For the selfless people
Nerve is a compiled language where Precog, a whole-program analyser, proves every overflow and bounds check at compile time. The final build carries none of them, or it doesn’t build.
Features & flaws
| What you get | What it costs |
|---|---|
| Precog proves every overflow and bounds check at compile time; the final build carries none of them. | Compile time is not a cost the language cares about: builds are slow, and every build is a full one — there is no fast development mode. |
| The working build checks what Precog can’t yet prove, whatever the runtime cost. | The final build refuses that code until you write a guardrail, a tighter type, or no_check. |
| Ownership, no garbage collector: every value has one owner, so the compiler knows when to free it. | Every call says what happens to a value: lend, give or copy. |
:= works out the best type from the whole program. | A value from outside the program has no bound, so there you write its type; := on it is an error. |
| Failures are part of a function’s signature, not exceptions. | The caller must handle every one; forgetting is a compile error. |
and / or always work out both sides: nothing written is skipped. | A check that guards the next step takes two ifs, or and.then. |
| An old spelling is refused with an error that names the new one. | No stability promise, ever: Nerve is unstable, and stays that way. |
| Native code, through LLVM. | In development: no release yet, nothing to download. |
Compare languages
Choose two languages. Compare their behavior, tooling and costs; performance depends on the workload.
Checked 3 Oct 2026. Nerve reflects current development and its stated design. Python means CPython, with free-threaded differences called out. Logo credits.
| Topic | NerveIn development | Rust1.99.0 |
|---|---|---|
| Maturity & stability | A hobby language in active development. No packaged release or stability promise; the compiler and libraries still have gaps. ProjectStability | A released, stable toolchain. Edition changes are opt-in; the compiler continues supporting older editions. Docs |
| Execution | CCA compiles supported programs to native code through LLVM. The oracle is a separate reference interpreter. Compiler | Ahead-of-time compilation: the resulting executable can run without the Rust toolchain installed. Docs |
| Types | Static types. The design asks Precog to choose a safe, efficient type across the program with | Static types with inference, generics and traits. Ownership and borrowing constraints are checked at compile time. OwnershipTypes |
| Memory | Ownership with explicit | Ownership and borrowing, with values dropped when their owner is dropped. No mandatory garbage collector; reference counting is available. OwnershipReference counting |
| Safety checks | Precog proves supported checks. Working builds keep unproven runtime checks; final builds refuse them unless explicitly trusted. Compiler and proof bugs are still being found. DesignKnown proof bug | Compile-time ownership checks in safe code; bounds checks can remain at runtime. Ordinary integer overflow is checked in debug builds and normally wraps in release builds. Docs |
| Failure handling | Function signatures list |
|
| Concurrency |
| Threads, channels and async/await. Ownership with |
| Everyday tooling | CCA and the oracle are in the repo. Library coverage and supporting tools are developing; there is no packaged download yet. Project | Cargo handles builds, dependencies and tests, with documentation and formatting tools. Packages are distributed through crates.io. Docs |
| Practical costs | Every build includes Precog. The design spends compile time to remove runtime checks; changing syntax and missing implementation pieces also cost developer time. Design | Borrowing and lifetime constraints shape API design. |