Amazon Bedrock now offers Anthropic Claude Opus 5.5 and Claude Sonnet 5.5 in the AWS GovCloud (US) Regions, and those models can be accessed through Claude Code, Anthropic’s agentic coding assistant. This change lets teams that must meet FedRAMP Class D and DoD IL‑4/IL‑5 requirements run AI‑assisted development directly in a regulated cloud environment.
Model Availability and Compliance Context
The new models are listed on the Bedrock compliance page and carry FedRAMP Class D certification; Claude Sonnet 5 also holds DoD Impact Level 4/5 authorization. Because GovCloud isolates workloads for US‑only customers with elevated compliance needs, the models inherit the region’s existing security controls. Practitioners can therefore treat the model inference path as a compliant component, provided they verify the current certification status for the specific model version they intend to use.
Endpoint Choices and Runtime Implications
Bedrock exposes two surfaces: bedrock-runtime and bedrock-mantle. Both run on the Mantle inference engine with Zero Operator Access design, but they differ in API surface and feature set. bedrock-runtime is accessed via the AWS SDK (InvokeModel and Converse APIs) and supports Guardrails, Knowledge Bases, Agents, and invocation logging—features useful for audit trails and compliance reporting. It is available in both GovCloud US‑West and US‑East. bedrock-mantle implements the Anthropic Messages API natively, exposing server‑side tools, background inference, and Projects; it is only in GovCloud US‑West. Selecting the runtime endpoint therefore depends on the required feature set and regional availability.
Claude Code Capabilities in a Regulated Setting
Claude Code runs on the same Bedrock models and can operate from a terminal, IDE extensions (VS Code, JetBrains), or as a background agent via the Claude Agent SDK. Its documented actions include:
- Generating or fixing code across multiple files.
- Answering architecture‑level questions about a codebase.
- Running and repairing tests, linting, and other CLI commands.
- Searching Git history, resolving merge conflicts, and creating commits or pull requests.
- Connecting to external tools (AWS CLI, Terraform, Kubernetes) through the Model Context Protocol.
- Spawning sub‑agents to parallelise work.
- Customising behaviour with
CLAUDE.mdmemory files.
All interactions respect Bedrock’s data‑protection guarantee: customer content is not stored, logged, or used to train AWS models.
Operational and Security Considerations
Deploying Claude Code in GovCloud introduces several practical points:
- Data residency and logging: Since Bedrock does not retain input data, teams must still implement their own logging for audit purposes, especially when using
bedrock-runtimewhich offers invocation logging as an optional feature. - Endpoint selection: Choosing
bedrock-runtimeenables Guardrails and logging but limits access to Mantle‑only features. Teams should map required capabilities to the appropriate endpoint before provisioning. - Compliance verification: The model’s certification applies to the inference service, not to downstream code generated by Claude Code. Organizations must assess whether generated artifacts meet their own compliance baselines.
- Credential handling: Claude Code can invoke the AWS CLI via MCP; practitioners must ensure that the underlying IAM role follows least‑privilege principles, as the tool can execute arbitrary commands in the environment.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Engineers can now prototype or automate routine development tasks in a GovCloud‑hosted environment without leaving the compliance boundary defined by FedRAMP Class D and DoD IL‑4/IL‑5. The key actions are to decide which Bedrock endpoint aligns with required features, enable invocation logging if auditability is needed, and enforce strict IAM policies for any CLI interactions initiated by Claude Code. By treating the model service as a compliant compute primitive and handling generated code through existing security pipelines, teams can accelerate development while preserving regulatory posture.



