Three layers. One gate.
Three architectural layers, each placed out of reach of the systems it governs. The control plane confirms that both Churchill and The Protector are operating, from offsite. Churchill verifies what executes. The Protector anchors Churchill in the kernel, where refusals happen at the kernel boundary rather than in user space.
Offsite from every client host, as a dedicated single-tenant instance in the region agreed at deployment. Exact siting is disclosed under NDA at technical qualification and withheld publicly for security reasons. It confirms that both Churchill and The Protector are still operating: if either goes silent, the control plane detects the anomaly and signals the host, which decides and enforces the imminent-breach response. Enforcement is on-host by design, so it holds even when the control plane is unreachable. Each fleet gets a self-contained instance, and your organization can operate it rather than WestGate.
The runtime gate. A cryptographically signed snapshot of your application defines what is allowed to run, verified in real time. Legitimate traffic passes at full speed. Anything outside the snapshot is stopped before it executes and preserved as forensic evidence.
Anchors Churchill at the kernel boundary, hidden, where an unauthorized operation is refused before it takes effect and the refusal is out of reach of user space or root. A sentinel failure refuses rather than permits, and it composes with SELinux, AppArmor, and kernel lockdown rather than replacing them: a denial by any of those is never converted into an allow. Without The Protector, Churchill could be tampered with. With it, Churchill sits out of reach of the systems it governs, including from root.
A refusal is not an outage. A lockdown is not a refusal.
Anyone evaluating this for a production workload should understand both. Never WestGate's decision, on either path.
This is what happens to an attack, a bad deploy, or config drift. The operation stops before it takes effect. Nothing restarts, nothing waits on a human. A refusal is not an outage.
No single administrator can clear a lockdown. Not triggered by refusals, however many: refusing an attack does not lead here. Two things do. Tampering with the protection itself, and a governed change window that closes with the binary still changed or that any one of your approvers vetoes. In the Anthropic program it fired once across the 29 adversarial sessions, after a second tamper attempt on a freshly delivered runtime. Four other sessions recovered automatically with no operator involved.
Both paths in full, including what you can and cannot configure →
Confidential computing protects your data in use from the infrastructure. Churchill protects your application in use from root.
You already own guarantees like this: the HSM holding your keys, the enclave sealing your memory. Root inside the workload is inside the enclave's trust boundary, and it can make authorized requests of your HSM. Churchill closes the side the enclave leaves open.
| HSM | Confidential computing | Churchill | |
|---|---|---|---|
| The guarantee | Keys cannot be extracted | The infrastructure cannot see or alter data in use | The application cannot be tampered with in execution |
| Protects you from | Key theft, even by insiders | The host, the hypervisor, the cloud operator | Anyone, or anything, with access to your application: super admins, tools, AIs, insiders, intruders |
| When attacked | The key never leaves the hardware | The enclave stays sealed | The unapproved operation is denied at the system's core (the kernel); the workload keeps running |
| What stops keeping you up | “Were the keys stolen?” | “Can the provider see our data?” | “Did anyone, or anything, with access change what is running?” |
| What it will never do | Govern how authorized users use the keys | Govern what happens inside the trust boundary | Hide memory or hold keys. That is their job |
| Why the price | Priced against the value of the keys | Priced against the sensitivity of the data | Priced against the cost of the workload failing |
| Track record | Decades. FIPS-certified. They win this row | Consortium-defined, hardware-attested. They win this row | New. So we proved it in public: 30 days, 31 researchers, 282 distinct techniques, zero breaches at the core |
The HSM signs whatever the application asks. Churchill guarantees the asker. Churchill is infrastructure, not a tool: like your HSM and your enclaves, it is not compared against the stack, it is what the stack stands on. Comparing Churchill to EDR, FIM, or allowlisting is a different job. See how Churchill fits your existing stack →
Change clears only through the approver pool you design.
As many members as you choose. Approval takes a minimum of two; a single veto denies. Every approval is a cryptographically signed receipt on the evidence chain, so an approver cannot hide or forge their vote.
The pool is the change board you already have.
Nobody outside it gains a vote, and no one at WestGate has one. The veto exists so an approver cannot be pressured into signing something they do not believe in, which protects the people who hold the keys as much as the system.
Whether that is a welcome change to how change happens on your critical hosts is a conversation with whoever owns those hosts, and it is better had early than discovered at the first release.
Built to fit the model you already run.
No new infrastructure to stand up and no changes to your build pipeline.
Structured events into the SIEM and SOAR you already run.
Hash-chained records in dual custody, exportable per host, per account, per window.
Kernel 5.0 and higher, at full strength from 5.7. x86_64 and IBM Z / LinuxONE today. A Windows edition is in development.
Five architectural decisions.
Not part of your build pipeline.
Build pipelines sign whatever the build infrastructure produces. A compromised build means signed corrupt code, deployed with full pipeline trust. Churchill operates separately, verifying what is actually running against what your governance board approved, regardless of how the code was built.
Stops the attack. Not your business.
When Churchill refuses an unauthorized change, the protected application keeps running. Customers, transactions, and operations continue uninterrupted. Churchill shuts a system down only when an attacker has compromised Churchill's own recovery layers and is attacking repeatedly.
The attempt becomes your evidence.
Refused attacks do not disappear, they are captured. Not one byte on the real system is modified, and every action becomes forensic evidence with a complete chain of custody, held in two places at once. You see the attempt; the attacker sees an ordinary permission error.
No gap between the check and the run.
Allowlisting and file-integrity tools verify a path, then let the kernel open the file separately. An attacker who substitutes the file between those two steps defeats the check. This is the time-of-check to time-of-use race, TOCTOU, and it is the failure mode of the category. Churchill hashes the contents of the file the kernel has already opened for that execution, so the verdict applies to the exact object about to run. There is no in between to exploit.
A verdict at every decision point.
Churchill evaluates every execution request before it runs. 406,433 enforcement decisions in 11.3 hours during the Mythos engagement. Every program, script, credential, and AI action evaluated against the board-signed package. Legitimate work ran at full speed. Unauthorized work did not run at all.