Nerve

For the selfless people

Nerve is a compiled language where Precog, a whole-program analyser, proves every overflow and bounds check at compile time. The final build carries none of them, or it doesn’t build.

Features & flaws

What you getWhat it costs
Precog proves every overflow and bounds check at compile time; the final build carries none of them.Compile time is not a cost the language cares about: builds are slow, and every build is a full one — there is no fast development mode.
The working build checks what Precog can’t yet prove, whatever the runtime cost.The final build refuses that code until you write a guardrail, a tighter type, or no_check.
Ownership, no garbage collector: every value has one owner, so the compiler knows when to free it.Every call says what happens to a value: lend, give or copy.
:= works out the best type from the whole program.A value from outside the program has no bound, so there you write its type; := on it is an error.
Failures are part of a function’s signature, not exceptions.The caller must handle every one; forgetting is a compile error.
and / or always work out both sides: nothing written is skipped.A check that guards the next step takes two ifs, or and.then.
An old spelling is refused with an error that names the new one.No stability promise, ever: Nerve is unstable, and stays that way.
Native code, through LLVM.In development: no release yet, nothing to download.

Compare languages

Choose two languages. Compare their behavior, tooling and costs; performance depends on the workload.

Left side
Right side

Checked 3 Oct 2026. Nerve reflects current development and its stated design. Python means CPython, with free-threaded differences called out. Logo credits.

Nerve compared with Rust
TopicNerveIn developmentRust1.99.0
Maturity & stability

A hobby language in active development. No packaged release or stability promise; the compiler and libraries still have gaps.

ProjectStability

A released, stable toolchain. Edition changes are opt-in; the compiler continues supporting older editions.

Docs
Execution

CCA compiles supported programs to native code through LLVM. The oracle is a separate reference interpreter.

Compiler

Ahead-of-time compilation: the resulting executable can run without the Rust toolchain installed.

Docs
Types

Static types. The design asks Precog to choose a safe, efficient type across the program with :=; outside boundaries need explicit types. Inference is still evolving.

Design

Static types with inference, generics and traits. Ownership and borrowing constraints are checked at compile time.

OwnershipTypes
Memory

Ownership with explicit lend, give and copy. The compiler arranges reclamation; the model does not require tracing garbage collection.

Design

Ownership and borrowing, with values dropped when their owner is dropped. No mandatory garbage collector; reference counting is available.

OwnershipReference counting
Safety checks

Precog proves supported checks. Working builds keep unproven runtime checks; final builds refuse them unless explicitly trusted. Compiler and proof bugs are still being found.

DesignKnown proof bug

Compile-time ownership checks in safe code; bounds checks can remain at runtime. Ordinary integer overflow is checked in debug builds and normally wraps in release builds.

Docs
Failure handling

Function signatures list fail outcomes. Callers must handle them with otherwise, including forwarding a failure to their own caller.

Design

Result and ? handle recoverable errors; panics also exist. Ignoring a Result produces a warning by default, which projects can make an error.

Docs
Concurrency

concur and channels, with a prototype runtime multiplexing tasks over worker threads. Its guarantees still depend on the developing compiler and runtime.

Runtime

Threads, channels and async/await. Ownership with Send and Sync prevents data races in sound safe code; deadlocks and logical races remain possible.

Docs
Everyday tooling

CCA and the oracle are in the repo. Library coverage and supporting tools are developing; there is no packaged download yet.

Project

Cargo handles builds, dependencies and tests, with documentation and formatting tools. Packages are distributed through crates.io.

Docs
Practical costs

Every build includes Precog. The design spends compile time to remove runtime checks; changing syntax and missing implementation pieces also cost developer time.

Design

Borrowing and lifetime constraints shape API design. unsafe code and foreign interfaces put additional safety obligations on their authors.

Docs