Multi-prover formal verification of Certified Null Operations (CNO: programs provably computing nothing) and Observational Null Disclosure (OND: programs provably revealing nothing). Two co-equal, logically independent pillars verified across Coq, Lean 4, and Agda, with axiom counts and out-of-scope residue lists honestly surfaced.
-
Updated
Aug 18, 2026 - Rocq Prover