The systems that run the regulated business.
Churchill protects any critical Linux application that must stay in its approved state. Banking payment systems are first, and the same guarantee applies wherever a regulated business runs on software no one should change unilaterally. These are next on the roadmap.
Where this applies after payments.
Electronic health records
The system of record for patient care. Integrity and availability of ePHI are named obligations, and an unauthorized change to the EHR is a reportable event, not an IT ticket.
Pharmacy and lab systems
Dosing, dispensing, and results. Applications where a silent change puts patients at risk, and where proof that nothing changed is worth as much as the prevention itself.
AI agent runtimes
The application that acts autonomously is the one that most needs a state it cannot leave. Churchill holds the runtime to its approved baseline, with a kill switch that was original equipment, not an add-on.
Industrial control systems
Plants, grids, and utilities run on hosts where change is rare, planned, and dangerous when unilateral. A refused change beats a detected one every time.
ERP and supply chain backbones
The backbone that pays vendors, moves inventory, and closes the books. Living-off-the-land attacks and config drift end at the gate.
Mainframe partitions running the regulated business
Linux partitions on the frame already carry the regulated workload. Churchill was built and validated there, on IBM LinuxONE.
The control is the same in every industry: only the application your quorum approved runs, unauthorized change is refused at the kernel, and every attempt becomes evidence. What changes is which system counts as critical, and which regulator asks for the proof.
Running one of these systems today?
The roadmap order is not fixed in stone. Early conversations in these industries shape what we build next.