Unlike a general-purpose OS, seL4 optimizes for a tiny trusted computing base: the fewer kernel lines that must be correct, the fewer places a bug becomes a security incident. As of August 2026, Proofcraft completed machine-checked confidentiality proofs for seL4 on AArch64 alongside existing functional correctness and integrity proofs. seL4 targets safety- and security-critical systems — defense, automotive, medical — where isolation claims must be auditable, not where teams need Docker and apt-get.