formal safety analysis