Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
AWS adds Claude Opus and Sonnet 5.5 to GovCloud for regulated workloads - OpenSmartRoute
AWS adds Claude Opus and Sonnet 5.5 to GovCloud for regulated workloads
Amazon Bedrock in AWS GovCloud now supports Claude Opus 5.5 and Claude Sonnet 5.5. These models hold FedRAMP Class D certification and DoD Impact Level 4 or 5 authorization.
Key points
AWS GovCloud (US) Regions added Claude Opus 5.5 and Claude Sonnet 5.5 support.
Claude Sonnet 5 holds FedRAMP Class D and DoD IL4/IL5 authorization.
Claude Opus 5.5 completes tasks with fewer tokens than the previous Opus version.
Two endpoint surfaces exist: bedrock-runtime and bedrock-mantle.
Why it matters: Organizations can run AI coding tools in sensitive environments while meeting strict government compliance rules.
By OpenSmartRoute editorial · written through the router by writer-small
From AWS machine learning blog - “Supercharge regulated workloads with Claude Code and Amazon Bedrock”
Bradley Wyman. Image: AWS machine learning blog (original)
AWS GovCloud now hosts Claude Opus 5.5 and Claude Sonnet 5.5. These models join Amazon Bedrock for regulated workloads. The launch supports government and defense agencies. ITAR compliance becomes easier with these tools. Developers can build secure AI applications today.
AWS GovCloud launches Claude Code with new compliant models
AWS GovCloud (US) regions are built for sensitive US data. They offer higher security than standard AWS regions. Amazon Bedrock now includes Claude Opus 5.5 and Sonnet 5.5 here. This allows agentic coding tools to run in trusted environments. ITAR regulations often restrict where AI code can execute. These models provide a legal path for such work.
Claude Code is an agent system that writes and fixes code. It reads entire codebases to understand project logic. The new deployment lets it operate within GovCloud boundaries. This ensures data never leaves the secure perimeter. Organizations previously had to run code outside these strict rules. Now they can integrate AI directly into their internal tools.
The availability of these models marks a shift in how agencies develop software. It removes the need for manual, non-AI coding steps. Teams can automate repetitive tasks while staying compliant. This speeds up development cycles significantly. Security teams gain confidence in using generative AI. They know the data remains protected at all times.
Certification details for Claude Opus 5.5 and Sonnet 5.5
FedRAMP is a federal standard for cloud security. Class D certification indicates a specific level of protection. The models hold this Class D status officially. DoD Impact Level 4 or 5 authorization also applies to them. These ratings cover data handling and system integrity. They replace older, less secure legacy systems in government use.
Claude Sonnet 5 holds FedRAMP Class D certification as well. It shares the same security posture as its newer siblings. Opus 5.5 offers higher reasoning capabilities but maintains the same safety standards. Users must verify current model certification status regularly. Policies change frequently in the regulated industry sector. Checking the official compliance page is essential for all teams.
Zhipu AI released GLM 5.3, a massive 753B-parameter model, on Amazon Bedrock today.
These certifications mean the models can serve military and defense projects. They handle classified information with strict protocols. The DoD requires these specific impact levels for certain workloads. Agencies can now deploy AI without fear of regulatory fines. Non-compliance could lead to severe penalties or system shutdowns.
The certification process involves rigorous third-party audits. AWS Bedrock undergoes continuous security assessments. This ensures the models meet evolving threat landscapes. Developers do not need to manage these complex checks themselves. The platform handles the heavy lifting behind the scenes. Trust in the technology increases with every successful audit.
Technical architecture of bedrock-runtime and bedrock-mantle endpoints
Amazon Bedrock uses two main endpoint surfaces for API access. These are bedrock-runtime and bedrock-mantle. Both rely on the same underlying Mantle inference engine. Zero Operator Access (ZOA) architecture powers both systems. This design limits direct operator interaction with raw model data.
The bedrock-runtime endpoint supports standard AWS SDK APIs. It uses InvokeModel and Converse API calls. Developers can access Guardrails and Knowledge Bases here too. Logging capabilities allow for full audit trail creation. This surface is recommended for most new applications. It fits well with existing enterprise security frameworks.
The bedrock-mantle endpoint supports the Anthropic Messages API natively. It offers server-side tools and background inference features. Some advanced capabilities exist only on this surface. Projects can be managed through the Mantle interface. However, it is currently available in only one region. The US-West region hosts this specific endpoint exclusively.
Both endpoints support Claude Opus 5.5 and Sonnet 5.5 models. They also include the older Sonnet 5 version for compatibility. Bedrock-runtime spans both US-East and US-West regions. Users can choose the location based on their latency needs. Mantle is restricted to the West region only. This geographic split affects deployment planning for global teams.
Inference profiles allow fine-tuning of model behavior within constraints. Teams can pin specific versions for consistent results. This prevents unexpected changes in output quality or cost. The architecture ensures predictable performance across different workloads. Security controls apply uniformly regardless of the endpoint chosen.
Claude Code capabilities and integration methods
Claude Code reads your entire codebase to understand context. It edits files and runs commands directly from the terminal. Integration happens within IDEs like VS Code and JetBrains. The tool works in the background via the Agent SDK. This allows for seamless operation without interrupting workflow.
It can write code spanning multiple files across projects. Fixing bugs requires understanding logic over large distances. Testing, linting, and command execution are all automated. Git history searches help resolve merge conflicts quickly. Commits and pull requests are created automatically by the agent.
External tools connect through the Model Context Protocol (MCP). The AWS Command Line Interface is a supported tool. Terraform and Kubernetes management are also integrated options. This expands what the AI can achieve beyond simple code edits. Data sources become accessible for informed decision making.
Sub-agents spawn to work on different parts of tasks simultaneously. Parallel processing increases overall throughput for complex projects. Memory files named CLAUDE.md store project-specific behaviors. Skills define repeatable workflows for common development needs. Hooks enable pre-action and post-action automation routines.
Continuous integration and delivery pipelines integrate with GitHub or GitLab. Automated testing becomes part of the standard development cycle. This reduces human error in critical deployment stages. Teams can focus on high-level architecture rather than syntax errors. Productivity gains are measurable across large organizations.
Why this matters for regulated industries
Regulated industries face strict rules about data privacy and usage. Government agencies often cannot use public cloud models freely. FedRAMP certification is a mandatory requirement for many contracts. Non-compliance risks losing critical government funding or projects. These new models solve that specific compliance problem directly.
Cost savings emerge when teams avoid manual coding overhead. Opus 5.5 completes tasks with fewer tokens than older versions. This lowers the price per token significantly for heavy users. Sonnet 5.5 remains cheaper while offering sufficient intelligence for most jobs. Budgets become more predictable and manageable for finance departments.
Safety improves because data never leaves the GovCloud perimeter. Customer content is not stored, logged, or used for training. Third parties cannot access sensitive government information via these models. This builds trust among security-conscious stakeholders and auditors. It removes a major barrier to AI adoption in defense sectors.
Speed of development accelerates with automated agent workflows. Teams spend less time on routine coding tasks. They focus more on innovation and strategic planning instead. The ROI on AI investment becomes clearer and faster to realize. Operational efficiency metrics improve across the board for all users.
Step-by-step setup instructions for developers
Developers need an AWS GovCloud account with Bedrock access first. IAM roles must have specific permissions for API calls. Minimum policies include bedrock:InvokeModel and related list actions. The AmazonBedrockMantleInferenceAccess policy covers Mantle endpoints too. Proper configuration prevents access denial errors later on.
Install Claude Code using the provided shell or command scripts. The bash script works on Linux and macOS systems. Windows users should use the install.cmd file instead. Follow the installation docs for additional method options. Ensure your system has the required dependencies installed beforehand.
Option A uses an interactive setup wizard for ease of use. Select 3rd-party platform and choose Amazon Bedrock as the provider. Pick us-gov-west-1 as the region during configuration. Pin specific models to ensure consistent team deployments. The wizard saves settings automatically to your local configuration file.
Option B requires manual environment variable configuration for scripting. Set ANTHROPIC_MODEL to the full model ID string. Use us-gov.anthropic.claude-sonnet-5-5 for Sonnet 5.5 specifically. Pin default models with separate variables for Opus and Sonnet versions. This ensures deterministic behavior across all developer machines.
Option C routes Claude Code through the Bedrock Mantle endpoint. This is only available in the US-West region. Guardrails and logging are exclusive to the bedrock-runtime surface. Choose Option A or B if you need these compliance features. Mantle lacks some audit capabilities required by strict auditors.
Verify installation by checking for the Welcome message in your terminal. Run /status to confirm your model and provider connection. The output should show Amazon Bedrock or Amazon Bedrock (Mantle). This confirms successful integration with the cloud infrastructure. Troubleshoot any errors using AWS CLI logs immediately.
Deployment considerations for enterprise organizations
Organizations must decide how to deploy Claude Code across their teams. Foundational architecture for security and governance is critical first. Use AWS IAM Identity Center to govern identity and access centrally. Temporary, role-based credentials replace static keys for better security. Configure AWS CLI to use the SSO profile before logging in.
Automated configuration of default environment variables ensures consistency. Variables like ANTHROPIC_MODEL and AWS_REGION must be set correctly. Self-service instructions help developers configure their own machines quickly. Settings files can manage configuration centrally for large groups. This reduces support tickets related to misconfiguration issues.
Implement Guidance for Claude Code in large enterprise deployments. This helps maintain strict control over AI resource access. Connect to existing identity infrastructure for seamless user experience. Observability patterns track developer productivity and usage patterns effectively. Monitoring guides help identify anomalies or misuse early on.
Review service quotas and set appropriate tokens per minute limits. TPM and RPM quotas must support the number of active developers. Follow rate limit recommendations to avoid unexpected throttling errors. High usage teams need larger quotas allocated from the start.
Pin model versions for consistent team deployments across projects. Unpinned deployments bill at Opus rates by default. Set ANTHROPIC_MODEL to Sonnet 5.5 full ID to save costs. Use default model variables to control transitions between versions. Cross-region inference profile IDs use the us-gov prefix format.
Implement cost monitoring and per-user token guardrails for budget control. Daily token limits per developer prevent runaway costs. Alerting at 80% and 100% thresholds triggers immediate notifications. Amazon CloudWatch invocation logging tracks these metrics in real time. AWS Lambda functions can enforce these limits dynamically.
Use prompt caching to reduce costs and improve response times. Both 5-minute and 1-hour TTL options are available for supported models. Default teams to Claude Sonnet 5.5 for lower cost operations. Reserve Opus 5.5 for tasks requiring deeper reasoning or longer runs. Workloads needing IL4/IL5 authorization should default to Sonnet 5.
Security teams can configure managed permissions for what Claude Code does. Local configuration cannot overwrite these managed restrictions. CLAUDE.md memory files auto-add common workflows and style conventions. Deploy enterprise direct files to align with organizational preferences globally.
Google launched EmbeddingGemma 2, a compact open-weight model that maps text, images, and audio into one vector space. It runs locally on phones with minimal RAM and enables instant on-device semantic search.