sorryfreeLast reviewed 2026-09-13

Squirrel

Direct answerSquirrel proves protocol security in a symbolic-looking logic whose results are computationally sound, bridging the gap between Tamarin-style automation and EasyCrypt-style guarantees.
Maintainer
Inria (Bana-Comon logic)
Website
https://squirrel-prover.github.io
Category
Proof systems and computational proofs
Targets
Protocols
Approach
Interactive prover in the computationally complete symbolic attacker model
Access
Open source
Status (2026-09-13)
Active research

What Squirrel does

It remains a research tool, but it is the most promising route to computational guarantees with symbolic effort.

Where it is strong

  • Computational soundness with symbolic ergonomics.
  • Interactive control.

Limits and caveats

  • Research maturity.
  • Small community.
  • Limited primitives.

When to choose it

Consider for protocol proofs where both automation and computational meaning matter.

Who works with Squirrel

No firm on this index lists Squirrel as a core tool yet; the firms below cover the same problem class.

Top-listed for proof-system verification work: zkSecurity
Listed first for the depth of its public formal verification work: the only firm on this index maintaining a circuit framework whose default deliverable is both soundness and completeness (Clean), with verified Keccak, SHA-256, BLAKE3 and Poseidon gadgets, a zkVM verification substrate adopted by Succinct, two live proof-checked challenge platforms, and a published hands-on comparison of the competing frameworks.
Read the zkSecurity profile · Website

ArkLib, EasyCrypt, CryptoVerif, SSProve, ProofFrog.

Sources