Skip to content

Formal methods tools

What tools exist, what problem each one checks, and how much traction each has: how many job postings name it, its Google search trend and its GitHub stars.

Each group below is “what problem you’re checking” → the tools that do it.

Design-level models (find bugs in the protocol before code exists) TLA+, Alloy, PlusCal, Quint, P, SPIN/Promela. You write an abstract model, the checker explores states. Best fit for distributed systems, consensus, cache coherence, API state machines.

Proof assistants (prove theorems and programs by hand, with tactics) Lean, Coq/Rocq, Isabelle/HOL, Agda, Idris. Deep guarantees, high effort. Used for compilers, crypto proofs, math, language semantics.

Contract-based verification of real code (annotate functions, a solver proves them) SPARK (Ada), Frama-C (C), Dafny, Why3, Verus and Creusot (Rust), JML/OpenJML (Java). You write pre/postconditions and invariants alongside normal code. This is the closest thing to “verified engineering” as a day job.

Model checkers for actual source code CBMC (C/C++), Java Pathfinder, Kani (Rust). Bounded checking of real programs rather than an abstract model.

Static analysis / abstract interpretation (prove absence of crash classes, no annotations) Astrée, Polyspace, Infer, CodeQL, Coverity. Lower ceiling, much lower cost, so this is what large companies actually deploy.

SMT and SAT solvers (the engines under most of the above) Z3, CVC5, Yices, MiniSat. Also used directly for scheduling, config validation, program synthesis.

Cryptographic protocol verification Tamarin, ProVerif, EasyCrypt, CryptoVerif. TLS 1.3 and Signal were analyzed with these.

Hardware verification SystemVerilog Assertions, JasperGold, SymbiYosys, ACL2. Oldest and most commercially mature branch of the whole field.

Type systems as lightweight verification Liquid Haskell, refinement types, Rust’s borrow checker, dependent types in Idris. Weaker guarantees, but they ride along with normal development.

Runtime verification and property testing Jepsen, TLA+ trace checking, QuickCheck/Hypothesis, Antithesis, deterministic simulation testing. Doesn’t prove anything, catches a lot. Highest practical payoff per hour.

The field looks huge because it grew from three separate communities — math, hardware, and safety-critical software — that never merged. Lots of overlapping tools, small user bases each.

Demand is counted by how many postings on Job postings name each tool directly. It skews hard toward proof assistants, not model checkers — Lean and Coq/Rocq beat TLA+ by a wide margin, even though neither is a model checker.

The Trend column is Google Trends search interest over the last 12 months (worldwide), included only where the term maps to a single, unambiguous Trends topic — most tool names here are too generic or collide with unrelated words (“Coq” is French for rooster, “Agda” without disambiguation returns a food brand) to trust a plain keyword search, so most rows don’t get one rather than showing misleading data. GitHub ★ is each project’s current star count, checked directly via the GitHub API; closed-source or non-GitHub-hosted tools (Antithesis, Certora, UPPAAL, CryptoVerif, MathSAT) don’t get one.

ToolJob mentionsWhat it isTrend (12mo)GitHub ★
Lean / Lean 49Interactive theorem prover — the single most-named tool found, concentrated at AI labs (Harmonic, DeepMind, Oath Technologies).Lean search trend9,234
Coq / Rocq8Interactive theorem prover, same AI-lab cluster as Lean.Rocq search trend5,581
SMT solvers (Z3, CVC5, MathSAT)8Underlying decision engine for most higher-level tools; rarely hired for by name alone.Z3 search trendZ3: 12,702 · CVC5: 1,361
TLA+ / TLC / Apalache6Exhaustive model checker — Huawei, Oracle, Architect Labs, Sigil Logic, Johns Hopkins APL, Google Cloud.TLA+ search trendTLA+: 3,058 · Apalache: 599
Isabelle/HOL4Interactive theorem prover; used for the seL4 verified microkernel.Isabelle search trend—
Agda2Interactive theorem prover, both mentions at Harmonic.Agda search trend2,928
Verus1Verification-aware Rust, used for Google Cloud’s C++→Rust migration.—3,192
Alloy1Spec language + model finder (Kodkod engine); 1 posting (Sigil Logic).Alloy search trend868
SPIN1Model checker for protocols, its own language (Promela); 1 posting (Johns Hopkins APL).SPIN search trend476
Quint0Modern executable-spec successor to TLA+, built by Informal Systems.—1,685
P (AWS)0State-machine modeling language, used internally across S3/DynamoDB/EC2.—3,687
Antithesis0Closed deterministic-simulation SaaS — can’t have a job posting since it’s proprietary tooling companies buy, not a skill anyone lists.——
QuickCheck/Hypothesis0Property-based testing (Haskell/Python); widely adopted, never hired for by name.—Hypothesis: 8,997 · QuickCheck: 790
Coyote0Microsoft’s systematic concurrency tester for C#, internal Azure tool.—1,598
FizzBee0Open-source, more approachable alternative to TLA+.—350
Stateright0Embedded model checker as a Rust library.—1,882
stateproof0TypeScript DSL compiling to TLA+; the closest TS-to-TLA+ tool found.—2
loom0Rust concurrency-permutation tester, under the Tokio project.—2,823
XState graph0Exhaustive state-graph traversal for XState machines, from Stately.ai.—30,138
fast-check0TypeScript/JS property-based testing, 139M downloads/month.—5,149
Certora Prover/CVL0SMT-based prover for smart contracts (Solidity/Solana/Move).——
K Framework/KEVM0Semantics framework; KEVM targets EVM bytecode.—591
Cryptol/SAW0Haskell-hosted crypto spec DSL + Software Analysis Workbench (Galois).Cryptol search trendCryptol: 1,221 · SAW: 518
Dafny0Verification-aware language, compiles to C#/Java/JS/Go/Python.Dafny search trend3,548
UPPAAL0Timed-automata model checker (academic, Uppsala/Aalborg).——
EasyCrypt1Cryptography-specific interactive theorem prover; 1 posting (Riverside Research).—416
F*1Dependently-typed proof assistant, used in Project Everest (verified TLS); 1 posting (Riverside Research).—3,109
CryptoVerif1Automated cryptographic protocol verifier, game-hopping proofs; 1 posting (Riverside Research).——

Last updated: