EC2’s formally verified “isolation engine” provides mathematical assurance of virtual-machine isolation (opens in new tab)
Splitting the “separation kernel” off from the rest of the Nitro security system and using only a subset of the Rust programming language to code it enabled its formal verification.
Read the original article