Fail-closed runtime integrity for Linux.
Churchill watches a protected application from inside and outside. Verified compromise ends in termination and lockdown, not in an alert queue.
From first host to governed fleet
The documentation follows the same path you will. Each step links to the section that covers it.
- 01Enroll a hostIssue a one-time provisioning code and run the bootstrapper. The host pairs outbound and proves its identity.
- 02Protect an applicationThe host discovers its own configuration. You review it in the console and submit it for CAB approval.
- 03Operate the fleetWatch posture and evidence live, replay sealed session recordings, and investigate lockdowns from one console.
- 04Govern changeEvery change to a protected application passes a Change Advisory Board. Every operator action lands on an audit chain.