Runtime Verification
Runtime Verification provides formal verification consulting and tools (K Framework, Kontrol, KaaS, Simbolik, Komet) for blockchain protocols, aerospace, automotive, and medical device clients. Its engineers apply mathematical methods and symbolic execution to mathematically prove correctness in mission-critical software systems.
- Company typePrivate
- Founded2010
- HeadquartersUrbana, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Runtime Verification does
Runtime Verification is a formal verification firm founded in 2010 by Grigore Rosu at the University of Illinois at Urbana-Champaign, headquartered in Moab, Utah with a regional presence in Urbana-Champaign, Illinois. The company applies formal methods, symbolic execution, fuzzing, and model checking to mathematically prove correctness in software systems where failure is unacceptable. Its core technology is the K Framework, a rewrite-based semantic framework for defining programming language semantics that the company has maintained since 2010, underpinned by Grigore Rosu's 2019 publication of matching logic as a unifying formal foundation.
The product portfolio built on K includes Kontrol (symbolic execution for Solidity via Foundry), KaaS (cloud-hosted fuzzing infrastructure with AI agent integration), Simbolik (Solidity developer toolkit), Komet (formal verification for Stellar/Soroban), ERCx (Ethereum smart contract specification language), and the legacy RV-Match, RV-Monitor, and RV-Predict tools for C and Java. Complementing these tools, the company delivers professional services including security audits, design reviews, fuzzing campaigns, and formal verification consulting, priced at $30k/month (Consult tier) and $50k/month (Outsource tier), with a free Use tier (Kontrol). Customers include NASA, Boeing, Toyota, DARPA, Ethereum Foundation, Solana Foundation, Stellar, MakerDAO, Uniswap, EigenLayer, and Optimism, spanning blockchain/DeFi, aerospace, automotive, and medical device verticals.
The company raised $5.3 million in a Series A led by IOSG Ventures in June 2021, with participation from Maven 11 Capital and five blockchain foundations, and earlier received grants from NSF ($1.4M in 2017, $180k in 2015) and NASA SBIR funding. Leadership includes CEO Everett Hildenbrandt, COO Paul Len, CTO Palina Tolmach, and founder Grigore Rosu, supported by 25+ senior engineers from top universities. Distribution combines direct enterprise sales for audits with self-serve open-source tooling and a formal partner referral program.
Runtime Verification firmographics
Firmographics- Name
- Runtime Verification
- Legal name
- Runtime Verification, Inc.
- Website
- https://runtimeverification.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Runtime Verification provides formal verification consulting and tools (K Framework, Kontrol, KaaS, Simbolik, Komet) for blockchain protocols, aerospace, automotive, and medical device clients. Its engineers apply mathematical methods and symbolic execution to mathematically prove correctness in mission-critical software systems.
- Ownership category
- akta.pro rank
Runtime Verification industry classification
Industry- Product category
- Cybersecurity Consulting & Formal Verification Services
- NAICS
- Custom Computer Programming Services (541511), Testing Laboratories and Services (541380), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371), Services-Testing Laboratories (8734), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Smart Contract Auditing & Formal Verification (FSAPAJAA)
- akta.pro secondary industries
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI), Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where Runtime Verification is headquartered
LocationHeadquarters
- HQ city
- Urbana
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Runtime Verification business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Formal Verification Consulting: Engagement-based consulting with three tiers: Use (free self-service Kontrol), Consult ($30k/month with dedicated engineer), and Outsource ($50k/month with two full-time verification engineers). Revenue generated through professional services engagements.
- Security Auditing Services: End-to-end security audits for blockchain protocols and critical systems. Pricing varies by scope and complexity. Includes design review, code review, fuzzing campaigns, and formal verification passes.
- Design Review Services: Architecture analysis, invariant specification, and audit-grade documentation services. Minimum one week engagement with formal methods engineers.
- Tool Licensing / SaaS: KaaS (Kontrol-as-a-Service) provides cloud infrastructure for fuzzing campaigns with free tier and potential paid enterprise features.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Use - Free symbolic execution tool |
| Subscription | Monthly | Consult - Full-time engineer dedicated to project |
| Subscription | Monthly | Outsource - Complete verification service |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Runtime Verification product offering
Product offeringCore offering
Runtime Verification provides high-assurance cybersecurity consulting and formal verification services for critical software systems, combined with a portfolio of proprietary open-source developer tools. The company combines formal methods expertise (symbolic execution, formal verification, advanced fuzzing, model checking) to deliver security audits, design reviews, and verification engagements for blockchain protocols, aerospace, automotive, and medical device software. Core proprietary tools include the K Framework, Kontrol, KaaS, Simbolik, Komet, and ERCx, while professional services are sold via tiered subscriptions ($30k-$50k/month) and project-based engagements.
Product overview
Runtime Verification offers a unified platform combining proprietary verification tools with consulting services for securing critical software systems. The core product portfolio includes K Framework (the foundational semantic framework for defining programming languages), Kontrol (symbolic execution for Solidity via Foundry), KaaS (cloud infrastructure for verification proofs), Simbolik (Solidity developer toolkit), Komet (Soroban verification), and ERCx (smart contract specification language). These are complemented by professional services including security audits, design reviews, fuzzing campaigns, and formal verification consulting. The company also maintains legacy tools (RV-Match, RV-Monitor, RV-Predict) for C and Java verification. The platform is designed for organizations building software that cannot fail, particularly in blockchain, aerospace, automotive, and medical device sectors.
Differentiator
Problem solved
Functional benefit
Brands
- K Framework: A semantic framework for programming language design, implementation and formal reasoning, maintained by Runtime Verification since 2010
- Kontrol
- KaaS
- Simbolik
- Komet
- ERCx
- RV-Match
- RV-Monitor
- RV-Predict
Products and services
- K Framework A semantic framework for defining programming language semantics and deriving correct-by-construction implementations and analysis tools. Created and maintained by Runtime Verification since 2010 and widely used as a platform for defining programming language semantics.
- Kontrol Open-source symbolic execution tool for Foundry that turns Foundry tests into formal proofs, enabling developers to verify smart contract correctness without learning new semantics or languages. Free to use.
- KaaS (Kontrol-as-a-Service) Web interface and cloud compute infrastructure for running formal verification proofs, providing free fuzzing infrastructure, test coverage reports, and AI agent integration for continuous security assurance.
- Simbolik Full Solidity developer toolkit providing debugging, security analysis, and development utilities for Ethereum smart contract engineers.
- Komet Formal verification tool specifically designed for Soroban smart contracts on the Stellar blockchain, enabling property testing and verification.
- ERCx Open-source specification language and runtime monitoring tool for Ethereum smart contracts that enables formal specification and runtime verification.
- Security Audits Comprehensive end-to-end security reviews combining formal methods, symbolic execution, fuzzing, and model checking to verify smart contracts and blockchain infrastructure for enterprise clients.
- Design Review Architecture analysis and invariant specification service starting at a one-week minimum engagement with one formal methods engineer. Helps define system properties and produces lasting documentation for AI tools, future audits, and engineering teams.
- Fuzzing Campaigns Advanced fuzzing harness development and execution service using differential fuzzing, property-based fuzzing, and coverage-guided exploration for critical software systems.
- Formal Verification Consulting Mathematical proof-based verification services using symbolic execution to test entire input spaces, offered in tiered subscriptions: Consult ($30k/month with one full-time engineer) and Outsource ($50k/month with two full-time verification engineers).
- RV-Match Semantics-based automatic debugger for C code and the most advanced semantics-based bug finding tool for detecting common and subtle C errors. Legacy product.
- RV-Monitor Runtime monitoring tool that automatically checks Java code for compliance with API specifications or custom specifications. Legacy product.
- RV-Predict Automatic data race detector for Java and C/C++ code, identifying the rarest and most difficult-to-find race conditions. Legacy product.
Quantifiable outcome
- Over $100B in Total Value Secured across client engagements
- +3 more outcomes
Companies that use Runtime Verification
Customer profileNamed customers26 records
Segments4 records
Ideal customer profiles3 records
Runtime Verification technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature9 records
Runtime Verification partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- IOHK/CardanocoreDeep collaboration since 2017 for formal verification tooling. Developed KEVM, IELE VM for Cardano, and K framework extensions. IOHK CEO Charles Hoskinson called IELE 'unbelievable stuff' and 'truly exciting'.
- Ethereum Trust AlliancecoreFounding member of the Ethereum Trust Alliance, a group of global blockchain security companies creating a security rating system for smart contracts. Founding members include MythX, Quantstamp, Sooho, SmartDec and ConsenSys Diligence.
- PlatON NetworksminorProtocol verification agreement for PlatON blockchain. Collaboration included verification of consensus protocol safety and stability, working on Grisk proof and concurrent scenarios.
Scale indicators6 records
Recent moves7 records
Expansion highlights5 records
Runtime Verification competitors and assessment
Company assessmentBroad incumbents
- OpenZeppelin: OpenZeppelin is a broad incumbent in smart contract security, combining open-source libraries (OpenZeppelin Contracts), audit services, and the Defender platform. Overlaps with Runtime Verification's audit and tooling business, but at much larger scale and broader portfolio.
- CertiK: CertiK is a broad incumbent in blockchain security, offering audits, formal verification, and the Skynet monitoring platform. Compares to Runtime Verification on formal verification and smart contract audits at significantly larger scale.
- ConsenSys Diligence: ConsenSys Diligence is the audit arm of ConsenSys and a founding member of the Ethereum Trust Alliance. Offers smart contract audits, MythX tooling, and security services directly overlapping with Runtime Verification's audit practice.
Emerging players
- Zellic: Zellic is an emerging player offering security audits and formal verification for blockchain protocols and zero-knowledge circuits. Directly comparable to Runtime Verification's audit and formal verification services.
- Spearbit: Spearbit is an emerging player that curates a network of senior security researchers for smart contract audits. Comparable to Runtime Verification's high-end audit engagements, though operating on a marketplace rather than employed-engineer model.
- Cyfrin: Cyfrin is an emerging player in smart contract security audits and developer education (Cyfrin Updraft). Directly comparable to Runtime Verification's audit services while also competing on developer-tooling distribution.
Direct peers
- Quantstamp: Quantstamp is a direct peer offering smart contract security audits and automated scanning tools for blockchain protocols. Founding member of the Ethereum Trust Alliance alongside Runtime Verification, with comparable service offerings.
- Halborn: Halborn is a direct peer providing end-to-end blockchain security services including smart contract audits, penetration testing, and security tooling. Overlaps with Runtime Verification across DeFi and Web3 protocol audits.
- Trail of Bits: Trail of Bits is a direct peer providing high-assurance security audits, formal verification, and security tooling for blockchain and critical infrastructure clients. Overlaps with Runtime Verification across smart contract audits and aerospace/defense engagements.
- Certora: Certora is a direct peer offering formal verification tools and services for smart contracts (Certora Prover, Sunbeam). Highly comparable to Runtime Verification's Kontrol + formal verification services across Solidity/EVM ecosystems.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights3 records
Customer concentration
Runtime Verification social profiles
Digital presenceRuntime Verification financial estimates
Financial estimateRevenue estimate
Valuation estimate
Runtime Verification leadership team
Management profileNumber of profiles
Profiles16 records
Runtime Verification funding detail
Funding detailFunding overview
Funding rounds3 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Runtime Verification M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Runtime Verification
What does Runtime Verification do?
Runtime Verification provides high-assurance cybersecurity consulting and formal verification services for critical software systems, combined with a portfolio of proprietary open-source developer tools. The company combines formal methods expertise (symbolic execution, formal verification, advanced fuzzing, model checking) to deliver security audits, design reviews, and verification engagements for blockchain protocols, aerospace, automotive, and medical device software. Core proprietary tools include the K Framework, Kontrol, KaaS, Simbolik, Komet, and ERCx, while professional services are sold via tiered subscriptions ($30k-$50k/month) and project-based engagements.
Is Runtime Verification a public or private company?
Runtime Verification is a private company. It is classified as venture growth investor backed and is currently operating.
When was Runtime Verification founded?
Runtime Verification was founded in 2010. It employs 11 to 50 people.
Where is Runtime Verification based?
Runtime Verification is headquartered in Urbana, United States, in the North America region.
How does Runtime Verification make money?
Four revenue lines are on record. Formal Verification Consulting is the primary driver. The others are security Auditing Services, design Review Services and tool Licensing / SaaS.
Who are Runtime Verification's main competitors?
Broad incumbents on record are OpenZeppelin, CertiK and ConsenSys Diligence. Emerging players are Zellic, Spearbit and Cyfrin. Direct peers are Quantstamp, Halborn, Trail of Bits and Certora.
Does Runtime Verification have an API?
No public API is recorded for Runtime Verification.
What industry is Runtime Verification in?
Runtime Verification's product category is Cybersecurity Consulting & Formal Verification Services. Its primary akta.pro industry code is FSAPAJAA, Smart Contract Auditing & Formal Verification, with a secondary code of FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification). Its NAICS code is 541511 and its SIC code is 7371.