Rewriting SymCrypt in Rust to modernize Microsoft’s cryptographic library

Conformance checking at MongoDB: Testing that our code matches our TLA+ specs

Proving completeness of an eventually perfect failure detector in Lean4

Telescopes Are Tries: A Dependent Type Shellac on SQLite

StarMalloc: verified memory allocator

AI is a gamechanger for TLA+ users

NVIDIA ISO-26262 SPARK Process

What works (and doesn't) selling formal methods

The current state of TLA⁺ development

A Lean companion to Analysis I

Are We Serious About Using TLA+ For Statistical Properties?

A leap year check in three instructions

Systems Correctness Practices at Amazon Web Services

Sleeping soundly with the help of TLA+ (2022)

A tool to verify estimates, II: a flexible proof assistant

GenAI-Accelerated TLA+ Challenge

The Coming AI Revolution in Distributed Systems

Warteschlangensimulator

Benchmarking Crimes Meet Formal Verification

Modular verification of MongoDB Transactions using TLA+

The value of model checking in distributed protocols design

New Life Hack: Using LLMs to Generate Constraint Solver Programs for Personal Logistics Tasks

Debugging a Logic Circuit in IDP-Z3

A Python frozenset interpretation of Dependent Type Theory

Model error

Advent of Code in Coq (2021)

3110 Coq Tactics Cheatsheet

Revisiting an early critique of formal verification

coqoban: Sokoban (in Coq)

certicoq: A Verified Compiler for Gallina, Written in Gallina

More →