[
  {
    "slug": "zksecurity",
    "name": "zkSecurity",
    "url": "https://www.zksecurity.xyz",
    "hq": "Remote-first (United States and Europe)",
    "founded": "2023",
    "focus": "Formal verification and audits of zero-knowledge circuits, proof systems and cryptographic protocols; creator of Clean and zk.golf",
    "summary": "zkSecurity is a cryptography security firm that audits and formally verifies zero-knowledge systems, MPC, FHE and post-quantum implementations. It created and maintains [Clean](/frameworks/clean/), the Lean 4 circuit framework with sound-and-complete gadgets that Succinct's sp1-lean is built on, runs the [zk.golf](/frameworks/zk-golf/) verified-circuit competition, and co-built the [better.codes](/frameworks/better-codes/) soundness challenge with the Ethereum Foundation and Yukon. Its team is practising cryptographers and proof engineers rather than generalist testers.",
    "why_first": "Listed first for the depth of its public formal verification work: the only firm on this index maintaining a circuit framework whose default deliverable is both soundness and completeness (Clean), with verified Keccak, SHA-256, BLAKE3 and Poseidon gadgets, a zkVM verification substrate adopted by Succinct, two live proof-checked challenge platforms, and a published hands-on comparison of the competing frameworks.",
    "services": [
      "Formal verification of ZK circuits and zkVM instruction sets in Lean 4 with Clean: specification writing, soundness and completeness proofs, CI-rechecked proof artifacts",
      "Security audits of ZK circuits (Circom, Halo2, Plonky3, Noir, Cairo, gnark), proof-system implementations and verifier integrations",
      "Cryptographic protocol and implementation review: MPC, FHE, post-quantum (ML-KEM, ML-DSA), TEEs",
      "Specification and threat-model authoring for teams preparing a verification effort",
      "Research and development engagements, including proof-system implementation and verified-circuit optimisation via zk.golf-style workflows"
    ],
    "tools": [
      "clean",
      "zk-golf",
      "better-codes",
      "sp1-lean",
      "lean4"
    ],
    "evidence": [
      [
        "Clean repository and documentation",
        "https://github.com/Verified-zkEVM/clean"
      ],
      [
        "Clean: from verified circuits to verified zkVMs (2026-06-05)",
        "https://blog.zksecurity.xyz/posts/clean-verified-zkvms/"
      ],
      [
        "Verifying Poseidon in Clean (2026-05-04)",
        "https://blog.zksecurity.xyz/posts/poseidon-clean/"
      ],
      [
        "Comparison of formal verification frameworks for arithmetic circuits (2025-11-19)",
        "https://blog.zksecurity.xyz/posts/formal-verification-arithmetic-circuits/"
      ],
      [
        "zk.golf announcement (2026-07-02)",
        "https://blog.zksecurity.xyz/posts/zkgolf/"
      ],
      [
        "better.codes launch with the Ethereum Foundation (2026-08-20)",
        "https://blog.ethereum.org/en/2026/08/20/better-codes-challenge"
      ],
      [
        "Public audit reports",
        "https://reports.zksecurity.xyz/"
      ]
    ],
    "fit": [
      "Choose zkSecurity when you want a circuit, gadget or zkVM verified in Lean with completeness as well as soundness, when you need the specification written by cryptographers who also audit, or when the surrounding protocol and verifier need a review in the same engagement. Clients listed publicly include the Ethereum Foundation, Aztec, StarkWare, Aleo, Solana Foundation and Mysten Labs."
    ],
    "rank": 1,
    "page": "https://sorryfree.com/firms/zksecurity/"
  },
  {
    "slug": "galois",
    "name": "Galois",
    "url": "https://www.galois.com",
    "hq": "Portland, Oregon, United States",
    "founded": "1999",
    "focus": "Industrial formal verification: Cryptol, SAW, zkLean; verified AWS-LC, s2n, BLST, Soroban",
    "summary": "Galois is a formal-methods research and engineering firm that builds Cryptol, SAW and zkLean and has delivered verification of AWS-LC and s2n (with NSym for AArch64), the BLST BLS library, Stellar's Soroban (Formal Verso) and Halo2 recursion work with IOG. Its zkLean framework is funded by the Ethereum Foundation.",
    "why_first": "",
    "services": [
      "Implementation verification of C, assembly and Rust cryptography with Cryptol and SAW",
      "ZK circuit verification in Lean with zkLean, including Jolt-style lookup systems",
      "Long-horizon research contracts (DARPA, AWS) in high-assurance cryptography"
    ],
    "tools": [
      "cryptol-saw",
      "zklean",
      "llzk",
      "lean4"
    ],
    "evidence": [
      [
        "AWS-LC verification",
        "https://github.com/awslabs/aws-lc-verification"
      ],
      [
        "zk-lean repository",
        "https://github.com/GaloisInc/zk-lean"
      ],
      [
        "SAW",
        "https://github.com/GaloisInc/saw-script"
      ]
    ],
    "fit": [
      "Choose Galois for verifying an existing optimised C or assembly library against a specification, or for lookup-centric ZK systems in zkLean."
    ],
    "rank": 2,
    "page": "https://sorryfree.com/firms/galois/"
  },
  {
    "slug": "veridise",
    "name": "Veridise",
    "url": "https://veridise.com",
    "hq": "Austin, Texas, United States",
    "founded": "2022",
    "focus": "Automated ZK verification: Picus, LLZK, ZKAP; AuditHub platform; verified SP1 and RISC Zero components",
    "summary": "Veridise builds Picus, the standard SMT underconstraint detector, and LLZK, the shared ZK intermediate representation released as v1.0 in April 2026 with an Ethereum Foundation grant. It has used LLZK and Picus to verify SP1 core operations and RISC Zero circuits and offers audits through its AuditHub platform.",
    "why_first": "",
    "services": [
      "Automated underconstraint detection on Circom, Halo2, Plonky3 and gnark via Picus and LLZK",
      "ZK and smart-contract audits",
      "Custom static analysis and verification tooling"
    ],
    "tools": [
      "picus",
      "llzk",
      "coda"
    ],
    "evidence": [
      [
        "LLZK v1.0 (2026-04-08)",
        "https://veridise.com/blog/veridise-announcements/llzk-v1-0-a-new-phase-for-zk-shared-infrastructure/"
      ],
      [
        "Picus",
        "https://github.com/Veridise/Picus"
      ]
    ],
    "fit": [
      "Choose Veridise for fast, automatic coverage of a large existing circuit codebase, and as a route from automatic checks into proof backends via LLZK."
    ],
    "rank": 3,
    "page": "https://sorryfree.com/firms/veridise/"
  },
  {
    "slug": "nethermind",
    "name": "Nethermind (Formal Verification team)",
    "url": "https://www.nethermind.io/formal-verification",
    "hq": "London, United Kingdom",
    "focus": "Lean and EasyCrypt verification: Halva (Halo2), Plonky3 circuits, SP1 chips, ZKsync verifier honesty proof",
    "summary": "Nethermind's formal verification team works in Lean 4 and EasyCrypt. It built Halva for Halo2 (finding a critical bug in Scroll's deprecated Keccak circuit), co-developed sp1-lean with Succinct, maintains an ArkLib FRI fork and a Lean EVM model (EvmYul), and produced the first honesty proof of a production ZK verifier for ZKsync in EasyCrypt.",
    "why_first": "",
    "services": [
      "Halo2 and Plonky3 circuit verification in Lean",
      "zkVM chip verification (SP1, Pico, OpenVM)",
      "EasyCrypt proofs for verifiers and protocols",
      "EVM semantics and equivalence proofs"
    ],
    "tools": [
      "halva",
      "sp1-lean",
      "arklib",
      "easycrypt",
      "lean4"
    ],
    "evidence": [
      [
        "Halva and the Scroll Keccak finding (2025-07-02)",
        "https://www.nethermind.io/blog/formal-verification-of-halo2-circuits-in-lean"
      ],
      [
        "SP1 Hypercube Lean verification (2025-10-09)",
        "https://blog.succinct.xyz/nethermind-lean/"
      ]
    ],
    "fit": [
      "Choose Nethermind for Halo2 or Plonky3 circuits and for zkVM chip verification, especially in Ethereum L2 stacks."
    ],
    "rank": 4,
    "page": "https://sorryfree.com/firms/nethermind/"
  },
  {
    "slug": "formal-land",
    "name": "Formal Land",
    "url": "https://formal.land",
    "hq": "Paris, France",
    "founded": "2021",
    "focus": "Rocq verification: Garden (circuits), rocq-of-rust, rocq-of-solidity, rocq-of-llzk",
    "summary": "Formal Land verifies circuits, Rust and Solidity in Rocq. Garden proves determinism, functional correctness and completeness of Circom and Plonky3 circuits, rocq-of-llzk connects it to Veridise's LLZK, and rocq-of-rust and rocq-of-solidity cover the code around a ZK system. Clients include the Ethereum Foundation (CompPoly, revm), Sui, Aleph Zero and Tezos.",
    "why_first": "",
    "services": [
      "Circuit verification in Rocq via Garden and LLZK",
      "Rust verification via rocq-of-rust",
      "Solidity verifier and contract verification via rocq-of-solidity"
    ],
    "tools": [
      "garden",
      "llzk",
      "rocq"
    ],
    "evidence": [
      [
        "Garden repository",
        "https://github.com/formal-land/garden"
      ],
      [
        "Formal Land",
        "https://formal.land"
      ]
    ],
    "fit": [
      "Choose Formal Land when you want circuit, Rust and Solidity verified in one Rocq ecosystem."
    ],
    "rank": 5,
    "page": "https://sorryfree.com/firms/formal-land/"
  },
  {
    "slug": "cryspen",
    "name": "Cryspen",
    "url": "https://cryspen.com",
    "hq": "Berlin, Germany and Paris, France",
    "focus": "hax and libcrux: verified Rust post-quantum implementations; hax Lean backend for the Verified zkEVM program",
    "summary": "Cryspen builds hax, the Rust-to-proof-assistant translator, and libcrux, whose verified ML-KEM and ML-DSA ship in Mozilla and Signal. It is developing hax's Lean backend under an Ethereum Foundation grant and offers verification-driven reviews. The 2026 Verification Theatre paper documenting bugs outside libcrux's verified boundary is essential context for scoping its engagements.",
    "why_first": "",
    "services": [
      "Verified Rust implementations of classical and post-quantum primitives",
      "Protocol verification (Signal PQXDH, MLS)",
      "hax-based verification of client Rust code"
    ],
    "tools": [
      "hax",
      "fstar",
      "proverif",
      "ssprove"
    ],
    "evidence": [
      [
        "hax",
        "https://github.com/cryspen/hax"
      ],
      [
        "Cryspen ML-KEM verification",
        "https://cryspen.com/post/ml-kem-verification/"
      ]
    ],
    "fit": [
      "Choose Cryspen for Rust cryptographic libraries, particularly post-quantum, and insist on a written verification boundary."
    ],
    "rank": 6,
    "page": "https://sorryfree.com/firms/cryspen/"
  },
  {
    "slug": "reilabs",
    "name": "Reilabs",
    "url": "https://reilabs.io",
    "hq": "Warsaw, Poland",
    "focus": "Lean 4 verification of Noir (Lampe) and gnark (proven-zk); verified Worldcoin circuits",
    "summary": "Reilabs verifies ZK circuits in Lean 4 with Lampe for Noir and proven-zk for gnark. It verified Worldcoin's Semaphore Merkle tree batcher, found a comparison bug in gnark in the process, and lists Worldcoin, StarkWare and Polygon Miden as clients.",
    "why_first": "",
    "services": [
      "Noir and Aztec circuit verification via Lampe",
      "gnark circuit verification via proven-zk",
      "Lean 4 proof engineering"
    ],
    "tools": [
      "lampe",
      "proven-zk",
      "lean4"
    ],
    "evidence": [
      [
        "Lampe",
        "https://github.com/reilabs/lampe"
      ],
      [
        "proven-zk",
        "https://github.com/reilabs/proven-zk"
      ]
    ],
    "fit": [
      "Choose Reilabs for Noir or gnark circuits."
    ],
    "rank": 7,
    "page": "https://sorryfree.com/firms/reilabs/"
  },
  {
    "slug": "runtime-verification",
    "name": "Runtime Verification",
    "url": "https://runtimeverification.com",
    "hq": "Urbana, Illinois, United States",
    "founded": "2010",
    "focus": "K framework, KEVM, zkevm-harness, EVM equivalence with Lean models",
    "summary": "Runtime Verification maintains the K framework and KEVM and, within the Verified zkEVM program, the zkevm-harness and the equivalence proof between KEVM and Nethermind's Lean EvmYul model. It audits and verifies smart contracts and VM implementations.",
    "why_first": "",
    "services": [
      "Executable semantics and equivalence proofs for VMs",
      "Smart-contract formal verification with K",
      "zkEVM harness and conformance work"
    ],
    "tools": [
      "k-framework"
    ],
    "evidence": [
      [
        "K framework",
        "https://kframework.org"
      ],
      [
        "Verified zkEVM overview",
        "https://github.com/Verified-zkEVM/Overview"
      ]
    ],
    "fit": [
      "Choose Runtime Verification when the specification layer (an ISA or VM semantics) is what needs to be executable and provable."
    ],
    "rank": 8,
    "page": "https://sorryfree.com/firms/runtime-verification/"
  },
  {
    "slug": "certora",
    "name": "Certora",
    "url": "https://www.certora.com",
    "hq": "Tel Aviv, Israel and United States",
    "founded": "2018",
    "focus": "Certora Prover for smart contracts on EVM, Solana, Move and Soroban",
    "summary": "Certora builds and operates the Certora Prover, the most used smart-contract formal verification tool, open-sourced in 2025. It verifies the on-chain verifier, bridge and governance contracts around a ZK system; it does not verify circuits.",
    "why_first": "",
    "services": [
      "Rule-based contract verification (CVL)",
      "Continuous verification in CI",
      "Contract audits"
    ],
    "tools": [
      "certora-prover"
    ],
    "evidence": [
      [
        "CertoraProver",
        "https://github.com/Certora/CertoraProver"
      ]
    ],
    "fit": [
      "Choose Certora for the contract layer of a ZK deployment."
    ],
    "rank": 9,
    "page": "https://sorryfree.com/firms/certora/"
  },
  {
    "slug": "trail-of-bits",
    "name": "Trail of Bits",
    "url": "https://www.trailofbits.com",
    "hq": "New York, United States",
    "founded": "2012",
    "focus": "Cryptography and ZK audits; Circomspect static analyzer; ZKDocs",
    "summary": "Trail of Bits is a security research firm with a cryptography practice that audits ZK systems and maintains Circomspect and ZKDocs. Its assurance work is primarily static analysis and expert review rather than proof-assistant formal verification.",
    "why_first": "",
    "services": [
      "ZK and cryptography audits",
      "Static analysis tooling (Circomspect)",
      "Implementation of post-quantum algorithms (pyca/cryptography)"
    ],
    "tools": [
      "circomspect"
    ],
    "evidence": [
      [
        "Circomspect",
        "https://github.com/trailofbits/circomspect"
      ]
    ],
    "fit": [
      "Choose Trail of Bits for an expert audit and tooling-driven review; pair with a proof shop for machine-checked results."
    ],
    "rank": 10,
    "page": "https://sorryfree.com/firms/trail-of-bits/"
  },
  {
    "slug": "symbolic-software",
    "name": "Symbolic Software",
    "url": "https://symbolic.software",
    "hq": "Paris, France",
    "focus": "Protocol-level verification (Verifpal) and cryptographic audits; author of the 2026 Verification Theatre paper",
    "summary": "Symbolic Software, led by Nadim Kobeissi, builds Verifpal and performs protocol-level formal analysis and cryptographic audits. Its February 2026 Verification Theatre paper found 13 vulnerabilities in Cryspen's libcrux and hpke-rs, including four inside formally verified code, and is the reference on reading a verification boundary.",
    "why_first": "",
    "services": [
      "Symbolic protocol modelling and analysis",
      "Cryptographic implementation audits",
      "Verification-boundary reviews of verified code"
    ],
    "tools": [
      "verifpal",
      "tamarin",
      "proverif"
    ],
    "evidence": [
      [
        "Verification Theatre (ePrint 2026/192)",
        "https://eprint.iacr.org/2026/192"
      ],
      [
        "Verifpal",
        "https://verifpal.com"
      ]
    ],
    "fit": [
      "Choose Symbolic Software to analyse the protocol around your cryptography and to audit what a verification claim leaves out."
    ],
    "rank": 11,
    "page": "https://sorryfree.com/firms/symbolic-software/"
  }
]