Formal methods & mathematical proofs
We prove mathematically that your code does what it must, and nothing else. Alt-Ergo, Rocq, Why3: the reference tools of industrial formal verification, developed and maintained by our teams.
Program proofs with Rocq
Formal specification and interactive verification. We build mathematical proofs of correctness for your critical algorithms with the Rocq prover (formerly Coq).
The Alt-Ergo SMT solver
Our open-source SMT solver, the proof engine behind Frama-C, SPARK, Why3, Atelier B and EasyCrypt. In production at AdaCore, Thales, CEA List and Mitsubishi Electric.
High-assurance certification
Formal verification for Common Criteria certification processes, from restricted distribution up to EAL6+.
Alt-Ergo: the reference SMT solver
Developed since 2006, maintained by OCamlPro since 2013. The proof engine behind Frama-C, SPARK (Ada), Why3, Atelier B and EasyCrypt. Industrial club: AdaCore, Thales, CEA List, Mitsubishi Electric. DéCySif project with Inria and TrustInSoft.
Our formal verification capabilities
Deductive verification
Property specification in first-order logic, with automated proof through Why3 and Alt-Ergo.
Interactive Rocq proofs
Formal proof development in Rocq for the most demanding algorithms and protocols: correctness, termination, absence of errors.
C code analysis
Through Frama-C with Alt-Ergo as its backend: no undefined behavior, no overflows, no memory violations.
Rust program verification
With Creusot, our formal verification tool for Rust: contract annotations and automated correctness proofs.
Formal methods training
Courses in Rocq, Alt-Ergo and deductive verification. Qualiopi certified, OPCO fundable, taught by the authors of the tools.
Problems solved by formal proof
Provably bug-free critical systems
Eliminating entire classes of vulnerability by proof: memory overflows, arithmetic errors, race conditions.
EAL5 and EAL6+ certification
Formally proving the security properties required by the highest Common Criteria assurance levels.
Ada verification through SPARK
Alt-Ergo is the proof engine of SPARK, the reference formal verification tool for Ada programs.
Cryptographic protocols
Verifying cryptographic implementations through EasyCrypt with Alt-Ergo, to prove the security of your protocols.