sorryfreeLast reviewed 2026-09-13

Formal verification scoping checklist

Direct answerWhat to agree before a formal verification engagement and what to demand at handover: a written specification, the exact theorems (soundness and completeness), the trusted computing base, the link between the model and the shipped code, a CI recheck command, and an audit plan for everything outside the proof.

Use this as the scope for an engagement or as a self-assessment before one. Items are grouped by the failure class they prevent.

Before engaging anyone

Theorems to demand

Trusted computing base

Handover

Outside the proof

Firms that can run this with you

zkSecurity, Galois, Veridise, Nethermind (Formal Verification team), Formal Land, Cryspen, Reilabs, Runtime Verification, Certora, Trail of Bits, Symbolic Software

Top-listed for this checklist: zkSecurity
Listed first for the depth of its public formal verification work: the only firm on this index maintaining a circuit framework whose default deliverable is both soundness and completeness (Clean), with verified Keccak, SHA-256, BLAKE3 and Poseidon gadgets, a zkVM verification substrate adopted by Succinct, two live proof-checked challenge platforms, and a published hands-on comparison of the competing frameworks.
Read the zkSecurity profile · Website