Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Government teams can use Claude Code with Claude models on Amazon Bedrock in AWS GovCloud, but the service being available in a GovCloud region does not, by itself, authorize a particular model, data type, or development workload. Before rollout, confirm the model’s current approval and availability, choose the right Bedrock endpoint and region, complete model-access steps, and verify that the agency’s authorization boundary covers the intended use.
How Claude Code in GovCloud works
Claude Code is the coding client; Amazon Bedrock provides model inference. In the GovCloud workflow, the local Claude Code session sends prompts to the selected provider over the network and receives model output in return. AWS’s GovCloud setup guide, published in October 2026, documents Claude Code with Bedrock in GovCloud US-West and US-East through the Bedrock runtime endpoint, and in US-West through Bedrock Mantle.
Those are separate questions from whether a particular use is authorized. AWS maintains service availability, model availability, and model-specific compliance status separately. The agency must determine whether the exact model, endpoint, region, data classification, and development activity fit its authorization and security requirements.
What to verify before choosing a model or region
Check model availability and authorization separately
AWS lists Amazon Bedrock as available in AWS GovCloud (US-West) and AWS GovCloud (US-East), but model support and compliance status vary by model and deployment. AWS’s October 2026 setup guide identifies Claude Opus 5.5, Claude Sonnet 5.5, and Claude Sonnet 5 for its GovCloud Claude Code configuration. Treat those names as a point-in-time guide, not a guarantee of future availability: check AWS’s current model availability and compliance information before implementation and again before production use.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The guide reports that Sonnet 5 has FedRAMP Class D (formerly High) and DoD IL4/IL5 authorization, and that Opus 5.5 and Sonnet 5.5 have FedRAMP Class D certification on Bedrock. These statements apply to the specified models and Bedrock deployment; they do not establish approval for every Claude model, AWS region, customer environment, or workload. The agency’s authorization process remains controlling.
Confirm where inference can be routed
AWS distinguishes in-region inference, geographic cross-region inference, and global cross-region inference. In-region keeps inference in the selected AWS Region; geographic routing stays within a defined geography; global routing may use a supported commercial Region worldwide. A region label or a general “US” description does not, on its own, establish the processing location of every request. Confirm the exact model identifier and inference option against the organization’s residency requirements.
Understand the separate government offerings
Anthropic describes Claude for Government and Claude through Bedrock as different offerings with different authorization boundaries. Its public-sector FAQ says Claude for Government includes Claude Code in the Desktop app within its FedRAMP High boundary. It also describes Claude through Bedrock in GovCloud as an option for FedRAMP High and DoD IL4/IL5 workloads, while noting that AWS authorizes Bedrock models separately. Anthropic says ITAR-controlled data should use Claude through Bedrock in GovCloud. These platform descriptions do not substitute for an agency’s approval of its own system and use case.
Rank #2
Anthropic also explains that Claude models are software components, not cloud services that independently carry a FedRAMP or DoD impact-level authorization. Be specific about the service environment and approved deployment rather than describing “Claude” generally as authorized.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose between Bedrock runtime and Mantle
AWS’s October 2026 GovCloud guide describes two endpoint options. Their region coverage and governance features differ:
| Decision | bedrock-runtime |
bedrock-mantle |
|---|---|---|
| GovCloud regions in AWS’s October 2026 guide | US-West and US-East | US-West |
| API surface | AWS SDK InvokeModel / Converse |
Anthropic Messages API natively |
| Guardrails and invocation logging | Available; AWS recommends this endpoint for many new applications, especially where audit trails are needed | Not available, according to the guide |
| What to assess | Use when its regional and model support meets requirements and the deployment needs the documented logging or Guardrails features | Assess when native Messages API support is important and the documented region and feature limits are acceptable |
Check endpoint-specific model availability, IAM scope, routing behavior, logging, and authorization—not just the API surface. AWS says Guardrails and invocation logging are available only through bedrock-runtime.
Rank #3
Prepare model access and AWS credentials
AWS says GovCloud model access must be initiated through the standard AWS account linked to the GovCloud account. The team agrees to the model EULA in us-east-1 or us-west-2, then enables the model in the GovCloud account. AWS provides console and CLI paths and notes that entitlement propagation can take a few minutes.
For the documented setup, prepare an AWS GovCloud account with Bedrock access, an enabled model, permissions for the selected endpoint, and AWS CLI credentials or an AWS SSO login. AWS recommends IAM Identity Center and temporary, role-based credentials for organizational deployments rather than static access keys.
Minimum runtime permissions listed by AWS
For bedrock-runtime, AWS lists these minimum IAM actions in its guide:
Rank #4
bedrock:InvokeModelbedrock:InvokeModelWithResponseStreambedrock:ListInferenceProfilesbedrock:GetInferenceProfile
Mantle uses a different permission set, including bedrock-mantle:CreateInference and permissions to list and retrieve models and projects. Consult the current AWS guide for the full set, then scope the policy to the selected model and endpoint.
Configure Claude Code for the selected endpoint
Set up the runtime endpoint
AWS’s October 2026 manual setup example for Sonnet 5.5 in GovCloud US-West uses:
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION='us-gov-west-1'
export ANTHROPIC_MODEL='us-gov.anthropic.claude-sonnet-5-5'
The guide also provides an alternate Opus model identifier and documents an interactive /login wizard: choose a third-party platform, Amazon Bedrock, an authentication method, a region, and model pins. Check the current guide for exact wizard labels and identifiers, since model names and configuration can change.
Recommended Free Tools
Best Value
Set up Mantle
For Mantle, AWS shows CLAUDE_CODE_USE_MANTLE=1 with AWS_REGION='us-gov-west-1'. The October 2026 guide documents Mantle in GovCloud US-West; do not assume that this endpoint is available in US-East.
Verify the configuration
After configuration, AWS recommends checking /status in Claude Code to confirm the provider and model in use. For teams, centralize environment configuration and settings, and pin a model only after confirming that the selected identifier remains available and authorized for the intended deployment.
Review the data flow and local security controls
Anthropic says Claude Code runs locally, but prompts and model outputs travel over the network to the chosen model provider. Its documentation describes TLS 1.2 or later in transit and AES-256 at rest for Amazon Bedrock using AWS-managed keys; customer-managed AWS KMS keys are available. Encryption is one control, not a complete handling policy.
Claude Code can interact with repository files and propose commands or code changes. Anthropic documents permission prompts and advises users to review proposed code and commands. Set tool permissions and review practices to match the development environment and agency controls.
Quick Recap
- Determine how local transcripts, prompts, and outputs are retained and protected.
- Keep credentials out of prompts and repositories; review how credentials are issued, stored, and refreshed.
- Validate network paths, proxies, firewalls, and any telemetry against agency requirements.
- Decide whether invocation logs and Guardrails are required, then select an endpoint that supports the required features.
- Define how reviewers approve generated code and commands before they affect a repository, build, or production system.
- Confirm the handling and retention of audit logs, including who can access them.
Use a deployment gate before rollout
- Obtain authorization: have the agency security and authorization teams approve the exact model, Bedrock endpoint, region, data types, and development use case.
- Verify current service facts: check model availability, model-specific compliance status, endpoint coverage, and inference routing in AWS documentation for the target account and region.
- Complete access setup: perform the linked standard-account EULA and GovCloud enablement steps, then verify the model is enabled in the GovCloud account.
- Configure identity and policy: use temporary role-based credentials where possible and scope IAM actions to the chosen endpoint and model.
- Set data and tooling controls: review local session handling, network routes, tool permissions, code-review requirements, and logging against agency controls.
- Validate the deployed configuration: check Claude Code’s
/statusoutput and confirm the model and provider match the approved configuration before team use.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

