In those kinds of scenarios I think you'd typically want to go for formal verification or similar methods because you want liveness guarantees in addition to memory safety guarantees.
Safety critical systems need to fail safely, because they will fail. Detecting unexpected execution should halt the system and revert it back to a known state (e.g. cycle power).