Verified Rust for low-level systems code
an abstract interpreter operating on Rust's mid-level intermediate representation (MIR)
Compile-time assertions to ensure that invariants are met