Detects coding rule violations and runtime errors without running the code
Defect list · Rule compliance rate · Metrics
Code Verification for Mission-Critical Software
The Suresofttech (SURESOFTTECH) verification suite supports code verification for mission-critical software in three stages: before the code runs (STATIC), while tests are designed and executed (CT), and by confirming how much of the code those tests actually executed (COVER).
STATIC · CT · COVER
Based on STATIC Enterprise.
Standalone supports up to 7.
automotive · aerospace · defense · railway · nuclear · medical
Each product verifies a different point in the development flow
Implementation and coding
Detects coding rule violations and runtime errors without running the code
Defect list · Rule compliance rate · Metrics
Unit and integration testing
Designs and executes unit and integration tests; confirms statement, branch, MC/DC
Test results · Traceability · Coverage
System and target testing
Measures how much of the code the executed tests actually reached
Coverage indicators · Unexecuted code · Reports
The build passed and testing is done is not a verification result.
memory leaks, NULL dereferences, and array-bound overruns pass compilation and survive into execution.
if you do not know which code actually ran, defects in the branches and conditions your tests never reached simply remain.
safety and regulated projects must leave behind, in reviewable form, what was verified and against which criteria.
STATIC works before execution, CT designs and executes the tests, and COVER verifies from the test results.
| Aspect | STATIC | CT | COVER |
|---|---|---|---|
| Verification method | Static analysis (no code execution) | Dynamic testing (test design and execution) | Dynamic analysis (measurement of execution results) |
| Question it answers | Does this code contain rule violations and latent defects? | Does this code behave as intended? | How far into the code did the tests reach? |
| Primary stage | Coding, commit, build | Unit and integration testing | From unit testing through system and target testing |
| Representative output | Defect list, rule compliance rate, quality metrics | Test results, requirements traceability, coverage | Coverage indicators, unexecuted code, measurement reports |
A static analysis tool that detects coding rule violations, runtime errors, and potential security vulnerabilities without executing the source code.
more than 1,200 inspection patterns and more than 30 kinds of semantic analysis find memory, arithmetic, and array-bound errors before the code is ever run.
automatically checks coding rules such as MISRA, AUTOSAR C++14, and CERT, CWE-based security weaknesses, and items from DAPA, HKMC, and Ministry of the Interior and Safety guidelines.
tracks defect status and assignees, and manages quality trends with the rule compliance rate (RCR) and defect density.
A test automation solution for unit, integration, and code-based testing of mission-critical C/C++ software. It connects test environment setup, test design and generation, execution, code coverage analysis, reporting, and traceability management into a single flow.
manages test conditions and data, designs and executes tests at the function, module, and interface level, and confirms them with statement, branch, and MC/DC coverage.
ALIRA AI inside the product and DVERA, the integration solution for AI coding agents, assist with test design, generation, and error analysis. Generated tests are verified against actual execution results and code coverage.
links requirements, tests, execution results, and coverage for use as review reports and traceability records.
A dynamic analysis tool that analyzes test execution results as code coverage to confirm the sufficiency of software testing.
Enterprise measures up to 10 coverage indicators and Standalone up to 7 from the results of a single test execution.
after the initial integration setup, you continue to use your existing compilers, IDEs, and test methods, and application source code is not modified manually.
a proprietary probe insertion method (Korean Patent No. 10-1667262) keeps the probe code small, so measurement is possible even on targets with little memory headroom. Execution overhead is around 10%.
Actual overhead varies with the language, target performance, the coverage types measured, and the instrumentation scope.
| What you need right now | Where to start |
|---|---|
| Check and evidence compliance with coding rules (MISRA, CERT, and others) | |
| Filter out memory, arithmetic, and boundary errors that are hard to reproduce in testing | |
| Manage code quality trends and defect handling across the organization | |
| Design and execute unit and integration tests and produce test records | |
| Maintain traceability linking requirements to tests and execution results | |
| Generate and run tests inside an AI coding agent workflow | |
| Measure how much code your existing tests actually execute | |
| Measure coverage on a real target board | |
| Consolidate coverage scattered across teams and servers into one report | |
| Build verification evidence for the highest grades such as ASIL D or Software Level A |
Clear the rule violations first, confirm behavior through testing, then confirm sufficiency with coverage - one connected body of verification evidence.
STATIC detects coding rule violations and runtime errors at commit and build time, assigns defects to owners, and tracks their handling status.
CT designs and executes requirements-based and structure-based tests, leaving statement, branch, and MC/DC coverage together with requirements traceability.
COVER measures coverage from test execution results including system testing and real-target testing, and uses unexecuted code as the basis for deciding what testing to add.
all three products can run automatically in a CI environment, so every code change is verified against the same criteria and the results accumulate.
Detects coding rule violations and runtime errors at commit and build time, then assigns them to owners for tracking.
Designs and executes requirements-based and structure-based tests, recording coverage and requirements traceability.
Measures coverage from system and target testing results, then uses unexecuted code to scope further testing.
Links defect, test, and coverage records into one body of verification evidence for reports and traceability.
Each product supports the verification activities required in safety and regulated projects in its own way.
| Domain | Representative standard | STATIC | CT | COVER |
|---|---|---|---|---|
| Automotive | ISO 26262 | Coding rule inspection and static analysis results used as verification evidence | Unit and integration testing, coverage, traceability (within TÜV SÜD certification scope) | Built-in measurement criteria for ASIL A–D |
| Aerospace | DO-178C / DO-330 | Static analysis results used as verification evidence | Supports the verification activities (not within the TÜV SÜD certification scope; tool qualification is judged per project) | Built-in measurement criteria for Software Level A–D and TQL-1–5 |
| Defense | DAPA weapon system software guidelines | Rule sets based on the reliability evaluation guidelines, 6 function metrics | Unit and integration testing with test result management | Built-in statement, branch, and MC/DC criteria |
| Railway | IEC 62279 / EN 50128 · EN 50716 | Static analysis results used as verification evidence | Unit and integration testing, coverage, traceability (within TÜV SÜD certification scope) | Built-in measurement criteria for SIL 0–4 |
| Nuclear | IEC 60880 | Static analysis results used as verification evidence | Unit and integration testing, result and report management (within TÜV SÜD certification scope) | Built-in statement, branch, and MC/DC criteria |
| Medical devices | IEC 62304 | Static analysis results used as verification evidence | Test execution, result and traceability records (within TÜV SÜD certification scope) | Built-in measurement criteria for Class A–C |
| Functional safety (general) | IEC 61508 | Coding rule inspection and static analysis results used as verification evidence | Unit and integration testing, coverage, verification records (within TÜV SÜD certification scope) | Built-in measurement criteria for SIL 1–4 |
CT holds TÜV SÜD tool certification for the standards marked above, and the certification applies to a specific product version and the functional scope defined in the Certification Report. DO-178C and DO-330 are not within CT's TÜV SÜD certification scope; for aerospace projects, tool qualification is judged per project based on the intended use and how the verification evidence is used. STATIC and COVER provide tool qualification materials for use in certification reviews; the materials actually provided and the applicable product versions and standard scope must be confirmed per project.
See COVER's grade-level coverage mapping → See CT's tool certification scope →
AI is used to reduce repetitive work, and its output is verified against actual execution results and code coverage.
Tests and judgments produced by AI are not verification evidence on their own. The test intent and expected results are reviewed first, and confirmation still comes from actual execution results and code coverage.
answers questions about tool usage, defect causes, and remediation guidance based on the STATIC guide documentation.
finds and recommends past suppression history similar to the current defect, and lets you compare the original code with the recommendation in a diff view before accepting it.
assists with the design and generation of requirements-based and structure-based tests, and with error analysis, inside CT.
connects AI coding agents such as Claude Code, Codex CLI, Cursor, and GitHub Copilot so they can use CT's analysis, execution, and coverage capabilities directly from their working context.
Custom coding rules to prevent recurring errors
Meeting reliability test criteria
Coverage as the gate for production release
No. Each product can be used independently. Because their verification purposes differ, however, projects that require coding rule compliance (STATIC), unit and integration testing (CT), and test sufficiency confirmation (COVER) get a single connected body of evidence when the products are used together.
The first product to adopt depends on which verification evidence your project lacks most. Start with STATIC if there is no code quality baseline, with CT if unit test records are required, and with COVER if you must confirm the sufficiency of testing you already perform. See Which Product Do You Need? for the detailed criteria.
STATIC Enterprise supports C/C++, C#, Java, Kotlin, and Python, and STATIC Standalone supports C/C++. CT targets C/C++. COVER Enterprise supports C/C++, C#, and Java, and COVER Standalone supports C/C++ and C#. Language versions and development environments are listed in the supported languages document.
All three products can run automatically in a CI environment. STATIC performs static analysis automatically during the build, CT repeats regression tests and coverage analysis through the CLI, a Jenkins plugin, or Docker, and COVER aggregates results through its Open API and CI integration. See each product page for the integration details.
Yes. For STATIC and COVER, the Enterprise editions run on servers and analysis or measurement agents inside your internal network, and the Standalone editions are installed on a local PC. Conditions such as AI feature availability and licensing method should be confirmed during the consultation.
Yes. STATIC supports embedded toolchains such as IAR, Keil, TASKING, Renesas, TI, and Microchip; CT executes tests on real targets over Ethernet, Serial, or JTAG; and COVER Standalone measures coverage even on resource-constrained targets.
CT holds TÜV SÜD tool certification for ISO 26262, IEC 62279/EN 50716, IEC 60880, IEC 62304, and IEC 61508, and STATIC and COVER provide tool qualification materials. The scope actually provided and the applicable product versions must be confirmed per project.
Find the verification scope and product configuration that fit your project environment.
| Product | One-line definition | Link |
|---|---|---|
| A static analysis tool that detects coding rule violations and runtime errors without execution | Learn more → | |
| A unit, integration, and code-based test automation solution for mission-critical C/C++ | Learn more → | |
| A dynamic analysis tool that analyzes test execution results as code coverage | Learn more → |