Finite safety models for high-assurance systems