ADA/Spark or Modula-2 would come to my mind, but there must be more like rune for constant-time and more such crypto-only problems. I'm sure djb has such one also. https://cr.yp.to/talks/2021.09.03/slides-djb-20210903-safere...
* https://github.com/GaloisInc/hacrypto
* https://github.com/fmlab-iis/cryptoline
* https://github.com/mit-plv/fiat-crypto/ (Bedrock2)
* https://github.com/hacl-star/hacl-star (F* and ValeCrypt)