{"slug": "a-billion-proofs-a-day", "title": "A billion proofs a day", "summary": "Amazon's Automated Reasoning Group published a decade of reflections on proving AWS correct, highlighting that its policy engine Zelkova answers a billion SMT queries a day about what policies permit. The group's work includes a machine-checked Alloy model in the AWS CDK repo that proves the risky statement merge algorithm safe in advance.", "body_md": "Amazon’s Automated Reasoning Group just published [a decade of reflections](https://www.amazon.science/blog/a-decade-of-mathematical-certainty-reflections-on-the-automated-reasoning-group).\n\nIt’s the story of a decade spent proving AWS correct. Their policy engine Zelkova answers [a billion SMT queries a day](https://www.amazon.science/blog/a-billion-smt-queries-a-day) about what policies permit. Every one of these queries happens after the artifact exists. The queries are against normal JSON that nothing upstream cleans up or constrains.\n\nCDK has a miniature version of this. It runs a risky statement merge at synth, so a machine-checked [Alloy model](https://github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-iam/docs/policy-merging.als) in the repo proves the merge algorithm safe in advance.", "url": "https://wpnews.pro/news/a-billion-proofs-a-day", "canonical_source": "https://lex00.github.io/posts/a-billion-proofs-a-day/", "published_at": "2026-08-15 00:00:00+00:00", "updated_at": "2026-08-25 15:46:45.276607+00:00", "lang": "en", "topics": ["ai-research", "ai-tools"], "entities": ["Amazon", "Automated Reasoning Group", "AWS", "Zelkova", "AWS CDK", "Alloy"], "alternates": {"html": "https://wpnews.pro/news/a-billion-proofs-a-day", "markdown": "https://wpnews.pro/news/a-billion-proofs-a-day.md", "text": "https://wpnews.pro/news/a-billion-proofs-a-day.txt", "jsonld": "https://wpnews.pro/news/a-billion-proofs-a-day.jsonld"}}