Claude in your own cloud tenant, under your own IAM roles.
Pexon deploys Claude into your own cloud account: Amazon Bedrock with an EU cross-region inference profile, or Claude in Microsoft Foundry on Azure. Requests authenticate through IAM roles or Entra ID groups scoped to one workload each, and invocation logs land in an account your security team already audits.
The starting point
The pilot signed up on a corporate card.
One team started on a subscription nobody in security owns, and the prompts have been leaving through it ever since. Nothing is logged where your SOC looks, no role separates finance from engineering, and the spend arrives as a single line on an expense report.
That is not a licensing problem. It is a deployment problem, and it gets more expensive the better the pilot goes.
What we build
What the deployment consists of
01
The endpoint inside your account
Claude on Amazon Bedrock in your own AWS account, or Claude in Microsoft Foundry in your Azure subscription. The endpoint sits inside the network, identity and billing perimeter your cloud team already operates, and consumption lands on the cloud invoice finance already reconciles.
- Amazon Bedrock
- Microsoft Foundry
02
One role per workload
Not a shared Bedrock role. Each workload gets an IAM role scoped to its inference profile ARN and to the model ARN in every destination Region AWS lists for that profile — the detail that silently breaks least-privilege setups and region-blocking service control policies. On Azure the same shape is expressed with Entra ID groups.
- IAM role
- inference profile ARN
- Entra ID groups
03
Residency and logging as configuration
An EU geographic inference profile chosen deliberately over the global one, and invocation logging written to a bucket or workspace you own. Where a request is processed and who asked for it become reviewable configuration in your account rather than an assurance in a vendor contract.
- EU geographic inference profile
- invocation logging
The platform decision
Bedrock versus Foundry, when EU processing is the requirement
| Question | Amazon Bedrock | Microsoft Foundry |
|---|---|---|
| EU inference today | Yes — EU cross-region inference profile | No — Global Standard and Data Zone Standard (US) only, as of July 2026 |
| Identity model | One IAM role per workload, scoped to profile and model ARNs | Entra ID groups with the same least-privilege shape |
| Invocation logging | Written to a bucket you own | Configurable, subject to the deployment type |
| Content filtering for Claude | Available at deployment | Microsoft states none is built in at deployment time |
If EU processing is a hard requirement today, the answer is Bedrock. The comparison is re-checked per engagement — the vendor pages move, and the deployment decision should move with them.
What changes
- Every Claude request carries an identity your security team can trace back to a person and a workload.
- Withdrawing one team's access stops meaning a change that touches everyone else.
- Processing stays inside the geography the inference profile names, and the profile is something an auditor can read.
- Model spend appears on the AWS or Azure invoice your finance team already reconciles.
- The rollout debate moves off procurement and onto which internal systems get connected next.
What the blueprint checks
Two weeks, and the questions it answers before any rollout
The Readiness Blueprint tests the three things that decide whether a tenant deployment is real: whether your identity model can express one role per workload, whether the deployment path actually meets your residency requirement — not a vendor's claim about it — and whether the logging lands where your security team already looks.
That is the difference between a deployment and a permission slip. The blueprint returns the path, the role model and a costed rollout plan, and the residency question is answered by the profile and the policy, both of which an auditor can read.
Start with the Readiness Blueprint.
Two weeks, €4,900 fixed price: we review your identity model, test the deployment path against your residency requirement, and hand back a costed rollout plan. It is yours to keep, whoever builds it. All prices are net and exclude VAT.
Deployment and residency questions
What does a tenant deployment of Claude cost?
The two-week Readiness Blueprint is fixed at €4,900 and returns the deployment path, the role model and a costed rollout plan. Build work is scoped from that plan. Model consumption is billed to you by AWS or Microsoft at their published rates — we do not resell tokens. If you want us to run it afterwards, a delivery pod starts at €7,500 per month. All prices are net and exclude VAT.
Can we keep prompts and completions inside the EU?
On Amazon Bedrock, yes. We deploy against an EU geographic cross-region inference profile, enumerate the permitted destination Regions in the IAM policy instead of trusting the profile name, and mirror that list in a service control policy so the constraint outlives the engineer who set it up. Because AWS stores abuse-detection copies in the destination Region, those Regions go into your processing record too.
Is Azure equivalent to Bedrock for a European deployment?
Not yet. Microsoft documents two hosting versions of Claude in Foundry — one on Anthropic infrastructure outside Azure, one on Azure end to end — and lists Global Standard plus a Data Zone Standard (US) deployment type, with no EU data zone as of July 2026. Microsoft also states that Foundry provides no built-in content filtering for Claude at deployment time. If EU processing is a hard requirement today, we deploy on Bedrock.
Next step
Not a sales call. An architecture call.
Thirty minutes with the architect who would actually run the engagement.
