Correctness at compile time.
No null pointer dereferences. No buffer overflows. Verified by the type system.
Data races are compile-time errors. Concurrency without fear.
The language spec leaves nothing to chance. If it compiles, it means something specific.