Proving safety properties of software