"Intel SGX is a set of central processing unit (CPU) instruction codes from Intel that allows user-level code to allocate private regions of memory, called enclaves, that are protected from processes running at higher privilege levels."
I still don't fully understand the security model of enclaves (for instance, the same wikipedia page also talks about modifying spectre to work against enclaves[2]).
[1]https://en.wikipedia.org/wiki/Software_Guard_Extensions [2]https://github.com/lsds/spectre-attack-sgx
(disclaimer: I work at Google, but obviously not on this)