github)
SukhoiRussia, MoscowAerospace and defenseANSYS SCADE Suite (source - A Formally Verified Compiler for Lustre)
ThalesFrama-C (A Bottom-Up Formal Verification Approach for Common Criteria Certification: Application to JavaCard Virtual Machine)
TrustInSoftUSA, CA, San Francisco-TrustInSoft AnalyzerSite
Trustworthy SystemsAustralia, SydneyIsabelle/HOL, CoqSite
Two Six TechnologiesUSADefense researchIsabelle/HOL, Hardware verification (example), Coq (example)
JetBrains ResearchSaint Petersburg, Russia-Coq (source)
МЦСТMoscow, Russia?SPIN/PromelaМетоды и средства верификации протоколов когерентности памяти
T-PlatformsMoscow, Russia-Coq, SPIN/Promela, TLA+, McErlang, mCRL2Employee CV
CERNGenève, SwitzerlandmCRL2Control Software of the CMS Experiment at CERN’s Large Hadron Collider
YandexSoftwareTLA+ClickHouse Replication Algorithm, lock-free Memory Allocator
ZilliqaSingaporeBlockchainCoqscilla-coq project
WavesBlockchain???

See also

About

A gently curated list of companies using verification formal methods in industry

Topics

Resources

Stars

610 stars

Watchers

59 watching

Forks

Contributors