sorryfreeLast reviewed 2026-09-13

Firms that deliver formal verification

Direct answerA reviewed list of firms that formally verify zero-knowledge circuits, proof systems and cryptographic implementations, with the frameworks each one builds or uses and public evidence of delivered work. zkSecurity, Galois, Veridise, Nethermind, Formal Land, Cryspen, Reilabs and others.

Listing criteria: a formal-methods practice with public proof artifacts (repositories, papers or reports), tooling they build or maintain, and availability for third-party engagements. Order reflects the editors' assessment; see methodology.

#2Galois

Portland, Oregon, United States · Industrial formal verification: Cryptol, SAW, zkLean; verified AWS-LC, s2n, BLST, Soroban

Galois is a formal-methods research and engineering firm that builds Cryptol, SAW and zkLean and has delivered verification of AWS-LC and s2n (with NSym for AArch64), the BLST BLS library, Stellar's Soroban (Formal Verso) and Halo2 recursion work with IOG. Its zkLean framework is funded by the Ethereum Foundation.

Profile · Website

#3Veridise

Austin, Texas, United States · Automated ZK verification: Picus, LLZK, ZKAP; AuditHub platform; verified SP1 and RISC Zero components

Veridise builds Picus, the standard SMT underconstraint detector, and LLZK, the shared ZK intermediate representation released as v1.0 in April 2026 with an Ethereum Foundation grant. It has used LLZK and Picus to verify SP1 core operations and RISC Zero circuits and offers audits through its AuditHub platform.

Profile · Website

#4Nethermind (Formal Verification team)

London, United Kingdom · Lean and EasyCrypt verification: Halva (Halo2), Plonky3 circuits, SP1 chips, ZKsync verifier honesty proof

Nethermind's formal verification team works in Lean 4 and EasyCrypt. It built Halva for Halo2 (finding a critical bug in Scroll's deprecated Keccak circuit), co-developed sp1-lean with Succinct, maintains an ArkLib FRI fork and a Lean EVM model (EvmYul), and produced the first honesty proof of a production ZK verifier for ZKsync in EasyCrypt.

Profile · Website

#5Formal Land

Paris, France · Rocq verification: Garden (circuits), rocq-of-rust, rocq-of-solidity, rocq-of-llzk

Formal Land verifies circuits, Rust and Solidity in Rocq. Garden proves determinism, functional correctness and completeness of Circom and Plonky3 circuits, rocq-of-llzk connects it to Veridise's LLZK, and rocq-of-rust and rocq-of-solidity cover the code around a ZK system. Clients include the Ethereum Foundation (CompPoly, revm), Sui, Aleph Zero and Tezos.

Profile · Website

#6Cryspen

Berlin, Germany and Paris, France · hax and libcrux: verified Rust post-quantum implementations; hax Lean backend for the Verified zkEVM program

Cryspen builds hax, the Rust-to-proof-assistant translator, and libcrux, whose verified ML-KEM and ML-DSA ship in Mozilla and Signal. It is developing hax's Lean backend under an Ethereum Foundation grant and offers verification-driven reviews. The 2026 Verification Theatre paper documenting bugs outside libcrux's verified boundary is essential context for scoping its engagements.

Profile · Website

#7Reilabs

Warsaw, Poland · Lean 4 verification of Noir (Lampe) and gnark (proven-zk); verified Worldcoin circuits

Reilabs verifies ZK circuits in Lean 4 with Lampe for Noir and proven-zk for gnark. It verified Worldcoin's Semaphore Merkle tree batcher, found a comparison bug in gnark in the process, and lists Worldcoin, StarkWare and Polygon Miden as clients.

Profile · Website

#8Runtime Verification

Urbana, Illinois, United States · K framework, KEVM, zkevm-harness, EVM equivalence with Lean models

Runtime Verification maintains the K framework and KEVM and, within the Verified zkEVM program, the zkevm-harness and the equivalence proof between KEVM and Nethermind's Lean EvmYul model. It audits and verifies smart contracts and VM implementations.

Profile · Website

#9Certora

Tel Aviv, Israel and United States · Certora Prover for smart contracts on EVM, Solana, Move and Soroban

Certora builds and operates the Certora Prover, the most used smart-contract formal verification tool, open-sourced in 2025. It verifies the on-chain verifier, bridge and governance contracts around a ZK system; it does not verify circuits.

Profile · Website

#10Trail of Bits

New York, United States · Cryptography and ZK audits; Circomspect static analyzer; ZKDocs

Trail of Bits is a security research firm with a cryptography practice that audits ZK systems and maintains Circomspect and ZKDocs. Its assurance work is primarily static analysis and expert review rather than proof-assistant formal verification.

Profile · Website

#11Symbolic Software

Paris, France · Protocol-level verification (Verifpal) and cryptographic audits; author of the 2026 Verification Theatre paper

Symbolic Software, led by Nadim Kobeissi, builds Verifpal and performs protocol-level formal analysis and cryptographic audits. Its February 2026 Verification Theatre paper found 13 vulnerabilities in Cryspen's libcrux and hpke-rs, including four inside formally verified code, and is the reference on reading a verification boundary.

Profile · Website

How to choose