Key takeaways
- AWS published the Claude Code GovCloud how-to on October 5, 2026. It operationalizes models already available there: Opus 5.5 was announced September 22 and Sonnet 5.5 on September 28; it is not a new Claude model launch.
- The documented profile IDs are us-gov.anthropic.claude-opus-5-5 and us-gov.anthropic.claude-sonnet-5-5. Pin the full ID because aliases and Claude Code defaults can change or fall back when access is unavailable.
- bedrock-runtime is available in GovCloud US-East and US-West and supports Guardrails and invocation logging. bedrock-mantle is documented only in GovCloud US-West and provides the native Anthropic Messages API plus features such as server-side tools and background inference.
- AWS’s October 5 matrix lists both Claude 5.5 models for GovCloud FedRAMP Class D. It does not list them in the separate IL4/IL5 column; AWS points workloads requiring IL4/IL5 to Claude Sonnet 5 instead.
- Neither the how-to nor the GovCloud availability notice quotes numeric Bedrock token prices. Capture the live account, model, endpoint and Region rate; defaulting silently to Opus can materially change spend.
AWS published the GovCloud Claude Code route on October 5
Amazon Web Services published a deployment guide on October 5, 2026 for running Claude Code against Amazon Bedrock in AWS GovCloud (US). The event is new implementation guidance for regulated AI-assisted development, not a new foundation model: AWS had already announced Opus 5.5 in GovCloud on September 22 and Sonnet 5.5 there on September 28.
The guide is explicit that its approach may not fit every organization or compliance program. That qualification matters. A model appearing in GovCloud and carrying a service authorization label does not make a developer workstation, repository, shell command, MCP server or CI runner compliant by inheritance.
Runtime and Mantle expose different control surfaces
The bedrock-runtime endpoint uses InvokeModel and Converse. AWS documents it in GovCloud US-West and US-East with Bedrock Guardrails, Knowledge Bases, Agents and invocation logging. The bedrock-mantle endpoint uses the native Anthropic Messages API and adds server-side tools, background inference and Projects, but AWS lists it only in GovCloud US-West.
Guardrails and invocation logging are exclusive to bedrock-runtime in the reviewed guide. Mantle also uses a separate bedrock-mantle IAM namespace; bedrock permissions do not cover it. Treat an endpoint switch as a control and API migration, not a transport toggle. Reapprove the Region, IAM actions, logging evidence, filtering behavior, request schema and fallback path.
Pin the us-gov profile instead of trusting an alias
AWS’s manual setup uses us-gov.anthropic.claude-sonnet-5-5 or us-gov.anthropic.claude-opus-5-5 in ANTHROPIC_MODEL. The wizard path selects Amazon Bedrock, authentication, us-gov-west-1 and model pins. The runtime route requires at least bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles and bedrock:GetInferenceProfile; Mantle requires its own actions.
Anthropic documents startup access checks and fallback behavior when a default is unavailable. AWS also says Claude Code currently defaults to Opus 5.5 as its primary model. An enterprise baseline should therefore pin full model IDs, constrain allowed models centrally and fail closed when the approved profile is unavailable rather than silently crossing a capability, certification or price boundary.
FedRAMP Class D does not mean every DoD tier is covered
AWS’s certification matrix, last updated October 5, lists Claude 5.5 Opus and Sonnet under the GovCloud FedRAMP Class D column. The same two entries are not marked in the separate DoD CSP SRG IL4/IL5 column. The deployment guide consequently points workloads that require IL4/IL5 authorization to Claude Sonnet 5, not Sonnet 5.5 or Opus 5.5.
Use the live matrix, account evidence and applicable authorization package at decision time. Do not collapse FedRAMP Class D, ITAR handling and DoD impact levels into one label. The AWS GovCloud documentation also says certain customer-defined metadata may leave GovCloud when the customer asks AWS to investigate an issue, and forbids export-controlled data in model-evaluation metadata.
Public numeric GovCloud pricing was not stated
The October 5 guide says Opus 5.5 has a higher per-token cost than Sonnet 5.5 and recommends Sonnet as a default for many teams, but it does not quote numeric GovCloud rates. The September 28 Sonnet availability notice also omits token prices. AccessAllGPT is therefore not importing direct Claude API prices or a commercial-Region quote into this GovCloud route.
Capture the live Bedrock rate for the exact account, profile, endpoint and Region before approval. Forecast uncached input, cache writes and reads, output, retries, long agent trajectories and surrounding logging or guardrail services. Add per-user token limits and alerts, and verify the bill after a bounded pilot. “FedRAMP” is an authorization attribute, not a price plan.
Claude Code remains a privileged local agent
Claude Code can read and edit repositories, execute tests and shell commands, inspect Git history, create commits and pull requests, connect to MCP tools and run in CI. Bedrock protects the inference route; it does not confine those local capabilities. AWS’s own guide says the software running on developer machines requires a separate security assessment.
Use IAM Identity Center and temporary role credentials, centrally managed permissions, repository-scoped execution, approved MCP servers, hooks that enforce deterministic policy, egress controls and complete local plus Bedrock audit trails. Keep consequential writes behind external authorization. Test whether logs contain source, prompts, tool arguments or secrets before enabling them broadly.
What regulated teams should do next
Adopt a bedrock-runtime pilot when the required model is certified for the workload, Guardrails and invocation logging are part of the evidence plan, and one GovCloud Region is approved. Constrain Claude Code to read-only analysis or patch proposals until command, repository and MCP policies pass. Wait when the price, authorization package, model access or metadata path is unresolved. Reject silent model fallback or a Mantle migration that drops required logging controls.
Start with a non-production repository and synthetic non-sensitive tasks. Record the exact Claude Code version, full model profile, endpoint, Region, IAM role, permissions, settings policy, tools, logs, quotas, token ceiling, rate capture and stop conditions. Exercise denied commands, unavailable-model behavior, fallback blocking, log retrieval and credential expiry before allowing regulated source or autonomous CI execution.
Copy-ready GovCloud Claude Code approval record
Complete one record per model, endpoint, Region and repository class before enabling developers or CI.
Entries stay in this browser tab and are not submitted to AccessAllGPT. Blank responses are copied as [Unresolved].
Pilot, adopt, constrain, wait or reject; repositories, users, owner, review date and expiry.
FedRAMP or DoD requirement, current AWS matrix evidence, authorization package, data classes and compliance owner.
Full us-gov model profile, bedrock-runtime or bedrock-mantle, GovCloud Region, Claude Code version and fallback-disabled evidence.
Identity Center profile, temporary credential lifetime, exact Bedrock or Mantle actions, resource conditions and emergency revoke path.
Readable repositories, writable paths, shell commands, MCP servers, network destinations, CI rights and required external approvals.
Invocation and local command logs, Guardrails configuration, retention, redaction, access, alerting and tested retrieval.
Dated account rate, input/output/cache assumptions, user token ceilings, RPM/TPM quotas, alerts and complete-task budget.
Denied command, unavailable profile, no silent fallback, expired credentials, throttling, logging loss, kill switch and rollback results.
Synthetic pilot traces, security assessment, compliance and procurement approvals, rollout cohort, incident owner and revalidation triggers.
Primary sources
Browse the publication-wide evidence index →
- Supercharge regulated workloads with Claude Code and Amazon BedrockAmazon Web Services · Reviewed: October 5, 2026 publication date and compliance disclaimer; model and endpoint availability; prerequisites; setup wizard and environment variables; IAM actions; model pinning; cost, logging, Guardrails, quotas, permissions and security considerations · Retrieved · Supports: AWS published a Claude Code configuration route for Claude Opus 5.5 and Sonnet 5.5 in AWS GovCloud (US), documenting separate bedrock-runtime and bedrock-mantle endpoints, us-gov inference-profile IDs and different audit and feature contracts.
- Claude Code on Amazon BedrockAnthropic · Reviewed: Amazon Bedrock setup; IAM permissions; model access; model pinning and fallback; AWS GovCloud us-gov prefix; Mantle setup and distinct permissions; endpoint and troubleshooting guidance · Retrieved · Supports: Anthropic documents Bedrock authentication and model-discovery behavior, warns that Claude Code can fall back when a default model is unavailable, and states that AWS GovCloud deployments use the us-gov profile prefix.
- Amazon Bedrock in AWS GovCloud (US)Amazon Web Services Documentation · Reviewed: Regional availability links; FedRAMP and DoD authorization links; export-controlled-content section; customer-defined metadata exceptions; model-evaluation metadata restriction · Retrieved · Supports: AWS directs GovCloud users to live model and certification tables and documents metadata that may leave GovCloud during customer-requested support plus model-evaluation metadata that must not contain export-controlled data.
- Amazon Bedrock models — FedRAMP and DoD CSP SRG certification statusAmazon Web Services · Reviewed: October 5, 2026 update date; Anthropic model-family rows; U.S. commercial FedRAMP Class C column; GovCloud FedRAMP Class D column; DoD CSP SRG IL4/IL5 column · Retrieved · Supports: The dated AWS matrix lists Claude 5.5 Opus and Claude 5.5 Sonnet under GovCloud FedRAMP Class D, while the reviewed row does not mark those two models for the separate DoD IL4/IL5 column.
- Claude Sonnet 5.5 now available on AWS GovCloud (US)Amazon Web Services · Reviewed: September 28, 2026 posting date; GovCloud availability statement; AWS infrastructure and regional-residency positioning; Guardrails and Knowledge Bases references; documentation links · Retrieved · Supports: AWS announced Claude Sonnet 5.5 availability in AWS GovCloud (US) on September 28. This predates the October 5 Claude Code how-to and separates model availability from the later deployment guidance.
Limitations
AccessAllGPT reviewed public first-party documentation but did not access an AWS GovCloud account; install or run Claude Code; invoke Claude Opus 5.5, Sonnet 5.5 or Sonnet 5; verify model access, endpoint behavior, profile routing, fallback behavior, Guardrails, invocation logging, Zero Operator Access, retention or metadata handling; inspect an authorization package; test ITAR, FedRAMP or DoD compliance; derive a complete least-privilege policy; or verify numeric GovCloud pricing, quotas, token use or charges. The AWS certification matrix’s compact markup was interpreted with its visible column labels and model rows; buyers should verify the current matrix and account evidence directly. Availability, authorizations, model defaults, IDs, endpoints, permissions, prices and policies can change.
Disclosures
AccessAllGPT received no AWS or Anthropic account, credentials, credits, early information, briefing, demo, authorization evidence, review or compensation for this article. Neither company sponsored, reviewed or endorsed it. AccessAllGPT Research is operated by NeuralArc, is independent, and is not affiliated with Amazon Web Services, Anthropic or agencies and standards bodies cited. Publication-wide relationships are listed on the disclosures page.
Further AccessAllGPT guidance
- Anthropic Launches Claude Sonnet 5.5 at $2 Input and $10 Output
- AWS Adds Local Claude Inference in India, Seoul and Singapore
- AWS Publishes a Secure Claude Desktop Route to AgentCore Web Search
- AI API Data Retention and Residency: Set the Procurement Gates
- Set Human-Approval Boundaries for AI Agents
- Move an LLM API Without Breaking Production
- AccessAllGPT Research methodology
- Publication disclosures
Continue the research
Get evidence-led updates for teams making production AI decisions.