Multi-prover formal verification of Certified Null Operations (CNO: programs provably computing nothing) and Observational Null Disclosure (OND: programs provably revealing nothing). Two co-equal, logically independent pillars verified across Coq, Lean 4, and Agda, with axiom counts and out-of-scope residue lists honestly surfaced.
security coq agda formal-verification proof-engineering lean4 reversible-computing non-interference null-operations
-
Updated
Sep 2, 2026 - Rocq Prover