Claude in your own cloud tenant, under your own IAM roles.

Pexon deploys Claude into your own cloud account: Amazon Bedrock with an EU cross-region inference profile, or Claude in Microsoft Foundry on Azure. Requests authenticate through IAM roles or Entra ID groups scoped to one workload each, and invocation logs land in an account your security team already audits.

The starting point

The pilot signed up on a corporate card.

One team started on a subscription nobody in security owns, and the prompts have been leaving through it ever since. Nothing is logged where your SOC looks, no role separates finance from engineering, and the spend arrives as a single line on an expense report.

That is not a licensing problem. It is a deployment problem, and it gets more expensive the better the pilot goes.

What we build

What the deployment consists of

  1. 01

    The endpoint inside your account

    Claude on Amazon Bedrock in your own AWS account, or Claude in Microsoft Foundry in your Azure subscription. The endpoint sits inside the network, identity and billing perimeter your cloud team already operates, and consumption lands on the cloud invoice finance already reconciles.

    • Amazon Bedrock
    • Microsoft Foundry
  2. 02

    One role per workload

    Not a shared Bedrock role. Each workload gets an IAM role scoped to its inference profile ARN and to the model ARN in every destination Region AWS lists for that profile — the detail that silently breaks least-privilege setups and region-blocking service control policies. On Azure the same shape is expressed with Entra ID groups.

    • IAM role
    • inference profile ARN
    • Entra ID groups
  3. 03

    Residency and logging as configuration

    An EU geographic inference profile chosen deliberately over the global one, and invocation logging written to a bucket or workspace you own. Where a request is processed and who asked for it become reviewable configuration in your account rather than an assurance in a vendor contract.

    • EU geographic inference profile
    • invocation logging

The platform decision

Bedrock versus Foundry, when EU processing is the requirement

QuestionAmazon BedrockMicrosoft Foundry
EU inference todayYes — EU cross-region inference profileNo — Global Standard and Data Zone Standard (US) only, as of July 2026
Identity modelOne IAM role per workload, scoped to profile and model ARNsEntra ID groups with the same least-privilege shape
Invocation loggingWritten to a bucket you ownConfigurable, subject to the deployment type
Content filtering for ClaudeAvailable at deploymentMicrosoft states none is built in at deployment time

If EU processing is a hard requirement today, the answer is Bedrock. The comparison is re-checked per engagement — the vendor pages move, and the deployment decision should move with them.

What changes

  • Every Claude request carries an identity your security team can trace back to a person and a workload.
  • Withdrawing one team's access stops meaning a change that touches everyone else.
  • Processing stays inside the geography the inference profile names, and the profile is something an auditor can read.
  • Model spend appears on the AWS or Azure invoice your finance team already reconciles.
  • The rollout debate moves off procurement and onto which internal systems get connected next.

What the blueprint checks

Two weeks, and the questions it answers before any rollout

The Readiness Blueprint tests the three things that decide whether a tenant deployment is real: whether your identity model can express one role per workload, whether the deployment path actually meets your residency requirement — not a vendor's claim about it — and whether the logging lands where your security team already looks.

That is the difference between a deployment and a permission slip. The blueprint returns the path, the role model and a costed rollout plan, and the residency question is answered by the profile and the policy, both of which an auditor can read.

Start with the Readiness Blueprint.

Two weeks, €4,900 fixed price: we review your identity model, test the deployment path against your residency requirement, and hand back a costed rollout plan. It is yours to keep, whoever builds it. All prices are net and exclude VAT.

Deployment and residency questions

What does a tenant deployment of Claude cost?

The two-week Readiness Blueprint is fixed at €4,900 and returns the deployment path, the role model and a costed rollout plan. Build work is scoped from that plan. Model consumption is billed to you by AWS or Microsoft at their published rates — we do not resell tokens. If you want us to run it afterwards, a delivery pod starts at €7,500 per month. All prices are net and exclude VAT.

Can we keep prompts and completions inside the EU?

On Amazon Bedrock, yes. We deploy against an EU geographic cross-region inference profile, enumerate the permitted destination Regions in the IAM policy instead of trusting the profile name, and mirror that list in a service control policy so the constraint outlives the engineer who set it up. Because AWS stores abuse-detection copies in the destination Region, those Regions go into your processing record too.

Is Azure equivalent to Bedrock for a European deployment?

Not yet. Microsoft documents two hosting versions of Claude in Foundry — one on Anthropic infrastructure outside Azure, one on Azure end to end — and lists Global Standard plus a Data Zone Standard (US) deployment type, with no EU data zone as of July 2026. Microsoft also states that Foundry provides no built-in content filtering for Claude at deployment time. If EU processing is a hard requirement today, we deploy on Bedrock.

Next step

Not a sales call. An architecture call.

Thirty minutes with the architect who would actually run the engagement.