What other options are there?
It's the only systems level language with a formally verified compiler afaik.
rust is a no go because you can't trust the compiler's output (remember, we can't trust people to write correct code, so we obviously can't trust the compiler writers either).